Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Cindyv10 logfile - what's wrong w/my computer?

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Cindyv10 logfile - what's wrong w/my computer?

Unread postby cindyv10 » May 3rd, 2008, 10:05 pm

Lately our computer has been repeatedly getting infected w/something. Usually our standard scanning programs find the problem, we fix it, and things are fine. It seems though that our programs (SpyBot, PestPatrol, AdAware, McAfee) are having problems. They'll hang up or come up with an error during the scan - I'm wondering if we got a really bad something that is beyond our limited experience in this area. I'm going to attempt to upload the logfile - cross your fingers!
cindyv10
Active Member
 
Posts: 11
Joined: May 3rd, 2008, 9:53 pm
Advertisement
Register to Remove

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby km2357 » May 4th, 2008, 3:26 pm

Hello and welcome to Malware Removal.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.


Step # 1: Download and Run HijackThis
Download HJTInstall.exe to your Desktop.

  • Doubleclick HJTInstall.exe to install it.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Copy/Paste the log to your next reply please.
Don't use the Analyse This button, its findings are dangerous if misinterpreted.
Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

Step # 2: Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.


In your next post/reply, I need to see the following:

1. Uninstall List
2. HiJackThis Log
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3206
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby km2357 » May 7th, 2008, 2:45 pm

Cindyv10? Do you still need help?
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3206
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby cindyv10 » May 8th, 2008, 6:58 am

I'm so sorry, I've been so incredibly busy! I have found what caused my "possessed" cursor - we have an optical mouse and there was a bunch of dog fur blocking the "eye"! However, I would still like you to look at what we've got and advise any cleanup action.

Here's the saved logfile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:56:17 AM, on 5/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\DSentry.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\GameHouse\Plant Tycoon\PlantTycoon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/customi ... //www.yaho

o.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://red.clientapps.yahoo.com/customi ... //www.yaho

o.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://red.clientapps.yahoo.com/customi ... //www.yaho

o.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/customi ... //www.yaho

o.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://red.clientapps.yahoo.com/customi ... //www.yaho

o.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://red.clientapps.yahoo.com/customi ... //www.yaho

o.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper -

{02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program

Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection -

{53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} -

C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 - BHO: Yahoo! IE Services Button -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -

C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -

C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: SidebarAutoLaunch Class -

{F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program

Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88}

- C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Motive SmartBridge]

C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PPMemCheck]

c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center]

c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program

Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program

Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support

Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client

Foundation\CFD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software

Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe"

/startup
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search

Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support

Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE"

/P7 /q

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\MLKTM5SX\CAIN

SH2N.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\MLKTM5SX\NEW

HER~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\2LAOYF2P\KAVA

ST~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\O9AZSTUJ\HAPP

YD~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\YZSF1A7M\LINKS

_~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\E5EDUPOV\LINK

_1~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\PFMJV5HE\NEW

AU_~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\PFMJV5HE\VAST

KA~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4T63CHIF\VOXAN

T~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4X2VCDYJ\AUTV

B_~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4T63CHIF\ADS_1

_~1.SH!

C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\M5KC3M2Y\PROF

IL~1.SH!
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &

Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default

user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital

Imaging\bin\hpqtra08.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program

Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program

Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &Search - ?p=ZJxdm070YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program

Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program

Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program

Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program

Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program

Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: AT&T Yahoo! Services -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -

C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

(no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine

Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?LinkId= ... lcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com

Operating System Class) -

http://bin.mcafee.com/molbin/shared/mci ... insctl.cab
O16 - DPF: {57B2CA01-6C40-44BB-9FCC-BFA7FADAA6E3}

(SightSpeedWebImpl Class) -

https://directory.sightspeed.com/releas ... _setup.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl

Class) -

http://www.update.microsoft.com/microso ... /client/mu

web_site.cab?1201988764296
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -

http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr

Class) -

http://bin.mcafee.com/molbin/shared/mcg ... cgdmgr.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools

WebPlayer Class) -

http://a532.g.akamai.net/f/532/6712/4h/ ... ayer/Insta

ll3.0/Installer.exe
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class)

- http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol hijack: mhtml -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program

Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program

Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation -

C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. -

C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program

Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. -

C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program

files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. -

C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. -

c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. -

C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. -

C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. -

C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation -

C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter)

(sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support

Center\bin\sprtsvc.exe
O23 - Service: YPCService - Yahoo! Inc. -

C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 12812 bytes


And here's the uninstall list:

3D Groove Playback Engine
Ad-Aware 2007
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
AnswerWorks 4.0 Runtime - English
AnswerWorks 5.0 English Runtime
AT&T Yahoo! Applications
Atari Anniversary Edition
ATT-AACE
AXIS Media Control
BroadJump Client Foundation
CADKEY 99
CAT 1.0
Classic PhoneTools
Conexant SmartHSFi V92 56K Speakerphone PCI Modem
Dell Digital Jukebox Driver
Dell Picture Studio - Dell Image Expert
Dell Solution Center
Dell Support
Dell Support Center
DellSupport
Design my Room
Digital Blue(tm) QX3(tm) Computer Microscope
Digital Voice Recorder
DVDSentry
Easy CD Creator 5 Basic
exPressit S.E. 2.1
Google Earth
Greeting Card Factory Premier
Greeting Card Maker
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Imaging Device Functions 7.0
HP Photosmart and Deskjet 7.0.A
HP Photosmart Essential
HP Software Update
HP Solution Center 7.0
Insaniquarium Deluxe 1.0
Intel(R) PRO Ethernet Adapter and Software
Intel(R) PROSet II
InterActual Player
ItsDeductible Express
iTunes
KONICA_MINOLTA DiMAGE remote camera driver
Logitech ImageStudio
LogMeIn
Macromedia Shockwave Player
Mahjongg Master Special Edition
Mastercam Demo 9.0
Mavis Beacon Teaches Typing 12 Standard
McAfee SecurityCenter
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Zoo Tycoon
Modem Helper
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Nancy Drew: Secret of Shadow Ranch
Network Play System (Patching)
NVIDIA Display Driver
NVIDIA Drivers
OCR Software by I.R.I.S 7.0
Paint Shop Pro 7
Palm Desktop
Photo Loader 2.1E
Plant Tycoon
Pop-Up Stopper
Post-it® Software Notes Lite
PowerDVD
Prince of Persia 3D
Quicken 2008
Quicken WillMaker Plus 2008
QuickTime
QuickVerse 7.0
RealPlayer
Rio Internet Update
Rio Music Manager
SBC Self Support Tool
SBC Yahoo! Applications
SBC Yahoo! DSL Activation
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
SetupPPUpdater
Shockwave
Sibelius Scorch
SightSpeed Video Messenger (remove only)
Solid State MP3 Player
Sound Blaster Live!
SplashShopper
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SpywareBlaster 4.0
Tumblebugs 2
TurboTax Deluxe 2003
TurboTax Deluxe 2004
TurboTax Deluxe 2005
TurboTax Deluxe 2007
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2005
TurboTax ItsDeductible 2006
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Wal-Mart Music Downloads Store
WebCyberCoach 3.2 Dell
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB810217
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinZip
WordPerfect Office 2002
WordPerfect Office 2002
Xvid 1.1.2 final uninstall
Yahoo! Anti-Spy
Yahoo! Search Protection

Thank you so much for your patience!

Cindy
cindyv10
Active Member
 
Posts: 11
Joined: May 3rd, 2008, 9:53 pm

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby km2357 » May 8th, 2008, 3:01 pm

Can you repost your HiJackThis Log please. The way you posted it made very hard to read. When posting it, make sure that Word Wrap is off. To check if Word Wrap if off, do the following:

Open up Notepad.
Click Edit and if there is checkmark/tick by Word Wrap, click it so the checkmark/tick disappears.

Thanks. :)
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3206
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby cindyv10 » May 8th, 2008, 9:46 pm

OK, I'll give it a shot...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:56:17 AM, on 5/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\DSentry.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\GameHouse\Plant Tycoon\PlantTycoon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customi ... ch/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customi ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customi ... .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customi ... ch/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customi ... .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customi ... .yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P7 /q C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\MLKTM5SX\CAINSH2N.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\MLKTM5SX\NEWHER~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\2LAOYF2P\KAVAST~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\O9AZSTUJ\HAPPYD~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\YZSF1A7M\LINKS_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\E5EDUPOV\LINK_1~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\PFMJV5HE\NEWAU_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\PFMJV5HE\VASTKA~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4T63CHIF\VOXANT~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4X2VCDYJ\AUTVB_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4T63CHIF\ADS_1_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\M5KC3M2Y\PROFIL~1.SH!
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &Search - ?p=ZJxdm070YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId= ... lcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mci ... insctl.cab
O16 - DPF: {57B2CA01-6C40-44BB-9FCC-BFA7FADAA6E3} (SightSpeedWebImpl Class) - https://directory.sightspeed.com/releas ... _setup.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 1988764296
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcg ... cgdmgr.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/ ... taller.exe
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol hijack: mhtml -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 12812 bytes
cindyv10
Active Member
 
Posts: 11
Joined: May 3rd, 2008, 9:53 pm

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby km2357 » May 9th, 2008, 2:21 am

That's a lot better, thanks. :)

Step # 1 BroadJump Client Foundation

You have Broadjump Client Foundation software installed. This is a memory and resource hog. Please uninstall BroadJump Client Foundation in the Control Panel /Add or Remove programs. This is the item to fix in HijackThis:

Source:
Again on XP, CFD has been seen to slowly but surely gobble up resources and memory, ending up running at 95% of CPU resources and an impossibly slow PC. You've guessed it : de-install "Broadjump Client Foundation" through "Add/Remove Programs" in the Control Panel, and/or disable BJCFD, or its newer incarnation, CFD, with The Ultimate Troubleshooter. Those users who have done so have reported no ill-effects whatsoever. You can also run Ad-Aware or Spybot Search & Destroy who will both rid your PC of the Broadjump software.



Step # 2: Disable Teatimer

Spybot S&D's tea timer normally provides real-time protection from spyware, however it may interfere with what we need to do. We will disable it until the machine is clean when it can be re-enabled.

This is a two step process.
First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident


Second step, For Either Version :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go To the bottom of the Vertical Panel on the Left, Click Tools
  • then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.


Step # 3: Disable Ad-Aware 2007 Service

Please disable the Ad-Aware 2007 Service as it may interfere with the fix.

  • On your desktop, click Start.
  • Choose Run.
  • Type services.msc in the open box and click OK or press Enter.
  • Scroll down the list of services and double-click Ad-Aware 2007 Service.
  • In the service properties window that opens, click the STOP button.
  • Under Startup Type, use the pull down menu and select Manual from the list of options.
  • Click OK and exit the Services Control Manager.
  • Reboot your machine for the changes to take effect.

Once your log is clean you can re-enable those settings.


Step # 4: Download and Run ATF Cleaner
Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Step # 5: Remove Hijackthis Entries




Step # 6 Download and Run Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Before running a scan, click the Update tab, next click Check for Updates to download any updates, if available.
  • Next click the Scanner tab and select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • You can also access the log by doing the following:
  • Click on the Malwarebytes' Anti-Malware icon to launch the program.
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open.


In your next post/reply, I need to see the following:

1. The MalwareBytes' Log
2. A fresh HiJackThis Log
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3206
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby cindyv10 » May 9th, 2008, 7:44 am

Whew! OK, here's the latest...

Malwarebytes' Anti-Malware 1.12
Database version: 736

Scan type: Quick Scan
Objects scanned: 45992
Time elapsed: 15 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:48:07 AM, on 5/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P7 /q C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\MLKTM5SX\CAINSH2N.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\MLKTM5SX\NEWHER~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\2LAOYF2P\KAVAST~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\O9AZSTUJ\HAPPYD~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\YZSF1A7M\LINKS_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\E5EDUPOV\LINK_1~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\PFMJV5HE\NEWAU_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\PFMJV5HE\VASTKA~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4T63CHIF\VOXANT~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4X2VCDYJ\AUTVB_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4T63CHIF\ADS_1_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\M5KC3M2Y\PROFIL~1.SH!
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId= ... lcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mci ... insctl.cab
O16 - DPF: {57B2CA01-6C40-44BB-9FCC-BFA7FADAA6E3} (SightSpeedWebImpl Class) - https://directory.sightspeed.com/releas ... _setup.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 1988764296
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcg ... cgdmgr.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/ ... taller.exe
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol hijack: mhtml -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 11282 bytes
cindyv10
Active Member
 
Posts: 11
Joined: May 3rd, 2008, 9:53 pm

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby km2357 » May 9th, 2008, 1:52 pm

Step # 1: Run Kaspersky Online Scan
Please do an online scan with Kaspersky WebScanner

You must be using Internet Explorer, Kaspersky does not work with Firefox

Click Accept

You will be promted to install an ActiveX component from Kaspersky,
Click Yes.

  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    • Scan using the following Anti-Virus database:


      Extended (if available otherwise Standard)


    • Scan Options:


      Scan Archives Scan Mail Bases
  • Click OK
  • Now under select a target to scan:

      Select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.

    • Now click on the Save as Text button:
  • Once finished, save the log to your Desktop as filename KAV.txt

In your next post/reply, I need to see the following:

1. Kaspersky results
2. A fresh HiJackThis Log
3. How is your computer doing, any problems?

Use multiple posts if you can't fit everything into one post.
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3206
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby cindyv10 » May 9th, 2008, 7:35 pm

Wow, that took a while. Everything seems to be working OK. Here are the Kaspersky results as well as the latest Hijackthis log...

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, May 09, 2008 7:32:33 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/05/2008
Kaspersky Anti-Virus database records: 750179
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 145682
Number of viruses found: 3
Number of infected objects: 17
Number of suspicious objects: 0
Duration of the scan process: 02:13:12

Infected Object Name / Virus Name / Last Action
C:\1c7b1dd4d425cad8d6060300ae\admin.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\admin.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\author.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\author.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\cfgwiz.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp40ext.inf Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4amsft.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4anscp.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4apws.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4areg.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4atxt.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4autl.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4avnb.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4avss.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4awebs.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp4awel.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp98sadm.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fp98swin.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fpadmcgi.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fpadmdll.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fpcount.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fpencode.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fpexedll.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fpmmc.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fpremadm.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\fpsrvadm.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\shtml.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\shtml.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\spmsg.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\spuninst.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\stub_fpsrvadm.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\stub_fpsrvwin.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\tcptest.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\update\kb810217.cat Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\update\spcustom.dll Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\update\update.exe Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\update\update.inf Object is locked skipped
C:\1c7b1dd4d425cad8d6060300ae\update\update.ver Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{CB2A5F67-FFA1-4F8D-A8E1-3175B1AC643D}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR3B.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ed33ac470e15454cff2fb5a2227c093_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\31c035515909307f7bb2ef2c2099a836_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3371e6720e1d169c04cfc0aae6a157c5_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55622f8573215e962782c9513a7b5316_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b3f9a2115c7852d03ccc0a456f2eeee2_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c77776d4533d3bd93502740699e69144_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\SupportSoft\DellSupportCenter\SYSTEM\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\Cynthia\Application Data\3M\PSNotes\PSNData Object is locked skipped
C:\Documents and Settings\Cynthia\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Cynthia\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Documents and Settings\Cynthia\Application Data\GTek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Documents and Settings\Cynthia\Application Data\GTek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Documents and Settings\Cynthia\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\Application Data\SupportSoft\DellSupportCenter\Cynthia\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\History\History.IE5\MSHist012008050920080510\index.dat Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\Temp\~DF2112.tmp Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\Temp\~DFE59E.tmp Object is locked skipped
C:\Documents and Settings\Cynthia\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cynthia\ntuser.dat Object is locked skipped
C:\Documents and Settings\Cynthia\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\John\Application Data\Mozilla\Profiles\default\3w81iw26.slt\Cache\484DDDCAd01 Infected: Trojan-Downloader.Win32.VB.df skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Nancy Drew\Secret of Shadow Ranch\setup.ilg Object is locked skipped
C:\Program Files\Common Files\Real\Toolbar\RealBar.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.s skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\00000002.ps1 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\00000002.ps2 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\00010002.ci Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\cicat.fid Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\cicat.hsh Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiCL0001.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiP10000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiP20000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiPT0000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiSL0001.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiSP0000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiST0000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiVP0000.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\INDEX.000 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\propstor.bk1 Object is locked skipped
C:\Program Files\Dell\Support\UI\Search\catalog.wci\propstor.bk2 Object is locked skipped
C:\Program Files\InstallShield Installation Information\{10798AE3-DCBB-43C3-9C93-C23512427E25}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{EC2AA0F6-F50A-44C8-8FC0-01C01D7CF519}\setup.ilg Object is locked skipped
C:\Program Files\PestPatrol\Quarantine\20040809214845625.zip Object is locked skipped
C:\Program Files\SBC Self Support Tool\SmartBridge\AlertFilter.log Object is locked skipped
C:\Program Files\SBC Self Support Tool\SmartBridge\log\httpclient.log Object is locked skipped
C:\Program Files\SBC Self Support Tool\SmartBridge\SmartBridge.log Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc45.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc46\Thumbs.db Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc47.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc48.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc49.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc50.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc51.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc52.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc53 Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc54.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc55.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc56.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc57.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc58.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc59.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc60.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc61.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc62.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc63.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc64.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc65.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc66.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc67.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc68.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc69.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc70.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc71.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc72.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc73.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc74.JPG Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc76.w180h200 Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc77.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc78.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc79.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc81\Thumbs.db Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\1107979355_Trippmd30.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\all that remains lyrics.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\Awesome story.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\duuuh.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\ericc.bmp Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\ericcc.bmp Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\HOT.bmp Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\joey&wednesday13.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\joey1.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\joey2.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\joeyj04.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\koey.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\lol.bmp Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\sexy1.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\Thumbs.db Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\untitled.bmp Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc82\yeah.bmp Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc83.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc84.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc85.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc86.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc87.txt Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc88.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc89.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc90.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc92.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-2196182023-2969185200-383524529-1008\Dc93.jpg Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps1 Object is locked skipped
C:\System Volume Information\catalog.wci\00000002.ps2 Object is locked skipped
C:\System Volume Information\catalog.wci\0001000D.ci Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2071\A0204256.exe/WISE0102.BIN/WISE0008.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2071\A0204256.exe/WISE0102.BIN/WISE0009.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2071\A0204256.exe/WISE0102.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2071\A0204256.exe WiseSFX: infected - 3 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2071\A0204256.exe WiseSFXDropper: infected - 3 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2072\A0204306.exe/WISE0102.BIN/WISE0008.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2072\A0204306.exe/WISE0102.BIN/WISE0009.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2072\A0204306.exe/WISE0102.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2072\A0204306.exe WiseSFX: infected - 3 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2072\A0204306.exe WiseSFXDropper: infected - 3 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2074\A0204385.exe/WISE0102.BIN/WISE0008.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2074\A0204385.exe/WISE0102.BIN/WISE0009.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2074\A0204385.exe/WISE0102.BIN Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2074\A0204385.exe WiseSFX: infected - 3 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2074\A0204385.exe WiseSFXDropper: infected - 3 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2092\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\shlwapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\sxs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\xpsp2res.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcafee_PlLqBbnhbut1Rvk Object is locked skipped
C:\WINDOWS\Temp\mcmsc_l0Oae65ELcss6Oa Object is locked skipped
C:\WINDOWS\Temp\mcmsc_nAZA34YsJVkMLd8 Object is locked skipped
C:\WINDOWS\Temp\mcmsc_tNXitjWcHOqitxj Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vso\44944495.upd Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vso\44954496.upd Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vso\44964497.upd Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vso\44974498.upd Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vso\44984499.upd Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vso\delta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcu10.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcu100.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu100.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu100.tmp\vso\48344835.upm Object is locked skipped
C:\WINDOWS\Temp\mcu100.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu107.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu107.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu107.tmp\vso\48084809.upm Object is locked skipped
C:\WINDOWS\Temp\mcu107.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu10E.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu10E.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu10E.tmp\vso\48544855.upm Object is locked skipped
C:\WINDOWS\Temp\mcu10E.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu110.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu110.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu110.tmp\vso\48554856.upm Object is locked skipped
C:\WINDOWS\Temp\mcu110.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vso\44844485.upd Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vso\44854486.upd Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vso\44864487.upd Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vso\44874488.upd Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vso\44884489.upd Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vso\delta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcu12.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcu120.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu120.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu120.tmp\vso\47114712.upm Object is locked skipped
C:\WINDOWS\Temp\mcu120.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu12E.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu12E.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu12E.tmp\vso\48934894.upm Object is locked skipped
C:\WINDOWS\Temp\mcu12E.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu13C.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu13C.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu13C.tmp\vso\48744875.upm Object is locked skipped
C:\WINDOWS\Temp\mcu13C.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu143.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu143.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu143.tmp\vso\49144915.upm Object is locked skipped
C:\WINDOWS\Temp\mcu143.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu14F.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu14F.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu14F.tmp\vso\49254926.upm Object is locked skipped
C:\WINDOWS\Temp\mcu14F.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu150.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu150.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu150.tmp\vso\49264927.upm Object is locked skipped
C:\WINDOWS\Temp\mcu150.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu151.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu151.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu151.tmp\vso\49274928.upm Object is locked skipped
C:\WINDOWS\Temp\mcu151.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu152.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu152.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu152.tmp\vso\49284929.upm Object is locked skipped
C:\WINDOWS\Temp\mcu152.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu156.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu156.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu156.tmp\vso\49324933.upm Object is locked skipped
C:\WINDOWS\Temp\mcu156.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu158.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu158.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu158.tmp\vso\49344935.upm Object is locked skipped
C:\WINDOWS\Temp\mcu158.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu15B.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu15B.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu15B.tmp\vso\49364937.upm Object is locked skipped
C:\WINDOWS\Temp\mcu15B.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu16C.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu16C.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu16C.tmp\vso\49544955.upm Object is locked skipped
C:\WINDOWS\Temp\mcu16C.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu18.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu18.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu18.tmp\vso\45864587.upm Object is locked skipped
C:\WINDOWS\Temp\mcu18.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu1A.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu1A.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu1A.tmp\vso\45894590.upm Object is locked skipped
C:\WINDOWS\Temp\mcu1A.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu1A6.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu1A6.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu1A6.tmp\vso\48404841.upm Object is locked skipped
C:\WINDOWS\Temp\mcu1A6.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu1C.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu1C.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu1C.tmp\vso\45924593.upm Object is locked skipped
C:\WINDOWS\Temp\mcu1C.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vso\45494550.upd Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vso\45504551.upd Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vso\45514552.upd Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vso\45524553.upd Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vso\45534554.upd Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vso\45544555.upd Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vso\delta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcu1D.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcu20.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu20.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu20.tmp\vso\45954596.upm Object is locked skipped
C:\WINDOWS\Temp\mcu20.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu233.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu233.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu233.tmp\vso\47804781.upm Object is locked skipped
C:\WINDOWS\Temp\mcu233.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu264.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu264.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu264.tmp\vso\48114812.upm Object is locked skipped
C:\WINDOWS\Temp\mcu264.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu2E.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu2E.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu2E.tmp\vso\46064607.upm Object is locked skipped
C:\WINDOWS\Temp\mcu2E.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu30.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu30.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu30.tmp\vso\46054606.upm Object is locked skipped
C:\WINDOWS\Temp\mcu30.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu35.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu35.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu35.tmp\vso\46124613.upm Object is locked skipped
C:\WINDOWS\Temp\mcu35.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu37.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu37.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu37.tmp\vso\46144615.upm Object is locked skipped
C:\WINDOWS\Temp\mcu37.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu38.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu38.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu38.tmp\vso\46154616.upm Object is locked skipped
C:\WINDOWS\Temp\mcu38.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vso\44894490.upd Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vso\44904491.upd Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vso\44914492.upd Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vso\44924493.upd Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vso\44934494.upd Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vso\delta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vso\en-us\us\vso.cab Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcu39.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcu3D.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu3D.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu3D.tmp\vso\46184619.upm Object is locked skipped
C:\WINDOWS\Temp\mcu3D.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu45.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu45.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu45.tmp\vso\46284629.upm Object is locked skipped
C:\WINDOWS\Temp\mcu45.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu49.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu49.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu49.tmp\vso\46344635.upm Object is locked skipped
C:\WINDOWS\Temp\mcu49.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu4B.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu4B.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu4B.tmp\vso\45734574.upm Object is locked skipped
C:\WINDOWS\Temp\mcu4B.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu4C.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu4C.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu4C.tmp\vso\46374638.upm Object is locked skipped
C:\WINDOWS\Temp\mcu4C.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu4E.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu4E.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu4E.tmp\vso\46394640.upm Object is locked skipped
C:\WINDOWS\Temp\mcu4E.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu4F.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu4F.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu4F.tmp\vso\46414642.upm Object is locked skipped
C:\WINDOWS\Temp\mcu4F.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu5.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu5.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu5.tmp\vso\45794580.upm Object is locked skipped
C:\WINDOWS\Temp\mcu5.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu50.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu50.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu50.tmp\vso\46424643.upm Object is locked skipped
C:\WINDOWS\Temp\mcu50.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu52.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu52.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu52.tmp\vso\46444645.upm Object is locked skipped
C:\WINDOWS\Temp\mcu52.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu55.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu55.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu55.tmp\vso\46494650.upm Object is locked skipped
C:\WINDOWS\Temp\mcu55.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu57.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu57.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu57.tmp\vso\46514652.upm Object is locked skipped
C:\WINDOWS\Temp\mcu57.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu58.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu58.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu58.tmp\vso\46574658.upm Object is locked skipped
C:\WINDOWS\Temp\mcu58.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\vso\45124513.upd Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\vso\45134514.upd Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\vso\delta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcu5A.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcu60.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu60.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu60.tmp\vso\46624663.upm Object is locked skipped
C:\WINDOWS\Temp\mcu60.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu61.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu61.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu61.tmp\vso\46634664.upm Object is locked skipped
C:\WINDOWS\Temp\mcu61.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu68.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu68.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu68.tmp\vso\46294630.upm Object is locked skipped
C:\WINDOWS\Temp\mcu68.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu6C.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu6C.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu6C.tmp\vso\46714672.upm Object is locked skipped
C:\WINDOWS\Temp\mcu6C.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu6D.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu6D.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu6D.tmp\vso\46724673.upm Object is locked skipped
C:\WINDOWS\Temp\mcu6D.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu6E.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu6E.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu6E.tmp\vso\46734674.upm Object is locked skipped
C:\WINDOWS\Temp\mcu6E.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu72.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu72.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu72.tmp\vso\46604661.upm Object is locked skipped
C:\WINDOWS\Temp\mcu72.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu73.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu73.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu73.tmp\vso\46784679.upm Object is locked skipped
C:\WINDOWS\Temp\mcu73.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu75.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu75.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu75.tmp\vso\46834684.upm Object is locked skipped
C:\WINDOWS\Temp\mcu75.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu76.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu76.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu76.tmp\vso\46564657.upm Object is locked skipped
C:\WINDOWS\Temp\mcu76.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu77.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu77.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu77.tmp\vso\46844685.upm Object is locked skipped
C:\WINDOWS\Temp\mcu77.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu79.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu79.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu79.tmp\vso\46864687.upm Object is locked skipped
C:\WINDOWS\Temp\mcu79.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu7B.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu7B.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu7B.tmp\vso\46884689.upm Object is locked skipped
C:\WINDOWS\Temp\mcu7B.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu7F.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu7F.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu7F.tmp\vso\46924693.upm Object is locked skipped
C:\WINDOWS\Temp\mcu7F.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu80.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu80.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu80.tmp\vso\46934694.upm Object is locked skipped
C:\WINDOWS\Temp\mcu80.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu83.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu83.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu83.tmp\vso\46964697.upm Object is locked skipped
C:\WINDOWS\Temp\mcu83.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu89.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu89.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu89.tmp\vso\47004701.upm Object is locked skipped
C:\WINDOWS\Temp\mcu89.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu8C.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu8C.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu8C.tmp\vso\47024703.upm Object is locked skipped
C:\WINDOWS\Temp\mcu8C.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu99.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu99.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu99.tmp\vso\47144715.upm Object is locked skipped
C:\WINDOWS\Temp\mcu99.tmp\vso\47154716.upm Object is locked skipped
C:\WINDOWS\Temp\mcu99.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu9D.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu9D.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu9D.tmp\vso\47214722.upm Object is locked skipped
C:\WINDOWS\Temp\mcu9D.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcu9E.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu9E.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcu9E.tmp\vso\47234724.upm Object is locked skipped
C:\WINDOWS\Temp\mcu9E.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuA0.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuA0.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuA0.tmp\vso\47254726.upm Object is locked skipped
C:\WINDOWS\Temp\mcuA0.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuA1.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuA1.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuA1.tmp\vso\47264727.upm Object is locked skipped
C:\WINDOWS\Temp\mcuA1.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuA2.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuA2.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuA2.tmp\vso\47274728.upm Object is locked skipped
C:\WINDOWS\Temp\mcuA2.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuA3.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuA3.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuA3.tmp\vso\47284729.upm Object is locked skipped
C:\WINDOWS\Temp\mcuA3.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuAE.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuAE.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuAE.tmp\vso\47404741.upm Object is locked skipped
C:\WINDOWS\Temp\mcuAE.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuB9.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuB9.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuB9.tmp\vso\47564757.upm Object is locked skipped
C:\WINDOWS\Temp\mcuB9.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuC1.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuC1.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuC1.tmp\vso\47634764.upm Object is locked skipped
C:\WINDOWS\Temp\mcuC1.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuC5.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuC5.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuC5.tmp\vso\47674768.upm Object is locked skipped
C:\WINDOWS\Temp\mcuC5.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuC8.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuC8.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuC8.tmp\vso\47684769.upm Object is locked skipped
C:\WINDOWS\Temp\mcuC8.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuC9.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuC9.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuC9.tmp\vso\47704771.upm Object is locked skipped
C:\WINDOWS\Temp\mcuC9.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuCA.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuCA.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuCA.tmp\vso\47714772.upm Object is locked skipped
C:\WINDOWS\Temp\mcuCA.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuCB.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuCB.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuCB.tmp\vso\47724773.upm Object is locked skipped
C:\WINDOWS\Temp\mcuCB.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuCF.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuCF.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuCF.tmp\vso\47784779.upm Object is locked skipped
C:\WINDOWS\Temp\mcuCF.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuD4.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuD4.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuD4.tmp\vso\47844785.upm Object is locked skipped
C:\WINDOWS\Temp\mcuD4.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\mcappins.inf Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\mcinsres.dll Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\agent.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\agentcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\agentdui.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\agentsub.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\agentupd.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mccomctl.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mcdetect.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mcgdmgr.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\McGDMgr.dll Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\McGDMgr.inf Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mcinsctl.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mcinsctl.dll Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mcinsctl.inf Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mctskshd.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mcuicfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\shared\mghtml.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\45614562.upm Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\45624563.upm Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\45634564.upm Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\emlscbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\emlscres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\imscnbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\imscnres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\oscnbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\oscnres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\scrpsbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\scrstres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\shextbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\shextres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\vsagntui.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\vscfgui.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\vso.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\vsocfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\wrmstbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\en-us\us\wrmstres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\mcinsupd.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\UNICOWS.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\winnt\en-us\oasres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vso\winnt\oasbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcuDB.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcuDC.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuDC.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuDC.tmp\vso\47914792.upm Object is locked skipped
C:\WINDOWS\Temp\mcuDC.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuDE.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuDE.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuDE.tmp\vso\47934794.upm Object is locked skipped
C:\WINDOWS\Temp\mcuDE.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuDF.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuDF.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuDF.tmp\vso\47944795.upm Object is locked skipped
C:\WINDOWS\Temp\mcuDF.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vso\45064507.upd Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vso\45074508.upd Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vso\45084509.upd Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vso\delta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcuE1.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE2.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE2.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE2.tmp\vso\47974798.upm Object is locked skipped
C:\WINDOWS\Temp\mcuE2.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE3.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE3.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE3.tmp\vso\47984799.upm Object is locked skipped
C:\WINDOWS\Temp\mcuE3.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\delta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\en-us\us\emlscbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\en-us\us\emlscres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\en-us\us\vscfgui.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\en-us\us\vso.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\en-us\us\vsocfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\en-us\us\wrmstbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\en-us\us\wrmstres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vso\winxp\en-us\oasres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcuE4.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE5.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE5.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE5.tmp\vso\47994800.upm Object is locked skipped
C:\WINDOWS\Temp\mcuE5.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE6.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE6.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE6.tmp\vso\47694770.upm Object is locked skipped
C:\WINDOWS\Temp\mcuE6.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuE8.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE8.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuE8.tmp\vso\48014802.upm Object is locked skipped
C:\WINDOWS\Temp\mcuE8.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuEC.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuEC.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuEC.tmp\vso\48054806.upm Object is locked skipped
C:\WINDOWS\Temp\mcuEC.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuEF.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuEF.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuEF.tmp\vso\48094810.upm Object is locked skipped
C:\WINDOWS\Temp\mcuEF.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vso\45094510.upd Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vso\45104511.upd Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vso\45114512.upd Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vso\delta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcuF.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcuFA.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuFA.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuFA.tmp\vso\48274828.upm Object is locked skipped
C:\WINDOWS\Temp\mcuFA.tmp\vso\48284829.upm Object is locked skipped
C:\WINDOWS\Temp\mcuFA.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\McAppIns.exe Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\mcinsres.dll Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\mcuninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\shared\mcdetect.cab Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\Uninst.dll Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\uninst.ini Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\VsCfgIns.dll Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vso\en-us\us\aolcfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vso\en-us\us\emlscbin.cab Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vso\en-us\us\emlscres.cab Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vso\en-us\us\vscfgui.cab Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vso\en-us\us\vso.cab Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vso\en-us\us\vsocfg.cab Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vsocfg.ini Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vsoins.cab Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vsoins.inf Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\vsoins.ui Object is locked skipped
C:\WINDOWS\Temp\mcuFB.tmp\VsoVer.ini Object is locked skipped
C:\WINDOWS\Temp\mcuFE.tmp\UpdReq.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuFE.tmp\UpdResp.mcaf Object is locked skipped
C:\WINDOWS\Temp\mcuFE.tmp\vso\48314832.upm Object is locked skipped
C:\WINDOWS\Temp\mcuFE.tmp\vso\mcdelta.ini Object is locked skipped
C:\WINDOWS\Temp\tmp3\COPYFILE.INF Object is locked skipped
C:\WINDOWS\Temp\WGANotify.settings Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:33:38 PM, on 5/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P7 /q C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\MLKTM5SX\CAINSH2N.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\MLKTM5SX\NEWHER~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\2LAOYF2P\KAVAST~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\O9AZSTUJ\HAPPYD~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\YZSF1A7M\LINKS_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\E5EDUPOV\LINK_1~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\PFMJV5HE\NEWAU_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\PFMJV5HE\VASTKA~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4T63CHIF\VOXANT~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4X2VCDYJ\AUTVB_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\4T63CHIF\ADS_1_~1.SH! C:\DOCUME~1\Cynthia\LOCALS~1\TEMPOR~1\Content.IE5\M5KC3M2Y\PROFIL~1.SH!
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/ka ... nicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId= ... lcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mci ... insctl.cab
O16 - DPF: {57B2CA01-6C40-44BB-9FCC-BFA7FADAA6E3} (SightSpeedWebImpl Class) - https://directory.sightspeed.com/releas ... _setup.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 1988764296
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcg ... cgdmgr.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/ ... taller.exe
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol hijack: mhtml -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

--
End of file - 11612 bytes
cindyv10
Active Member
 
Posts: 11
Joined: May 3rd, 2008, 9:53 pm

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby km2357 » May 9th, 2008, 11:17 pm

Kaspersky found some infected System Restore points, but those are harmless where they are. I'll show you how to clear them out and set a new, clean one in the next post.

You have a lot of files in your C:\WINDOWS\Temp\ folder. They are harmless in themselves, (they are related to McAfee), but you can delete them from your Computer with no worries. Just open up Windows Explorer and select everything into the C:\WINDOWS\Temp folder and delete it, do not delete the folder itself. Deleting the files will help clear up some Hard Drive space and make any future online scans go a lot faster, since the scanner you use won't be scanning those files.

You also need to clear Firefox's cache as it is infected:

Start Firefox.
Once it is loaded, click Tools
Then click Clear Private Data
In the new box/window that opens, make sure that Cache has a checkmark/tick by it. If it does not, click by it so that it does.
Finally click Private Data Now


Finally, empty your Recycle Bin.


Let me know how everything went.
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3206
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby cindyv10 » May 10th, 2008, 8:52 am

RATS! And it's gone so smoothly up to this point. When I try to delete the files in C:\Windows\Temp\ I get "...Access denied. Make sure disk is not full or write protected and that file is not currently in use."

Also, I can't find Firefox. I was never aware of anyone using it. I can find a few items using "search", and found a bookmark to mozilla's site. I deleted that and did another search and come up with nothing.

Wadda ya think?
cindyv10
Active Member
 
Posts: 11
Joined: May 3rd, 2008, 9:53 pm

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby km2357 » May 10th, 2008, 3:45 pm

RATS! And it's gone so smoothly up to this point. When I try to delete the files in C:\Windows\Temp\ I get "...Access denied. Make sure disk is not full or write protected and that file is not currently in use."


As I said in my previous post, those .tmp files are harmless, so you can keep them on your computer without any ill effects. If you want to get rid of them, try running ATF Cleaner again and make that Windows Temp under Main is selected when you run ATF Cleaner and it should delete those files.

Also, I can't find Firefox. I was never aware of anyone using it. I can find a few items using "search", and found a bookmark to mozilla's site. I deleted that and did another search and come up with nothing.


Since Firefox is no longer on your computer, it may once have been and someone uninstalled it, let's do this to get rid of the infected cache:

Reconfigure Windows XP to show hidden files:
To enable the viewing of Hidden files follow these steps:


  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
  • Now your computer is configured to show all hidden files.

Be sure to re-hide your files once you are finished cleaning your computer.


Using Windows Explorer, find and delete the following folder:

C:\Documents and Settings\John\Application Data\Mozilla

Empty your Recycle Bin.

Let me know how things went.
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3206
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby cindyv10 » May 10th, 2008, 5:47 pm

By George, I think she's got it!

Everything's working fine. Any suggestions for preventive measures?
cindyv10
Active Member
 
Posts: 11
Joined: May 3rd, 2008, 9:53 pm

Re: Cindyv10 logfile - what's wrong w/my computer?

Unread postby km2357 » May 11th, 2008, 1:22 am

Please take the time to read my All Clean Post.

Please follow these simple steps in order to keep your computer clean and secure:
  • This is a good time to clear your existing system restore points and establish a new clean restore point:
    • Go to Start > All Programs > Accessories > System Tools > System Restore
    • Select Create a restore point, and Ok it.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and OK it.
    • This will remove all restore points except the new one you just created.
    .

    Clearing your restore points is not something you should do on a regular basis. Normally, this process only needs to be done after clearing out an infestation of malware.

  • Make your Internet Explorer more secure This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub frames across different domains to Prompt
    5. When all these settings have been made, click on the OK button.
    6. If it asks you if you want to save the settings, press the Yes button.
    7. Next press the Apply button and then the OK to exit the Internet Properties page.
    Set correct settings for files that should be hidden in Windows XP
    • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
    • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
    • If unchecked please checkHide protected operating system files (Recommended)
    • If necessary check "Display content of system folders"
    • If necessary Uncheck Hide file extensions for known file types.
    • Click OK
    • Use An Antivirus Software and Keep It Updated - It is very important that your computer has an antivirus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a day. If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out.
    • Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
      1. Click the start button on the task bar at the bottom of your screen
      2. Click run
      3. In the dialog box, type services.msc
      4. hit enter, then locate dns client
      5. Highlight it, then doubleclick it.
      6. On the dropdown box, change the setting from automatic to manual.
      7. Click ok..
    • Use an alternative instant messenger program.Trillian and Miranda IM These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
    • Please read Tony Klein's excellent article: How I got Infected in the First Place
    • Please read Understanding Spyware, Browser Hijackers, and Dialers
    • Please read Simple and easy ways to keep your computer safe and secure on the Internet
    • If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox or
      Opera.
      If you decide to use either FireFox or Opera, it is very important that you keep them up to date and check frequently for updates of the browser of your choice.
    • Update all these programs regularly Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
    • If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back.
Follow these steps and your potential for being infected again will reduce dramatically.

Here's a good website to read about Malware prevention:

http://users.telenet.be/bluepatchy/miek ... ntion.html

Good luck!


Please reply one last time so that I know you have read my post and this thread can be closed.
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3206
Joined: January 30th, 2007, 2:48 pm
Location: California
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 262 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware