Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Here is my Hijackthis file. Please help

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 15th, 2009, 11:15 pm

Here is my latest log file. My computer is very much bogged down. Thanks in advance for your help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:38 PM, on 6/15/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\PayPal\PayPal Plug-In\RBroker.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/mpfplus/en-us ... popup=true
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: FCTBPos00Pos - {A1023BB9-453C-463F-9288-56AE96C52807} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: (no name) - {BB0CBE93-CD99-45B9-BF11-291F1B260698} - (no file)
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O3 - Toolbar: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [PC ScanAndSweep] C:\Program Files\Ascentive\PC ScanAndSweep\PCScanAndSweep.exe -m
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Jennifer')
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Jennifer')
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User 'Jennifer')
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1009\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Benjamin')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://www.cnn.com/diskless/bin/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsup ... gctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInCon ... ontrol.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{78F2A078-1F75-4C31-B962-0CE047F7C5E3}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 13267 bytes
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm
Advertisement
Register to Remove

Re: Here is my Hijackthis file. Please help

Unread postby km2357 » June 18th, 2009, 2:19 pm

Hello and welcome to Malware Removal.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.

Sorry for the delay in replying, the forum is very busy. If you still need help, please post a fresh HiJackThis Log
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3007
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 19th, 2009, 6:17 am

Yes, I still need help. Here is the fresh Hijack This log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:16:18 AM, on 6/19/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\PayPal\PayPal Plug-In\RBroker.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/mpfplus/en-us ... popup=true
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: FCTBPos00Pos - {A1023BB9-453C-463F-9288-56AE96C52807} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: (no name) - {BB0CBE93-CD99-45B9-BF11-291F1B260698} - (no file)
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O3 - Toolbar: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [PC ScanAndSweep] C:\Program Files\Ascentive\PC ScanAndSweep\PCScanAndSweep.exe -m
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Jennifer')
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Jennifer')
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User 'Jennifer')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://www.cnn.com/diskless/bin/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsup ... gctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInCon ... ontrol.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{78F2A078-1F75-4C31-B962-0CE047F7C5E3}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 12861 bytes
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm

Re: Here is my Hijackthis file. Please help

Unread postby km2357 » June 19th, 2009, 2:36 pm

IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

LimeWire

I'd like you to read the MRU policy for P2P Programs.

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

Please run a new HJT scan when finished and post the log back here.
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3007
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 19th, 2009, 7:06 pm

Limewire removed...new hijack file follows:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:05:36 PM, on 6/19/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\PayPal\PayPal Plug-In\RBroker.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=del ... channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/mpfplus/en-us ... popup=true
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: FCTBPos00Pos - {A1023BB9-453C-463F-9288-56AE96C52807} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: (no name) - {BB0CBE93-CD99-45B9-BF11-291F1B260698} - (no file)
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O3 - Toolbar: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [PC ScanAndSweep] C:\Program Files\Ascentive\PC ScanAndSweep\PCScanAndSweep.exe -m
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Jennifer')
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Jennifer')
O4 - HKUS\S-1-5-21-3412372317-1838671817-1207155025-1007\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User 'Jennifer')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://www.cnn.com/diskless/bin/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsup ... gctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInCon ... ontrol.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{78F2A078-1F75-4C31-B962-0CE047F7C5E3}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 12854 bytes
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm

Re: Here is my Hijackthis file. Please help

Unread postby km2357 » June 20th, 2009, 12:21 am

Step # 1: Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.



Step # 2: Download and Run ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

*Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

When finished, it shall produce a log for you. Please include the Uninstall List,C:\ComboFix.txt and a fresh HiJackThis Log in your next reply.

Use multiple posts if you can't fit everything into one post.
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3007
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 21st, 2009, 7:43 am

3ivx MPEG-4 5.0.3 (remove only)
725plc32
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 2.0
Adobe Photoshop Elements 4.0
Adobe Premiere Elements 2.0
Adobe Reader 8.1.2
Adobe Shockwave Player 11
America Online (Choose which version to remove)
AnswerWorks 5.0 English Runtime
AOL Coach Version 1.0(Build:20040229.1 en)
AOL Connectivity Services
AOLIcon
AppCore
Apple Mobile Device Support
Apple Software Update
ATI Control Panel
ATI Display Driver
Bonjour
ccCommon
ccCommon
Charter High-Speed™ Self-Installation
CheckIt Diagnostics
CinepPlayer 30 Update
Component Framework
Conexant D850 56K V.9x DFVc Modem
Connection Keep Alive
Critical Update for Windows Media Player 11 (KB959772)
CSTextControl Update
Cucusoft DVD to iPod + iPod Video Converter Suite 7.21.7.15
Dell CinePlayer
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Media Experience
Dell Support Center (Support Software)
DellSupport
DHCP Convertor
Digital Content Portal
Digital Line Detect
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Documentation & Support Launcher
DOM
Driver Robot
EducateU
ELIcon
eMusic Toolbar
ffdshow (remove only)
FlipShare
Games, Music, & Photos Launcher
Get High Speed Internet!
Google Desktop
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB952287)
Intel(R) PRO Network Connections Drivers
Intel(R) PROSet for Wired Connections
Internet Service Offers Launcher
iTunes
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 3
Java 2 Runtime Environment, SE v1.4.2_03
Java(TM) 6 Update 11
Learn2 Player (Uninstall Only)
LiveUpdate (Symantec Corporation)
LiveUpdate (Symantec Corporation)
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Outlook 2003 with Business Contact Manager Update
Microsoft Office Small Business Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MobileMe Control Panel
Modem Helper
MSN
MSRedist
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Musicmatch for Windows Media Player
Musicmatch® Jukebox
My Print Boutique 3
Nero Suite
NetWaiting
NetZeroInstallers
Norton AntiVirus
Norton AntiVirus (Symantec Corporation)
Norton AntiVirus Help
Norton Cleanup
Norton Protection Center
Norton Protection Center
Norton SystemWorks
Norton SystemWorks
Norton SystemWorks
Norton SystemWorks (Symantec Corporation)
Norton Utilities
PayPal Plug-In
PC SpeedScan Pro
PowerDVD
Quicken 2009
QuickTime
RealPlayer Basic
Roxio DLA
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Safari
Search Assist
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Sonic Activation Module
Sonic Update Manager
SPBBC 32bit
Spy Sweeper
Susan G. Komen for the Cure® Toolbar 1.409
Symantec Technical Support Web Controls
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
URL Assistant
Viewpoint Media Player
WD Backup
WD Diagnostics
WD Firewire HID Driver
WebCyberCoach 3.2 Dell
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 21st, 2009, 8:40 am

ComboFix 09-06-20.04 - Tom 06/21/2009 6:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.425 [GMT -5:00]
Running from: c:\documents and settings\Tom\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: Norton AntiVirus *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\NPROTECT\00000000
c:\recycler\NPROTECT\00000001
c:\recycler\NPROTECT\00000002.dat
c:\recycler\NPROTECT\00000003
c:\recycler\NPROTECT\00000004
c:\recycler\NPROTECT\00000005
c:\recycler\NPROTECT\00000006
c:\recycler\NPROTECT\00000009.DAT
c:\recycler\NPROTECT\00000010
c:\recycler\NPROTECT\00000011
c:\recycler\NPROTECT\00000012
c:\recycler\NPROTECT\00000013
c:\recycler\NPROTECT\00000014
c:\recycler\NPROTECT\00000015
c:\recycler\NPROTECT\00000016
c:\recycler\NPROTECT\00000017
c:\recycler\NPROTECT\00000018
c:\recycler\NPROTECT\00000021
c:\recycler\NPROTECT\00000022.DAT
c:\recycler\NPROTECT\00000023
c:\recycler\NPROTECT\00000024
c:\recycler\NPROTECT\00000025
c:\recycler\NPROTECT\00000026
c:\recycler\NPROTECT\00000027
c:\recycler\NPROTECT\00000028
c:\recycler\NPROTECT\00000029
c:\recycler\NPROTECT\00000030
c:\recycler\NPROTECT\00000031
c:\recycler\NPROTECT\00000032
c:\recycler\NPROTECT\00000033
c:\recycler\NPROTECT\00000034
c:\recycler\NPROTECT\00000035
c:\recycler\NPROTECT\00000036
c:\recycler\NPROTECT\00000037
c:\recycler\NPROTECT\00000038
c:\recycler\NPROTECT\00000039
c:\recycler\NPROTECT\00000040
c:\recycler\NPROTECT\00000041
c:\recycler\NPROTECT\00000042
c:\recycler\NPROTECT\00000045
c:\recycler\NPROTECT\00000046
c:\recycler\NPROTECT\00000047
c:\recycler\NPROTECT\00000048
c:\recycler\NPROTECT\00000049
c:\recycler\NPROTECT\00000050
c:\recycler\NPROTECT\00000051
c:\recycler\NPROTECT\00000052
c:\recycler\NPROTECT\00000053
c:\recycler\NPROTECT\00000054
c:\recycler\NPROTECT\00000055
c:\recycler\NPROTECT\00000056
c:\recycler\NPROTECT\00000057
c:\recycler\NPROTECT\00000058
c:\recycler\NPROTECT\00000060
c:\recycler\NPROTECT\00000061
c:\recycler\NPROTECT\00000062
c:\recycler\NPROTECT\00000065
c:\recycler\NPROTECT\00000066
c:\recycler\NPROTECT\00000067
c:\recycler\NPROTECT\00000068
c:\recycler\NPROTECT\00000070
c:\recycler\NPROTECT\00000072
c:\recycler\NPROTECT\00000073
c:\recycler\NPROTECT\00000074
c:\recycler\NPROTECT\00000077
c:\recycler\NPROTECT\00000078
c:\recycler\NPROTECT\00000079
c:\recycler\NPROTECT\00000080
c:\recycler\NPROTECT\00000081
c:\recycler\NPROTECT\00000082
c:\recycler\NPROTECT\00000083
c:\recycler\NPROTECT\00000084
c:\recycler\NPROTECT\00000085
c:\recycler\NPROTECT\00000087
c:\recycler\NPROTECT\00000088
c:\recycler\NPROTECT\00000089
c:\recycler\NPROTECT\00000090
c:\recycler\NPROTECT\00000092
c:\recycler\NPROTECT\00000093
c:\recycler\NPROTECT\00000094
c:\recycler\NPROTECT\00000096
c:\recycler\NPROTECT\00000097
c:\recycler\NPROTECT\00000098
c:\recycler\NPROTECT\00000099
c:\recycler\NPROTECT\00000100
c:\recycler\NPROTECT\00000101
c:\recycler\NPROTECT\00000103
c:\recycler\NPROTECT\00000104
c:\recycler\NPROTECT\00000105
c:\recycler\NPROTECT\00000106
c:\recycler\NPROTECT\00000107
c:\recycler\NPROTECT\00000109
c:\recycler\NPROTECT\00000110
c:\recycler\NPROTECT\00000111
c:\recycler\NPROTECT\00000112
c:\recycler\NPROTECT\00000113
c:\recycler\NPROTECT\00000114
c:\recycler\NPROTECT\00000115
c:\recycler\NPROTECT\00000116
c:\recycler\NPROTECT\00000120
c:\recycler\NPROTECT\00000121.dat
c:\recycler\NPROTECT\00000122.dat
c:\recycler\NPROTECT\00000123.dat
c:\recycler\NPROTECT\00000124.dat
c:\recycler\NPROTECT\00000125
c:\recycler\NPROTECT\00000126
c:\recycler\NPROTECT\00000127
c:\recycler\NPROTECT\00000128
c:\recycler\NPROTECT\00000129
c:\recycler\NPROTECT\00000130
c:\recycler\NPROTECT\00000131
c:\recycler\NPROTECT\00000132
c:\recycler\NPROTECT\00000133
c:\recycler\NPROTECT\00000134
c:\recycler\NPROTECT\00000135
c:\recycler\NPROTECT\00000137
c:\recycler\NPROTECT\00000141
c:\recycler\NPROTECT\00000142.bat
c:\recycler\NPROTECT\00000143
c:\recycler\NPROTECT\00000144
c:\recycler\NPROTECT\00000145
c:\recycler\NPROTECT\00000146
c:\recycler\NPROTECT\00000147
c:\recycler\NPROTECT\00000148
c:\recycler\NPROTECT\00000149
c:\recycler\NPROTECT\00000151
c:\recycler\NPROTECT\00000152
c:\recycler\NPROTECT\00000154
c:\recycler\NPROTECT\00000155
c:\recycler\NPROTECT\00000156
c:\recycler\NPROTECT\00000159
c:\recycler\NPROTECT\00000160
c:\recycler\NPROTECT\00000161
c:\recycler\NPROTECT\00000162
c:\recycler\NPROTECT\00000163
c:\recycler\NPROTECT\00000164
c:\recycler\NPROTECT\00000165
c:\recycler\NPROTECT\00000167
c:\recycler\NPROTECT\00000168
c:\recycler\NPROTECT\00000169
c:\recycler\NPROTECT\00000170
c:\recycler\NPROTECT\00000171
c:\recycler\NPROTECT\00000172
c:\recycler\NPROTECT\00000173
c:\recycler\NPROTECT\00000174
c:\recycler\NPROTECT\00000175
c:\recycler\NPROTECT\00000176
c:\recycler\NPROTECT\00000177
c:\recycler\NPROTECT\00000178
c:\recycler\NPROTECT\00000179
c:\recycler\NPROTECT\00000180
c:\recycler\NPROTECT\00000181
c:\recycler\NPROTECT\00000182
c:\recycler\NPROTECT\00000183
c:\recycler\NPROTECT\00000184
c:\recycler\NPROTECT\00000185
c:\recycler\NPROTECT\00000186
c:\recycler\NPROTECT\00000187
c:\recycler\NPROTECT\00000188
c:\recycler\NPROTECT\00000189
c:\recycler\NPROTECT\00000190
c:\recycler\NPROTECT\00000191
c:\recycler\NPROTECT\00000192
c:\recycler\NPROTECT\00000193
c:\recycler\NPROTECT\00000194
c:\recycler\NPROTECT\00000195
c:\recycler\NPROTECT\00000196
c:\recycler\NPROTECT\00000198
c:\recycler\NPROTECT\00000199
c:\recycler\NPROTECT\00000200
c:\recycler\NPROTECT\00000201
c:\recycler\NPROTECT\00000203
c:\recycler\NPROTECT\00000206
c:\recycler\NPROTECT\00000207
c:\recycler\NPROTECT\00000208
c:\recycler\NPROTECT\00000209
c:\recycler\NPROTECT\00000210
c:\recycler\NPROTECT\00000211.dat
c:\recycler\NPROTECT\00000212
c:\recycler\NPROTECT\00000213.bad
c:\recycler\NPROTECT\00000214
c:\recycler\NPROTECT\00000215
c:\recycler\NPROTECT\00000216
c:\recycler\NPROTECT\00000217
c:\recycler\NPROTECT\00000218
c:\recycler\NPROTECT\00000224.md5
c:\recycler\NPROTECT\00000231
c:\recycler\NPROTECT . . . . failed to delete
c:\recycler\NPROTECT\00000000.DAT
c:\recycler\NPROTECT\00000001.DAT
c:\recycler\NPROTECT\00000002
c:\recycler\NPROTECT\00000003
c:\recycler\NPROTECT\00000004
c:\recycler\NPROTECT\00000005
c:\recycler\NPROTECT\00000006
c:\recycler\NPROTECT\00000007
c:\recycler\NPROTECT\00000009
c:\recycler\NPROTECT\00000011
c:\recycler\NPROTECT\00000012
c:\recycler\NPROTECT\00000013
c:\recycler\NPROTECT\00000014
c:\recycler\NPROTECT\00196020.ZIP
c:\recycler\NPROTECT\00196024.ZIP
c:\recycler\NPROTECT\00196027.ZIP
c:\recycler\NPROTECT\00196031.ZIP
c:\recycler\NPROTECT\00196035.ZIP
c:\recycler\NPROTECT\00196039.ZIP
c:\recycler\NPROTECT\00196042.ZIP
c:\recycler\NPROTECT\00196046.ZIP
c:\recycler\NPROTECT\00196049.ZIP
c:\recycler\NPROTECT\00196055.ZIP
c:\recycler\NPROTECT\00196059.ZIP
c:\recycler\NPROTECT\00196065.ZIP
c:\recycler\NPROTECT\00196069.ZIP
c:\recycler\NPROTECT\00196073.ZIP
c:\recycler\NPROTECT\00196077.ZIP
c:\recycler\NPROTECT\00196081.ZIP
c:\recycler\NPROTECT\00196084.ZIP
c:\recycler\NPROTECT\00196090.ZIP
c:\recycler\NPROTECT\00196096.ZIP
c:\recycler\NPROTECT\00196099.ZIP
c:\recycler\NPROTECT\00196105.ZIP
c:\recycler\NPROTECT\00196109.ZIP
c:\recycler\NPROTECT\00196112.ZIP
c:\recycler\NPROTECT\00196118.ZIP
c:\recycler\NPROTECT\00196124.ZIP
c:\recycler\NPROTECT\00196130.ZIP
c:\recycler\NPROTECT\00196134.ZIP
c:\recycler\NPROTECT\00196138.ZIP
c:\recycler\NPROTECT\00196142.ZIP
c:\recycler\NPROTECT\00196146.ZIP
c:\recycler\NPROTECT\00196149.ZIP
c:\recycler\NPROTECT\00196153.ZIP
c:\recycler\NPROTECT\00196156.ZIP
c:\recycler\NPROTECT\00196160.ZIP
c:\recycler\NPROTECT\00196166.ZIP
c:\recycler\NPROTECT\00196170.ZIP
c:\recycler\NPROTECT\00196174.ZIP
c:\recycler\NPROTECT\00196177.ZIP
c:\recycler\NPROTECT\00196180.ZIP
c:\recycler\NPROTECT\00196184.ZIP
c:\recycler\NPROTECT\00196187.ZIP
c:\recycler\NPROTECT\00196193.ZIP
c:\recycler\NPROTECT\00196196.ZIP
c:\recycler\NPROTECT\00196199.ZIP
c:\recycler\NPROTECT\00196202.ZIP
c:\recycler\NPROTECT\00196206.ZIP
c:\recycler\NPROTECT\00196209.ZIP
c:\recycler\NPROTECT\00196212.ZIP
c:\recycler\NPROTECT\00196215.ZIP
c:\recycler\NPROTECT\00196218.ZIP
c:\recycler\NPROTECT\00196221.ZIP
c:\recycler\NPROTECT\00196224.ZIP
c:\recycler\NPROTECT\00196228.ZIP
c:\recycler\NPROTECT\00196232.ZIP
c:\recycler\NPROTECT\00196235.ZIP
c:\recycler\NPROTECT\00196239.ZIP
c:\recycler\NPROTECT\00196242.ZIP
c:\recycler\NPROTECT\00196246.ZIP
c:\recycler\NPROTECT\00196250.ZIP
c:\recycler\NPROTECT\00196253.ZIP
c:\recycler\NPROTECT\00196256.ZIP
c:\recycler\NPROTECT\00196260.ZIP
c:\recycler\NPROTECT\00196264.ZIP
c:\recycler\NPROTECT\00196268.ZIP
c:\recycler\NPROTECT\00196274.ZIP
c:\recycler\NPROTECT\00196277.ZIP
c:\recycler\NPROTECT\00196281.ZIP
c:\recycler\NPROTECT\00196285.ZIP
c:\recycler\NPROTECT\00196289.ZIP
c:\recycler\NPROTECT\00196292.ZIP
c:\recycler\NPROTECT\00196296.ZIP
c:\recycler\NPROTECT\00196300.ZIP
c:\recycler\NPROTECT\00196304.ZIP
c:\recycler\NPROTECT\00196307.ZIP
c:\recycler\NPROTECT\00196313.ZIP
c:\recycler\NPROTECT\00196316.ZIP
c:\recycler\NPROTECT\00196319.ZIP
c:\recycler\NPROTECT\00196323.ZIP
c:\recycler\NPROTECT\00196328.ZIP
c:\recycler\NPROTECT\00196334.ZIP
c:\recycler\NPROTECT\00196338.ZIP
c:\recycler\NPROTECT\00196342.ZIP
c:\recycler\NPROTECT\00196346.ZIP
c:\recycler\NPROTECT\00196350.ZIP
c:\recycler\NPROTECT\00196353.ZIP
c:\recycler\NPROTECT\00196356.ZIP
c:\recycler\NPROTECT\00196360.ZIP
c:\recycler\NPROTECT\00196364.ZIP
c:\recycler\NPROTECT\00196367.ZIP
c:\recycler\NPROTECT\00196370.ZIP
c:\recycler\NPROTECT\00196373.ZIP
c:\recycler\NPROTECT\00196377.ZIP
c:\recycler\NPROTECT\00196383.ZIP
c:\recycler\NPROTECT\00196387.ZIP
c:\recycler\NPROTECT\00196391.ZIP
c:\recycler\NPROTECT\00196395.ZIP
c:\recycler\NPROTECT\00196400.ZIP
c:\recycler\NPROTECT\00196404.ZIP
c:\recycler\NPROTECT\00196408.ZIP
c:\recycler\NPROTECT\00196412.ZIP
c:\recycler\NPROTECT\00196418.ZIP
c:\recycler\NPROTECT\00196422.ZIP
c:\recycler\NPROTECT\00196428.ZIP
c:\recycler\NPROTECT\00196434.ZIP
c:\recycler\NPROTECT\00196438.ZIP
c:\recycler\NPROTECT\00196441.ZIP
c:\recycler\NPROTECT\00196444.ZIP
c:\recycler\NPROTECT\00196448.ZIP
c:\recycler\NPROTECT\00196452.ZIP
c:\recycler\NPROTECT\00196456.ZIP
c:\recycler\NPROTECT\00196460.ZIP
c:\recycler\NPROTECT\00196464.ZIP
c:\recycler\NPROTECT\00196468.ZIP
c:\recycler\NPROTECT\00196472.ZIP
c:\recycler\NPROTECT\00196478.ZIP
c:\recycler\NPROTECT\00196484.ZIP
c:\recycler\NPROTECT\00196488.ZIP
c:\recycler\NPROTECT\00196492.ZIP
c:\recycler\NPROTECT\00196498.ZIP
c:\recycler\NPROTECT\00196504.ZIP
c:\recycler\NPROTECT\00196507.ZIP
c:\recycler\NPROTECT\00196510.ZIP
c:\recycler\NPROTECT\00196516.ZIP
c:\recycler\NPROTECT\00196520.ZIP
c:\recycler\NPROTECT\00196524.ZIP
c:\recycler\NPROTECT\00196530.ZIP
c:\recycler\NPROTECT\00196533.ZIP
c:\recycler\NPROTECT\00196537.ZIP
c:\recycler\NPROTECT\00196543.ZIP
c:\recycler\NPROTECT\00196546.ZIP
c:\recycler\NPROTECT\00196550.ZIP
c:\recycler\NPROTECT\00196554.ZIP
c:\recycler\NPROTECT\00196558.ZIP
c:\recycler\NPROTECT\00196561.ZIP
c:\recycler\NPROTECT\00196564.ZIP
c:\recycler\NPROTECT\00196567.ZIP
c:\recycler\NPROTECT\00196571.ZIP
c:\recycler\NPROTECT\00196575.ZIP
c:\recycler\NPROTECT\00196578.ZIP
c:\recycler\NPROTECT\00196583.ZIP
c:\recycler\NPROTECT\00196586.ZIP
c:\recycler\NPROTECT\00196590.ZIP
c:\recycler\NPROTECT\00196593.ZIP
c:\recycler\NPROTECT\00196597.ZIP
c:\recycler\NPROTECT\00196600.ZIP
c:\recycler\NPROTECT\00196604.ZIP
c:\recycler\NPROTECT\00196608.ZIP
c:\recycler\NPROTECT\00196612.ZIP
c:\recycler\NPROTECT\00196616.ZIP
c:\recycler\NPROTECT\00196620.ZIP
c:\recycler\NPROTECT\00196626.ZIP
c:\recycler\NPROTECT\00196629.ZIP
c:\recycler\NPROTECT\00196632.ZIP
c:\recycler\NPROTECT\00196636.ZIP
c:\recycler\NPROTECT\00196639.ZIP
c:\recycler\NPROTECT\00196650.XML
c:\recycler\NPROTECT\00196654.CAB
c:\recycler\NPROTECT\00196660.edb
c:\recycler\NPROTECT\00196667.XML
c:\recycler\NPROTECT\00196678.XML
c:\recycler\NPROTECT\00196691.edb
c:\recycler\NPROTECT\00196693.LOG
c:\recycler\NPROTECT\00196694.LOG
c:\recycler\NPROTECT\00196704.XML
c:\recycler\NPROTECT\00196705.XML
c:\recycler\NPROTECT\00196716.XML
c:\recycler\NPROTECT\00196733.XML
c:\recycler\NPROTECT\00196759.TXT
c:\recycler\NPROTECT\00196797.TXT
c:\recycler\NPROTECT\00196805.TXT
c:\recycler\NPROTECT\00196807.TXT
c:\recycler\NPROTECT\00196835.TXT
c:\recycler\NPROTECT\00196836.TXT
c:\recycler\NPROTECT\00196840.TXT
c:\recycler\NPROTECT\00196868.TXT
c:\recycler\NPROTECT\00196869.TXT
c:\recycler\NPROTECT\00196870.TXT
c:\recycler\NPROTECT\00196908.INI
c:\recycler\NPROTECT\00196909.SQL
c:\recycler\NPROTECT\00196910.SQL
c:\recycler\NPROTECT\00196911.SQL
c:\recycler\NPROTECT\00196916.SQL
c:\recycler\NPROTECT\00196917.SQL
c:\recycler\NPROTECT\00196918.SQL
c:\recycler\NPROTECT\00196919.SQL
c:\recycler\NPROTECT\00196920.SQL
c:\recycler\NPROTECT\00196921.SQL
c:\recycler\NPROTECT\00196922.SQL
c:\recycler\NPROTECT\00196923.SQL
c:\recycler\NPROTECT\00196924.SQL
c:\recycler\NPROTECT\00196925.SQL
c:\recycler\NPROTECT\00196926.SQL
c:\recycler\NPROTECT\00196927.SQL
c:\recycler\NPROTECT\00196928.SQL
c:\recycler\NPROTECT\00196929.SQL
c:\recycler\NPROTECT\00196930.SQL
c:\recycler\NPROTECT\00196931.PRO
c:\recycler\NPROTECT\00196932.SQL
c:\recycler\NPROTECT\00196934.XML
c:\recycler\NPROTECT\00196937
c:\recycler\NPROTECT\00196938
c:\recycler\NPROTECT\00196939
c:\recycler\NPROTECT\00196940.DAT
c:\recycler\NPROTECT\00196941.DAT
c:\recycler\NPROTECT\00196942.DAT
c:\recycler\NPROTECT\00196943
c:\recycler\NPROTECT\00196954
c:\recycler\NPROTECT\00196965
c:\recycler\NPROTECT\00196966
c:\recycler\NPROTECT\00196967
c:\recycler\NPROTECT\00196968
c:\recycler\NPROTECT\00196969
c:\recycler\NPROTECT\00196970
c:\recycler\NPROTECT\00196971
c:\recycler\NPROTECT\00196972.PRO
c:\recycler\NPROTECT\00196973.log
c:\recycler\NPROTECT\00196974.BAC
c:\recycler\NPROTECT\00196975.SCR
c:\recycler\NPROTECT\00196976.PRO
c:\recycler\NPROTECT\00196977.lck
c:\recycler\NPROTECT\00196980
c:\recycler\NPROTECT\00196998.XML
c:\recycler\NPROTECT\00197010.C$$
c:\recycler\NPROTECT\00197011.cfg
c:\recycler\NPROTECT\00197066.XML
c:\recycler\NPROTECT\00197072.txt
c:\recycler\NPROTECT\00197073.dat
c:\recycler\NPROTECT\00197074.txt
c:\recycler\NPROTECT\00197080.XML
c:\recycler\NPROTECT\00197096.grd
c:\recycler\NPROTECT\00197097.sig
c:\recycler\NPROTECT\00197098.wlt
c:\recycler\NPROTECT\00197099.grd
c:\recycler\NPROTECT\00197100.sig
c:\recycler\NPROTECT\00197101.grd
c:\recycler\NPROTECT\00197102.sig
c:\recycler\NPROTECT\00197103.wlt
c:\recycler\NPROTECT\00197104.dat
c:\recycler\NPROTECT\00197105.grd
c:\recycler\NPROTECT\00197106.sig
c:\recycler\NPROTECT\00197107.wlt
c:\recycler\NPROTECT\00197108.txt
c:\recycler\NPROTECT\00197109.grd
c:\recycler\NPROTECT\00197110.sig
c:\recycler\NPROTECT\00197111.dat
c:\recycler\NPROTECT\00197112.997
c:\recycler\NPROTECT\00197113.998
c:\recycler\NPROTECT\00197114.999
c:\recycler\NPROTECT\00197115.scr
c:\recycler\NPROTECT\00197116.txt
c:\recycler\NPROTECT\00197117.dis
c:\recycler\NPROTECT\00197118.DIS
c:\recycler\NPROTECT\00197119.DIS
c:\recycler\NPROTECT\00197120.grd
c:\recycler\NPROTECT\00197121.sig
c:\recycler\NPROTECT\00197129.XML
c:\recycler\NPROTECT\00197130.XML
c:\recycler\NPROTECT\00197143.CAB
c:\recycler\NPROTECT\00197149.edb
c:\recycler\NPROTECT\00197150.log
c:\recycler\NPROTECT\00197151.XML
c:\recycler\NPROTECT\00197170.XML
c:\recycler\NPROTECT\00197203.TXT
c:\recycler\NPROTECT\00197240.TXT
c:\recycler\NPROTECT\00197256.TXT
c:\recycler\NPROTECT\00197287.TXT
c:\recycler\NPROTECT\00197293.TXT
c:\recycler\NPROTECT\00197319.TXT
c:\recycler\NPROTECT\00197333.TXT
c:\recycler\NPROTECT\00197336.TXT
c:\recycler\NPROTECT\00197357.TXT
c:\recycler\NPROTECT\00197383.TXT
c:\recycler\NPROTECT\00197384.TXT
c:\recycler\NPROTECT\00197385.TXT
c:\recycler\NPROTECT\00197386.TXT
c:\recycler\NPROTECT\00197389.TXT
c:\recycler\NPROTECT\00197393.sxx
c:\recycler\NPROTECT\00197394.TXT
c:\recycler\NPROTECT\00197420.TXT
c:\recycler\NPROTECT\00197451.TXT
c:\recycler\NPROTECT\00197472.TXT
c:\recycler\NPROTECT\00197493.TXT
c:\recycler\NPROTECT\00197509.TXT
c:\recycler\NPROTECT\00197518.TXT
c:\recycler\NPROTECT\00197520.TXT
c:\recycler\NPROTECT\00197522.TXT
c:\recycler\NPROTECT\00197523.TXT
c:\recycler\NPROTECT\00197524.TXT
c:\recycler\NPROTECT\00197525.TXT
c:\recycler\NPROTECT\00197526.TXT
c:\recycler\NPROTECT\00197530.TXT
c:\recycler\NPROTECT\00197546.TXT
c:\recycler\NPROTECT\00197549.TXT
c:\recycler\NPROTECT\00197550.TXT
c:\recycler\NPROTECT\00197551.TXT
c:\recycler\NPROTECT\00197552.sxx
c:\recycler\NPROTECT\00197558.TXT
c:\recycler\NPROTECT\00197589.TXT
c:\recycler\NPROTECT\00197591.TXT
c:\recycler\NPROTECT\00197601.TXT
c:\recycler\NPROTECT\00197617.TXT
c:\recycler\NPROTECT\00197633.TXT
c:\recycler\NPROTECT\00197634.TXT
c:\recycler\NPROTECT\00197640.TXT
c:\recycler\NPROTECT\00197651.TXT
c:\recycler\NPROTECT\00197652.TXT
c:\recycler\NPROTECT\00197653.TXT
c:\recycler\NPROTECT\00197654.TXT
c:\recycler\NPROTECT\00197658.TXT
c:\recycler\NPROTECT\00197681.TXT
c:\recycler\NPROTECT\00197712.TXT
c:\recycler\NPROTECT\00197718.TXT
c:\recycler\NPROTECT\00197739.TXT
c:\recycler\NPROTECT\00197752.TXT
c:\recycler\NPROTECT\00197753.TXT
c:\recycler\NPROTECT\00197769.TXT
c:\recycler\NPROTECT\00197770.TXT
c:\recycler\NPROTECT\00197776.TXT
c:\recycler\NPROTECT\00197778.TXT
c:\recycler\NPROTECT\00197781.TXT
c:\recycler\NPROTECT\00197784.TXT
c:\recycler\NPROTECT\00197785.TXT
c:\recycler\NPROTECT\00197789.sxx
c:\recycler\NPROTECT\00197792.TXT
c:\recycler\NPROTECT\00197818.TXT
c:\recycler\NPROTECT\00197819.TXT
c:\recycler\NPROTECT\00197835.TXT
c:\recycler\NPROTECT\00197856.TXT
c:\recycler\NPROTECT\00197867.TXT
c:\recycler\NPROTECT\00197889.TXT
c:\recycler\NPROTECT\00197890.TXT
c:\recycler\NPROTECT\00197891.TXT
c:\recycler\NPROTECT\00197892.TXT
c:\recycler\NPROTECT\00197893.TXT
c:\recycler\NPROTECT\00197919.TXT
c:\recycler\NPROTECT\00197921.TXT
c:\recycler\NPROTECT\00197936.TXT
c:\recycler\NPROTECT\00197947.TXT
c:\recycler\NPROTECT\00197955.TXT
c:\recycler\NPROTECT\00197979.TXT
c:\recycler\NPROTECT\00197990.TXT
c:\recycler\NPROTECT\00198001.TXT
c:\recycler\NPROTECT\00198012.TXT
c:\recycler\NPROTECT\00198013.TXT
c:\recycler\NPROTECT\00198014.TXT
c:\recycler\NPROTECT\00198015.TXT
c:\recycler\NPROTECT\00198016.TXT
c:\recycler\NPROTECT\00198017.TXT
c:\recycler\NPROTECT\00198018.TXT
c:\recycler\NPROTECT\00198024.TXT
c:\recycler\NPROTECT\00198030.TXT
c:\recycler\NPROTECT\00198031.TXT
c:\recycler\NPROTECT\00198057.sxx
c:\recycler\NPROTECT\00198058.TXT
c:\recycler\NPROTECT\00198089.TXT
c:\recycler\NPROTECT\00198105.TXT
c:\recycler\NPROTECT\00198116.TXT
c:\recycler\NPROTECT\00198126.TXT
c:\recycler\NPROTECT\00198153.TXT
c:\recycler\NPROTECT\00198169.TXT
c:\recycler\NPROTECT\00198178.TXT
c:\recycler\NPROTECT\00198181.TXT
c:\recycler\NPROTECT\00198189.TXT
c:\recycler\NPROTECT\00198193.TXT
c:\recycler\NPROTECT\00198219.TXT
c:\recycler\NPROTECT\00198252.TXT
c:\recycler\NPROTECT\00198253.TXT
c:\recycler\NPROTECT\00198257.TXT
c:\recycler\NPROTECT\00198296.TXT
c:\recycler\NPROTECT\00198317.TXT
c:\recycler\NPROTECT\00198339.TXT
c:\recycler\NPROTECT\00198342.TXT
c:\recycler\NPROTECT\00198345.TXT
c:\recycler\NPROTECT\00198346.TXT
c:\recycler\NPROTECT\00198348.TXT
c:\recycler\NPROTECT\00198351.TXT
c:\recycler\NPROTECT\00198354.TXT
c:\recycler\NPROTECT\00198355.TXT
c:\recycler\NPROTECT\00198368.TXT
c:\recycler\NPROTECT\00198382.TXT
c:\recycler\NPROTECT\00198383.sxx
c:\recycler\NPROTECT\00198384.TXT
c:\recycler\NPROTECT\00198387.TXT
c:\recycler\NPROTECT\00198391.TXT
c:\recycler\NPROTECT\00198397.TXT
c:\recycler\NPROTECT\00198398.TXT
c:\recycler\NPROTECT\00198424.TXT
c:\recycler\NPROTECT\00198440.TXT
c:\recycler\NPROTECT\00198451.TXT
c:\recycler\NPROTECT\00198472.TXT
c:\recycler\NPROTECT\00198473.TXT
c:\recycler\NPROTECT\00198484.TXT
c:\recycler\NPROTECT\00198485.TXT
c:\recycler\NPROTECT\00198486.TXT
c:\recycler\NPROTECT\00198487.TXT
c:\recycler\NPROTECT\00198488.TXT
c:\recycler\NPROTECT\00198489.TXT
c:\recycler\NPROTECT\00198490.TXT
c:\recycler\NPROTECT\00198491.TXT
c:\recycler\NPROTECT\00198502.TXT
c:\recycler\NPROTECT\00198503.TXT
c:\recycler\NPROTECT\00198504.TXT
c:\recycler\NPROTECT\00198505.sxx
c:\recycler\NPROTECT\00198506.TXT
c:\recycler\NPROTECT\00198507.TXT
c:\recycler\NPROTECT\00198508.TXT
c:\recycler\NPROTECT\00198534.TXT
c:\recycler\NPROTECT\00198538.TXT
c:\recycler\NPROTECT\00198546.TXT
c:\recycler\NPROTECT\00198572.TXT
c:\recycler\NPROTECT\00198593.TXT
c:\recycler\NPROTECT\00198595.TXT
c:\recycler\NPROTECT\00198605.TXT
c:\recycler\NPROTECT\00198606.TXT
c:\recycler\NPROTECT\00198607.TXT
c:\recycler\NPROTECT\00198608.TXT
c:\recycler\NPROTECT\00198609.TXT
c:\recycler\NPROTECT\00198610.TXT
c:\recycler\NPROTECT\00198616.TXT
c:\recycler\NPROTECT\00198622.TXT
c:\recycler\NPROTECT\00198648.TXT
c:\recycler\NPROTECT\00198649.TXT
c:\recycler\NPROTECT\00198654.TXT
c:\recycler\NPROTECT\00198661.TXT
c:\recycler\NPROTECT\00198678.TXT
c:\recycler\NPROTECT\00198693.TXT
c:\recycler\NPROTECT\00198724.TXT
c:\recycler\NPROTECT\00198738.TXT
c:\recycler\NPROTECT\00198741.TXT
c:\recycler\NPROTECT\00198743.TXT
c:\recycler\NPROTECT\00198746.TXT
c:\recycler\NPROTECT\00198749.TXT
c:\recycler\NPROTECT\00198755.TXT
c:\recycler\NPROTECT\00198761.TXT
c:\recycler\NPROTECT\00198767.TXT
c:\recycler\NPROTECT\00198768.TXT
c:\recycler\NPROTECT\00198769.TXT
c:\recycler\NPROTECT\00198770.TXT
c:\recycler\NPROTECT\00198771.TXT
c:\recycler\NPROTECT\00198772.TXT
c:\recycler\NPROTECT\00198799.TXT
c:\recycler\NPROTECT\00198830.TXT
c:\recycler\NPROTECT\00198861.TXT
c:\recycler\NPROTECT\00198878.TXT
c:\recycler\NPROTECT\00198888.TXT
c:\recycler\NPROTECT\00198914.TXT
c:\recycler\NPROTECT\00198945.TXT
c:\recycler\NPROTECT\00198961.TXT
c:\recycler\NPROTECT\00198967.TXT
c:\recycler\NPROTECT\00198973.TXT
c:\recycler\NPROTECT\00198974.TXT
c:\recycler\NPROTECT\00199000.TXT
c:\recycler\NPROTECT\00199031.TXT
c:\recycler\NPROTECT\00199032.TXT
c:\recycler\NPROTECT\00199033.TXT
c:\recycler\NPROTECT\00199071.DAT
c:\recycler\NPROTECT\00199072.QTC
c:\recycler\NPROTECT\00199073.DAT
c:\recycler\NPROTECT\00199074.DAT
c:\recycler\NPROTECT\00199075.DAT
c:\recycler\NPROTECT\00199076.DAT
c:\recycler\NPROTECT\00199079.EXE
c:\recycler\NPROTECT\00199080.URL
c:\recycler\NPROTECT\00199081.PRO
c:\recycler\NPROTECT\00199082
c:\recycler\NPROTECT\00199083.ser
c:\recycler\NPROTECT\00199084.PRO
c:\recycler\NPROTECT\00199085.JAR
c:\recycler\NPROTECT\00199086.JAR
c:\recycler\NPROTECT\00199087.JAR
c:\recycler\NPROTECT\00199088.JAR
c:\recycler\NPROTECT\00199089.jar
c:\recycler\NPROTECT\00199090.JAR
c:\recycler\NPROTECT\00199091.JAR
c:\recycler\NPROTECT\00199092.JAR
c:\recycler\NPROTECT\00199093.jar
c:\recycler\NPROTECT\00199094.JAR
c:\recycler\NPROTECT\00199095.JAR
c:\recycler\NPROTECT\00199096.JAR
c:\recycler\NPROTECT\00199097.JAR
c:\recycler\NPROTECT\00199098.JAR
c:\recycler\NPROTECT\00199099.JAR
c:\recycler\NPROTECT\00199100
c:\recycler\NPROTECT\00199101.jar
c:\recycler\NPROTECT\00199102.JAR
c:\recycler\NPROTECT\00199103.JAR
c:\recycler\NPROTECT\00199104.JAR
c:\recycler\NPROTECT\00199105.jar
c:\recycler\NPROTECT\00199106.JAR
c:\recycler\NPROTECT\00199107.DLL
c:\recycler\NPROTECT\00199108.DLL
c:\recycler\NPROTECT\00199109.JAR
c:\recycler\NPROTECT\00199110.JAR
c:\recycler\NPROTECT\00199111.JAR
c:\recycler\NPROTECT\00199112.jar
c:\recycler\NPROTECT\00199113.dll
c:\recycler\NPROTECT\00199114.jar
c:\recycler\NPROTECT\00199115.JAR
c:\recycler\NPROTECT\00199116.jar
c:\recycler\NPROTECT\00199117.jar
c:\recycler\NPROTECT\00199118.jar
c:\recycler\NPROTECT\00199119.jar
c:\recycler\NPROTECT\00199120.jar
c:\recycler\NPROTECT\00199121.jar
c:\recycler\NPROTECT\00199122.jar
c:\recycler\NPROTECT\00199123.ico
c:\recycler\NPROTECT\00199124.jar
c:\recycler\NPROTECT\00199125.jar
c:\recycler\NPROTECT\00199126.PRO
c:\recycler\NPROTECT\00199127.jar
c:\recycler\NPROTECT\00199128.JAR
c:\recycler\NPROTECT\00199129.JAR
c:\recycler\NPROTECT\00199130.JAR
c:\recycler\NPROTECT\00199131.JAR
c:\recycler\NPROTECT\00199132.jar
c:\recycler\NPROTECT\00199133.jar
c:\recycler\NPROTECT\00199134.JAR
c:\recycler\NPROTECT\00199135.JAR
c:\recycler\NPROTECT\00199136.jar
c:\recycler\NPROTECT\00199137.JAR
c:\recycler\NPROTECT\00199138.jar
c:\recycler\NPROTECT\00199139.JAR
c:\recycler\NPROTECT\00199140.JAR
c:\recycler\NPROTECT\00199141.DLL
c:\recycler\NPROTECT\00199142.DLL
c:\recycler\NPROTECT\00199143.jar
c:\recycler\NPROTECT\00199144.JAR
c:\recycler\NPROTECT\00199145.exe
c:\recycler\NPROTECT\00199146.ico
c:\recycler\NPROTECT\00199147.ico
c:\recycler\NPROTECT\00199148.img
c:\recycler\NPROTECT\00199149.IMG
c:\recycler\NPROTECT\00199150.gif
c:\recycler\NPROTECT\00199151.js
c:\recycler\NPROTECT\00199152.JS
c:\recycler\NPROTECT\00199153
c:\recycler\NPROTECT\00199154.gif
c:\recycler\NPROTECT\00199155.LNK
c:\recycler\NPROTECT\00199156.log
c:\recycler\NPROTECT\00199157.EXE
c:\recycler\NPROTECT\00199158.log
c:\recycler\NPROTECT\00199159.LNK
c:\recycler\NPROTECT\00199160.LNK
c:\recycler\NPROTECT\00199161.LNK
c:\recycler\NPROTECT\00199185.TXT
c:\recycler\NPROTECT\00199186.TXT
c:\recycler\NPROTECT\00199190.TXT
c:\recycler\NPROTECT\00199203.TXT
c:\recycler\NPROTECT\00199240.DAT
c:\recycler\NPROTECT\00199241.DAT
c:\recycler\NPROTECT\00199242.DAT
c:\recycler\NPROTECT\00199243.DAT
c:\recycler\NPROTECT\00199310.LOG
c:\recycler\NPROTECT\00199326.LOG
c:\recycler\NPROTECT\00199332.XML
c:\recycler\NPROTECT\00199339.XML
c:\recycler\NPROTECT\00199356.ZIP
c:\recycler\NPROTECT\00199360.ZIP
c:\recycler\NPROTECT\00199366.ZIP
c:\recycler\NPROTECT\00199369.ZIP
c:\recycler\NPROTECT\00199372.ZIP
c:\recycler\NPROTECT\00199376.ZIP
c:\recycler\NPROTECT\00199379.ZIP
c:\recycler\NPROTECT\00199382.ZIP
c:\recycler\NPROTECT\00199386.ZIP
c:\recycler\NPROTECT\00199389.ZIP
c:\recycler\NPROTECT\00199393.ZIP
c:\recycler\NPROTECT\00199399.ZIP
c:\recycler\NPROTECT\00199403.ZIP
c:\recycler\NPROTECT\00199407.ZIP
c:\recycler\NPROTECT\00199410.ZIP
c:\recycler\NPROTECT\00199414.ZIP
c:\recycler\NPROTECT\00199418.ZIP
c:\recycler\NPROTECT\00199422.ZIP
c:\recycler\NPROTECT\00199425.ZIP
c:\recycler\NPROTECT\00199429.ZIP
c:\recycler\NPROTECT\00199435.ZIP
c:\recycler\NPROTECT\00199438.ZIP
c:\recycler\NPROTECT\00199441.ZIP
c:\recycler\NPROTECT\00199444.ZIP
c:\recycler\NPROTECT\00199450.ZIP
c:\recycler\NPROTECT\00199456.ZIP
c:\recycler\NPROTECT\00199459.ZIP
c:\recycler\NPROTECT\00199463.ZIP
c:\recycler\NPROTECT\00199466.ZIP
c:\recycler\NPROTECT\00199469.ZIP
c:\recycler\NPROTECT\00199473.ZIP
c:\recycler\NPROTECT\00199479.ZIP
c:\recycler\NPROTECT\00199482.ZIP
c:\recycler\NPROTECT\00199485.ZIP
c:\recycler\NPROTECT\00199489.ZIP
c:\recycler\NPROTECT\00199493.ZIP
c:\recycler\NPROTECT\00199497.ZIP
c:\recycler\NPROTECT\00199500.ZIP
c:\recycler\NPROTECT\00199504.ZIP
c:\recycler\NPROTECT\00199508.ZIP
c:\recycler\NPROTECT\00199511.ZIP
c:\recycler\NPROTECT\00199514.ZIP
c:\recycler\NPROTECT\00199518.ZIP
c:\recycler\NPROTECT\00199522.ZIP
c:\recycler\NPROTECT\00199526.ZIP
c:\recycler\NPROTECT\00199530.ZIP
c:\recycler\NPROTECT\00199535.ZIP
c:\recycler\NPROTECT\00199538.ZIP
c:\recycler\NPROTECT\00199541.ZIP
c:\recycler\NPROTECT\00199545.ZIP
c:\recycler\NPROTECT\00199549.ZIP
c:\recycler\NPROTECT\00199552.ZIP
c:\recycler\NPROTECT\00199558.ZIP
c:\recycler\NPROTECT\00199564.ZIP
c:\recycler\NPROTECT\00199567.ZIP
c:\recycler\NPROTECT\00199570.ZIP
c:\recycler\NPROTECT\00199574.ZIP
c:\recycler\NPROTECT\00199580.ZIP
c:\recycler\NPROTECT\00199584.ZIP
c:\recycler\NPROTECT\00199590.ZIP
c:\recycler\NPROTECT\00199594.ZIP
c:\recycler\NPROTECT\00199599.ZIP
c:\recycler\NPROTECT\00199605.ZIP
c:\recycler\NPROTECT\00199609.ZIP
c:\recycler\NPROTECT\00199615.ZIP
c:\recycler\NPROTECT\00199619.ZIP
c:\recycler\NPROTECT\00199622.ZIP
c:\recycler\NPROTECT\00199626.ZIP
c:\recycler\NPROTECT\00199630.ZIP
c:\recycler\NPROTECT\00199634.ZIP
c:\recycler\NPROTECT\00199637.ZIP
c:\recycler\NPROTECT\00199641.ZIP
c:\recycler\NPROTECT\00199644.ZIP
c:\recycler\NPROTECT\00199650.ZIP
c:\recycler\NPROTECT\00199654.ZIP
c:\recycler\NPROTECT\00199660.ZIP
c:\recycler\NPROTECT\00199664.ZIP
c:\recycler\NPROTECT\00199668.ZIP
c:\recycler\NPROTECT\00199672.ZIP
c:\recycler\NPROTECT\00199676.ZIP
c:\recycler\NPROTECT\00199679.ZIP
c:\recycler\NPROTECT\00199685.ZIP
c:\recycler\NPROTECT\00199691.ZIP
c:\recycler\NPROTECT\00199694.ZIP
c:\recycler\NPROTECT\00199700.ZIP
c:\recycler\NPROTECT\00199704.ZIP
c:\recycler\NPROTECT\00199707.ZIP
c:\recycler\NPROTECT\00199713.ZIP
c:\recycler\NPROTECT\00199719.ZIP
c:\recycler\NPROTECT\00199725.ZIP
c:\recycler\NPROTECT\00199729.ZIP
c:\recycler\NPROTECT\00199733.ZIP
c:\recycler\NPROTECT\00199737.ZIP
c:\recycler\NPROTECT\00199741.ZIP
c:\recycler\NPROTECT\00199744.ZIP
c:\recycler\NPROTECT\00199748.ZIP
c:\recycler\NPROTECT\00199751.ZIP
c:\recycler\NPROTECT\00199755.ZIP
c:\recycler\NPROTECT\00199761.ZIP
c:\recycler\NPROTECT\00199765.ZIP
c:\recycler\NPROTECT\00199769.ZIP
c:\recycler\NPROTECT\00199772.ZIP
c:\recycler\NPROTECT\00199775.ZIP
c:\recycler\NPROTECT\00199779.ZIP
c:\recycler\NPROTECT\00199782.ZIP
c:\recycler\NPROTECT\00199788.ZIP
c:\recycler\NPROTECT\00199791.ZIP
c:\recycler\NPROTECT\00199794.ZIP
c:\recycler\NPROTECT\00199797.ZIP
c:\recycler\NPROTECT\00199801.ZIP
c:\recycler\NPROTECT\00199804.ZIP
c:\recycler\NPROTECT\00199807.ZIP
c:\recycler\NPROTECT\00199810.ZIP
c:\recycler\NPROTECT\00199813.ZIP
c:\recycler\NPROTECT\00199816.ZIP
c:\recycler\NPROTECT\00199819.ZIP
c:\recycler\NPROTECT\00199823.ZIP
c:\recycler\NPROTECT\00199827.ZIP
c:\recycler\NPROTECT\00199830.ZIP
c:\recycler\NPROTECT\00199834.ZIP
c:\recycler\NPROTECT\00199837.ZIP
c:\recycler\NPROTECT\00199841.ZIP
c:\recycler\NPROTECT\00199845.ZIP
c:\recycler\NPROTECT\00199848.ZIP
c:\recycler\NPROTECT\00199851.ZIP
c:\recycler\NPROTECT\00199855.ZIP
c:\recycler\NPROTECT\00199859.ZIP
c:\recycler\NPROTECT\00199863.ZIP
c:\recycler\NPROTECT\00199869.ZIP
c:\recycler\NPROTECT\00199872.ZIP
c:\recycler\NPROTECT\00199876.ZIP
c:\recycler\NPROTECT\00199880.ZIP
c:\recycler\NPROTECT\00199884.ZIP
c:\recycler\NPROTECT\00199887.ZIP
c:\recycler\NPROTECT\00199891.ZIP
c:\recycler\NPROTECT\00199895.ZIP
c:\recycler\NPROTECT\00199899.ZIP
c:\recycler\NPROTECT\00199902.ZIP
c:\recycler\NPROTECT\00199908.ZIP
c:\recycler\NPROTECT\00199911.ZIP
c:\recycler\NPROTECT\00199914.ZIP
c:\recycler\NPROTECT\00199918.ZIP
c:\recycler\NPROTECT\00199923.ZIP
c:\recycler\NPROTECT\00199929.ZIP
c:\recycler\NPROTECT\00199933.ZIP
c:\recycler\NPROTECT\00199937.ZIP
c:\recycler\NPROTECT\00199941.ZIP
c:\recycler\NPROTECT\00199945.ZIP
c:\recycler\NPROTECT\00199948.ZIP
c:\recycler\NPROTECT\00199951.ZIP
c:\recycler\NPROTECT\00199955.ZIP
c:\recycler\NPROTECT\00199959.ZIP
c:\recycler\NPROTECT\00199962.ZIP
c:\recycler\NPROTECT\00199965.ZIP
c:\recycler\NPROTECT\00199968.ZIP
c:\recycler\NPROTECT\00199972.ZIP
c:\recycler\NPROTECT\00199978.ZIP
c:\recycler\NPROTECT\00199982.ZIP
c:\recycler\NPROTECT\00199986.ZIP
c:\recycler\NPROTECT\00199990.ZIP
c:\recycler\NPROTECT\00199995.ZIP
c:\recycler\NPROTECT\00199999.ZIP
c:\recycler\NPROTECT\00200003.ZIP
c:\recycler\NPROTECT\00200007.ZIP
c:\recycler\NPROTECT\00200013.ZIP
c:\recycler\NPROTECT\00200017.ZIP
c:\recycler\NPROTECT\00200023.ZIP
c:\recycler\NPROTECT\00200029.ZIP
c:\recycler\NPROTECT\00200033.ZIP
c:\recycler\NPROTECT\00200036.ZIP
c:\recycler\NPROTECT\00200039.ZIP
c:\recycler\NPROTECT\00200043.ZIP
c:\recycler\NPROTECT\00200047.ZIP
c:\recycler\NPROTECT\00200051.ZIP
c:\recycler\NPROTECT\00200055.ZIP
c:\recycler\NPROTECT\00200059.ZIP
c:\recycler\NPROTECT\00200063.ZIP
c:\recycler\NPROTECT\00200067.ZIP
c:\recycler\NPROTECT\00200073.ZIP
c:\recycler\NPROTECT\00200079.ZIP
c:\recycler\NPROTECT\00200083.ZIP
c:\recycler\NPROTECT\00200087.ZIP
c:\recycler\NPROTECT\00200093.ZIP
c:\recycler\NPROTECT\00200099.ZIP
c:\recycler\NPROTECT\00200102.ZIP
c:\recycler\NPROTECT\00200105.ZIP
c:\recycler\NPROTECT\00200111.ZIP
c:\recycler\NPROTECT\00200115.ZIP
c:\recycler\NPROTECT\00200119.ZIP
c:\recycler\NPROTECT\00200125.ZIP
c:\recycler\NPROTECT\00200128.ZIP
c:\recycler\NPROTECT\00200132.ZIP
c:\recycler\NPROTECT\00200138.ZIP
c:\recycler\NPROTECT\00200141.ZIP
c:\recycler\NPROTECT\00200145.ZIP
c:\recycler\NPROTECT\00200149.ZIP
c:\recycler\NPROTECT\00200153.ZIP
c:\recycler\NPROTECT\00200156.ZIP
c:\recycler\NPROTECT\00200159.ZIP
c:\recycler\NPROTECT\00200162.ZIP
c:\recycler\NPROTECT\00200166.ZIP
c:\recycler\NPROTECT\00200170.ZIP
c:\recycler\NPROTECT\00200173.ZIP
c:\recycler\NPROTECT\00200178.ZIP
c:\recycler\NPROTECT\00200181.ZIP
c:\recycler\NPROTECT\00200185.ZIP
c:\recycler\NPROTECT\00200188.ZIP
c:\recycler\NPROTECT\00200192.ZIP
c:\recycler\NPROTECT\00200195.ZIP
c:\recycler\NPROTECT\00200199.ZIP
c:\recycler\NPROTECT\00200203.ZIP
c:\recycler\NPROTECT\00200207.ZIP
c:\recycler\NPROTECT\00200211.ZIP
c:\recycler\NPROTECT\00200215.ZIP
c:\recycler\NPROTECT\00200221.ZIP
c:\recycler\NPROTECT\00200224.ZIP
c:\recycler\NPROTECT\00200227.ZIP
c:\recycler\NPROTECT\00200231.ZIP
c:\recycler\NPROTECT\00200234.ZIP
c:\recycler\NPROTECT\00200245.XML
c:\recycler\NPROTECT\00200259.XML
c:\recycler\NPROTECT\00200293.TXT
c:\recycler\NPROTECT\00200324.TXT
c:\recycler\NPROTECT\00200326.TXT
c:\recycler\NPROTECT\00200332.TXT
c:\recycler\NPROTECT\00200353.TXT
c:\recycler\NPROTECT\00200379.TXT
c:\recycler\NPROTECT\00200380.TXT
c:\recycler\NPROTECT\00200419.DAT
c:\recycler\NPROTECT\00200420.DAT
c:\recycler\NPROTECT\00200421.DAT
c:\recycler\NPROTECT\00200433.XML
c:\recycler\NPROTECT\00200444.edb
c:\recycler\NPROTECT\00200446.LOG
c:\recycler\NPROTECT\00200447.LOG
c:\recycler\NPROTECT\00200461.XML
c:\recycler\NPROTECT\00200462.XML
c:\recycler\NPROTECT\00200473.XML
c:\recycler\NPROTECT\00200490.XML
c:\recycler\NPROTECT\00200514.TXT
c:\recycler\NPROTECT\00200545.TXT
c:\recycler\NPROTECT\00200577.TXT
c:\recycler\NPROTECT\00200608.TXT
c:\recycler\NPROTECT\00200609.TXT
c:\recycler\NPROTECT\00200610.TXT
c:\recycler\NPROTECT\00200612.TXT
c:\recycler\NPROTECT\00200642.TXT
c:\recycler\NPROTECT\00200708.TXT
c:\recycler\NPROTECT\00200709.TXT
c:\recycler\NPROTECT\00200724.TXT
c:\recycler\NPROTECT\00200746.TXT
c:\recycler\NPROTECT\00200777.TXT
c:\recycler\NPROTECT\00200793.TXT
c:\recycler\NPROTECT\00200819.TXT
c:\recycler\NPROTECT\00200825.TXT
c:\recycler\NPROTECT\00200831.TXT
c:\recycler\NPROTECT\00200832.TXT
c:\recycler\NPROTECT\00200833.TXT
c:\recycler\NPROTECT\00200839.TXT
c:\recycler\NPROTECT\00200850.TXT
c:\recycler\NPROTECT\00200876.TXT
c:\recycler\NPROTECT\00200907.TXT
c:\recycler\NPROTECT\00200929.TXT
c:\recycler\NPROTECT\00200934.TXT
c:\recycler\NPROTECT\00200960.TXT
c:\recycler\NPROTECT\00200971.TXT
c:\recycler\NPROTECT\00201002.TXT
c:\recycler\NPROTECT\00201008.TXT
c:\recycler\NPROTECT\00201034.TXT
c:\recycler\NPROTECT\00201046.TXT
c:\recycler\NPROTECT\00201076.TXT
c:\recycler\NPROTECT\00201107.TXT
c:\recycler\NPROTECT\00201128.TXT
c:\recycler\NPROTECT\00201134.TXT
c:\recycler\NPROTECT\00201135.TXT
c:\recycler\NPROTECT\00201136.TXT
c:\recycler\NPROTECT\00201137.TXT
c:\recycler\NPROTECT\00201138.TXT
c:\recycler\NPROTECT\00201149.TXT
c:\recycler\NPROTECT\00201157.TXT
c:\recycler\NPROTECT\00201158.TXT
c:\recycler\NPROTECT\00201162.TXT
c:\recycler\NPROTECT\00201163.TXT
c:\recycler\NPROTECT\00201164.TXT
c:\recycler\NPROTECT\00201165.TXT
c:\recycler\NPROTECT\00201166.TXT
c:\recycler\NPROTECT\00201173.TXT
c:\recycler\NPROTECT\00201178.TXT
c:\recycler\NPROTECT\00201179.TXT
c:\recycler\NPROTECT\00201205.TXT
c:\recycler\NPROTECT\00201216.TXT
c:\recycler\NPROTECT\00201247.TXT
c:\recycler\NPROTECT\00201258.TXT
c:\recycler\NPROTECT\00201289.TXT
c:\recycler\NPROTECT\00201295.TXT
c:\recycler\NPROTECT\00201326.TXT
c:\recycler\NPROTECT\00201352.TXT
c:\recycler\NPROTECT\00201368.TXT
c:\recycler\NPROTECT\00201394.TXT
c:\recycler\NPROTECT\00201425.TXT
c:\recycler\NPROTECT\00201451.TXT
c:\recycler\NPROTECT\00201477.DAT
c:\recycler\NPROTECT\00201478.TXT
c:\recycler\NPROTECT\00201509.DAT
c:\recycler\NPROTECT\00201510.DAT
c:\recycler\NPROTECT\00201540.TXT
c:\recycler\NPROTECT\00201567.TXT
c:\recycler\NPROTECT\00201570.TXT
c:\recycler\NPROTECT\00201573.TXT
c:\recycler\NPROTECT\00201606.TXT
c:\recycler\NPROTECT\00201607.TXT
c:\recycler\NPROTECT\00201638.TXT
c:\recycler\NPROTECT\00201669.TXT
c:\recycler\NPROTECT\00201675.TXT
c:\recycler\NPROTECT\00201676.TXT
c:\recycler\NPROTECT\00201700.TXT
c:\recycler\NPROTECT\00201727.TXT
c:\recycler\NPROTECT\00201729.TXT
c:\recycler\NPROTECT\00201730.TXT
c:\recycler\NPROTECT\00201731.TXT
c:\recycler\NPROTECT\00201732.TXT
c:\recycler\NPROTECT\00201733.TXT
c:\recycler\NPROTECT\00201734.TXT
c:\recycler\NPROTECT\00201735.TXT
c:\recycler\NPROTECT\00201736.TXT
c:\recycler\NPROTECT\00201737.TXT
c:\recycler\NPROTECT\00201738.TXT
c:\recycler\NPROTECT\00201739.TXT
c:\recycler\NPROTECT\00201740.TXT
c:\recycler\NPROTECT\00201741.TXT
c:\recycler\NPROTECT\00201742.TXT
c:\recycler\NPROTECT\00201743.TXT
c:\recycler\NPROTECT\00201744.TXT
c:\recycler\NPROTECT\00201745.TXT
c:\recycler\NPROTECT\00201746.TXT
c:\recycler\NPROTECT\00201757.TXT
c:\recycler\NPROTECT\00201758.TXT
c:\recycler\NPROTECT\00201784.TXT
c:\recycler\NPROTECT\00201790.TXT
c:\recycler\NPROTECT\00201816.TXT
c:\recycler\NPROTECT\00201817.TXT
c:\recycler\NPROTECT\00201818.TXT
c:\recycler\NPROTECT\00201852.TXT
c:\recycler\NPROTECT\00201855.TXT
c:\recycler\NPROTECT\00201856.TXT
c:\recycler\NPROTECT\00201860.TXT
c:\recycler\NPROTECT\00201883.TXT
c:\recycler\NPROTECT\00201884.TXT
c:\recycler\NPROTECT\00201905.TXT
c:\recycler\NPROTECT\00201906.TXT
c:\recycler\NPROTECT\00201937.TXT
c:\recycler\NPROTECT\00201942.TXT
c:\recycler\NPROTECT\00201944.TXT
c:\recycler\NPROTECT\00201955.TXT
c:\recycler\NPROTECT\00201964.TXT
c:\recycler\NPROTECT\00201967.TXT
c:\recycler\NPROTECT\00201993.TXT
c:\recycler\NPROTECT\00201994.TXT
c:\recycler\NPROTECT\00202026.TXT
c:\recycler\NPROTECT\00202048.TXT
c:\recycler\NPROTECT\00202051.TXT
c:\recycler\NPROTECT\00202075.TXT
c:\recycler\NPROTECT\00202079.TXT
c:\recycler\NPROTECT\00202087.TXT
c:\recycler\NPROTECT\00202113.TXT
c:\recycler\NPROTECT\00202114.TXT
c:\recycler\NPROTECT\00202129.TXT
c:\recycler\NPROTECT\00202131.TXT
c:\recycler\NPROTECT\00202162.TXT
c:\recycler\NPROTECT\00202168.TXT
c:\recycler\NPROTECT\00202174.TXT
c:\recycler\NPROTECT\00202200.TXT
c:\recycler\NPROTECT\00202201.TXT
c:\recycler\NPROTECT\00202232.TXT
c:\recycler\NPROTECT\00202233.TXT
c:\recycler\NPROTECT\00202234.TXT
c:\recycler\NPROTECT\00202270.TXT
c:\recycler\NPROTECT\00202271.TXT
c:\recycler\NPROTECT\00202272.TXT
c:\recycler\NPROTECT\00202283.TXT
c:\recycler\NPROTECT\00202284.TXT
c:\recycler\NPROTECT\00202295.TXT
c:\recycler\NPROTECT\00202321.TXT
c:\recycler\NPROTECT\00202352.TXT
c:\recycler\NPROTECT\00202353.TXT
c:\recycler\NPROTECT\00202354.TXT
c:\recycler\NPROTECT\00202380.TXT
c:\recycler\NPROTECT\00202381.TXT
c:\recycler\NPROTECT\00202382.TXT
c:\recycler\NPROTECT\00202383.TXT
c:\recycler\NPROTECT\00202394.TXT
c:\recycler\NPROTECT\00202395.TXT
c:\recycler\NPROTECT\00202421.TXT
c:\recycler\NPROTECT\00202422.TXT
c:\recycler\NPROTECT\00202438.TXT
c:\recycler\NPROTECT\00202439.TXT
c:\recycler\NPROTECT\00202440.TXT
c:\recycler\NPROTECT\00202441.TXT
c:\recycler\NPROTECT\00202442.TXT
c:\recycler\NPROTECT\00202453.TXT
c:\recycler\NPROTECT\00202479.TXT
c:\recycler\NPROTECT\00202480.TXT
c:\recycler\NPROTECT\00202516.TXT
c:\recycler\NPROTECT\00202519.TXT
c:\recycler\NPROTECT\00202528.TXT
c:\recycler\NPROTECT\00202554.TXT
c:\recycler\NPROTECT\00202555.TXT
c:\recycler\NPROTECT\00202576.TXT
c:\recycler\NPROTECT\00202577.TXT
c:\recycler\NPROTECT\00202578.TXT
c:\recycler\NPROTECT\00202604.TXT
c:\recycler\NPROTECT\00202605.TXT
c:\recycler\NPROTECT\00202643.TXT
c:\recycler\NPROTECT\00202644.TXT
c:\recycler\NPROTECT\00202665.TXT
c:\recycler\NPROTECT\00202666.TXT
c:\recycler\NPROTECT\00202672.TXT
c:\recycler\NPROTECT\00202698.TXT
c:\recycler\NPROTECT\00202699.TXT
c:\recycler\NPROTECT\00202730.TXT
c:\recycler\NPROTECT\00202731.TXT
c:\recycler\NPROTECT\00202767.TXT
c:\recycler\NPROTECT\00202768.TXT
c:\recycler\NPROTECT\00202769.TXT
c:\recycler\NPROTECT\00202795.TXT
c:\recycler\NPROTECT\00202796.TXT
c:\recycler\NPROTECT\00202797.TXT
c:\recycler\NPROTECT\00202813.TXT
c:\recycler\NPROTECT\00202814.TXT
c:\recycler\NPROTECT\00202815.TXT
c:\recycler\NPROTECT\00202841.TXT
c:\recycler\NPROTECT\00202842.TXT
c:\recycler\NPROTECT\00202843.TXT
c:\recycler\NPROTECT\00202879.TXT
c:\recycler\NPROTECT\00202880.TXT
c:\recycler\NPROTECT\00202891.TXT
c:\recycler\NPROTECT\00202917.TXT
c:\recycler\NPROTECT\00202918.TXT
c:\recycler\NPROTECT\00202944.TXT
c:\recycler\NPROTECT\00202965.TXT
c:\recycler\NPROTECT\00202966.TXT
c:\recycler\NPROTECT\00202967.TXT
c:\recycler\NPROTECT\00202993.TXT
c:\recycler\NPROTECT\00202994.TXT
c:\recycler\NPROTECT\00202995.TXT
c:\recycler\NPROTECT\00203011.TXT
c:\recycler\NPROTECT\00203012.TXT
c:\recycler\NPROTECT\00203013.TXT
c:\recycler\NPROTECT\00203024.TXT
c:\recycler\NPROTECT\00203025.TXT
c:\recycler\NPROTECT\00203031.TXT
c:\recycler\NPROTECT\00203032.TXT
c:\recycler\NPROTECT\00203034.TXT
c:\recycler\NPROTECT\00203039.TXT
c:\recycler\NPROTECT\00203040.TXT
c:\recycler\NPROTECT\00203044.TXT
c:\recycler\NPROTECT\00203052.TXT
c:\recycler\NPROTECT\00203085.TXT
c:\recycler\NPROTECT\00203086.TXT
c:\recycler\NPROTECT\00203092.TXT
c:\recycler\NPROTECT\00203118.TXT
c:\recycler\NPROTECT\00203149.XML
c:\recycler\NPROTECT\00203155.TXT
c:\recycler\NPROTECT\00203186.C$$
c:\recycler\NPROTECT\00203187.cfg
c:\recycler\NPROTECT\00203203.TXT
c:\recycler\NPROTECT\00203239.TXT
c:\recycler\NPROTECT\00203279.TXT
c:\recycler\NPROTECT\00203310.XML
c:\recycler\NPROTECT\00203316.txt
c:\recycler\NPROTECT\00203317.txt
c:\recycler\NPROTECT\00203318.TXT
c:\recycler\NPROTECT\00203354.XML
c:\recycler\NPROTECT\00203363.CAB
c:\recycler\NPROTECT\00203369.edb
c:\recycler\NPROTECT\00203381.XML
c:\recycler\NPROTECT\00203382.XML
c:\recycler\NPROTECT\00203393.XML
c:\recycler\NPROTECT\00203416.XML
c:\recycler\NPROTECT\00203420
c:\recycler\NPROTECT\00203421.dll
c:\recycler\NPROTECT\00203422.exe
c:\recycler\NPROTECT\00203423.inf
c:\recycler\NPROTECT\00203424.txt
c:\recycler\NPROTECT\00203425.CAT
c:\recycler\NPROTECT\00203426.dll
c:\recycler\NPROTECT\00203427.exe
c:\recycler\NPROTECT\00203428.ver
c:\recycler\NPROTECT\00203429.inf
c:\recycler\NPROTECT\00203430.INF
c:\recycler\NPROTECT\00203431.INF
c:\recycler\NPROTECT\00203432.dll
c:\recycler\NPROTECT\00203433.STA
c:\recycler\NPROTECT\00203434.TXT
c:\recycler\NPROTECT\00203435.STA
c:\recycler\NPROTECT\00203436.STA
c:\recycler\NPROTECT\00203437.sys
c:\recycler\NPROTECT\00203438.sys
c:\recycler\NPROTECT\00203439.sys
c:\recycler\NPROTECT\00203440.sys
c:\recycler\NPROTECT\00203441.dll
c:\recycler\NPROTECT\00203442.exe
c:\recycler\NPROTECT\00203443.rq0
c:\recycler\NPROTECT\00203444.inf
c:\recycler\NPROTECT\00203445.txt
c:\recycler\NPROTECT\00203446.cat
c:\recycler\NPROTECT\00203447.dll
c:\recycler\NPROTECT\00203448.exe
c:\recycler\NPROTECT\00203449.url
c:\recycler\NPROTECT\00203450.ver
c:\recycler\NPROTECT\00203451.inf
c:\recycler\NPROTECT\00203452.INF
c:\recycler\NPROTECT\00203453.INF
c:\recycler\NPROTECT\00203454.INF
c:\recycler\NPROTECT\00203455.INF
c:\recycler\NPROTECT\00203456.dll
c:\recycler\NPROTECT\00203457.dll
c:\recycler\NPROTECT\00203458.cat
c:\recycler\NPROTECT\00203459.PSM
c:\recycler\NPROTECT\00203460.STA
c:\recycler\NPROTECT\00203461.STA
c:\recycler\NPROTECT\00203462.STA
c:\recycler\NPROTECT\00203463.dll
c:\recycler\NPROTECT\00203464.dll
c:\recycler\NPROTECT\00203465.dll
c:\recycler\NPROTECT\00203466.dll
c:\recycler\NPROTECT\00203467.dll
c:\recycler\NPROTECT\00203468.exe
c:\recycler\NPROTECT\00203469.rq0
c:\recycler\NPROTECT\00203470.inf
c:\recycler\NPROTECT\00203471.txt
c:\recycler\NPROTECT\00203472.cat
c:\recycler\NPROTECT\00203473.dll
c:\recycler\NPROTECT\00203474.exe
c:\recycler\NPROTECT\00203475.url
c:\recycler\NPROTECT\00203476.ver
c:\recycler\NPROTECT\00203477.inf
c:\recycler\NPROTECT\00203478.INF
c:\recycler\NPROTECT\00203479.INF
c:\recycler\NPROTECT\00203480.INF
c:\recycler\NPROTECT\00203481.INF
c:\recycler\NPROTECT\00203482.dll
c:\recycler\NPROTECT\00203483.PSM
c:\recycler\NPROTECT\00203484.STA
c:\recycler\NPROTECT\00203485.STA
c:\recycler\NPROTECT\00203486.STA
c:\recycler\NPROTECT\00203487.dll
c:\recycler\NPROTECT\00203488.dll
c:\recycler\NPROTECT\00203489.dll
c:\recycler\NPROTECT\00203490.dll
c:\recycler\NPROTECT\00203491.dll
c:\recycler\NPROTECT\00203492.exe
c:\recycler\NPROTECT\00203493.rq0
c:\recycler\NPROTECT\00203494.inf
c:\recycler\NPROTECT\00203495.txt
c:\recycler\NPROTECT\00203496.cat
c:\recycler\NPROTECT\00203497.dll
c:\recycler\NPROTECT\00203498.exe
c:\recycler\NPROTECT\00203499.url
c:\recycler\NPROTECT\00203500.ver
c:\recycler\NPROTECT\00203501.inf
c:\recycler\NPROTECT\00203502.INF
c:\recycler\NPROTECT\00203503.INF
c:\recycler\NPROTECT\00203504.INF
c:\recycler\NPROTECT\00203505.INF
c:\recycler\NPROTECT\00203506.dll
c:\recycler\NPROTECT\00203507.PSM
c:\recycler\NPROTECT\00203508.STA
c:\recycler\NPROTECT\00203509.STA
c:\recycler\NPROTECT\00203510.STA
c:\recycler\NPROTECT\00203511.exe
c:\recycler\NPROTECT\00203512.dll
c:\recycler\NPROTECT\00203513.dll
c:\recycler\NPROTECT\00203514.dll
c:\recycler\NPROTECT\00203515.dll
c:\recycler\NPROTECT\00203516.cpl
c:\recycler\NPROTECT\00203517.dll
c:\recycler\NPROTECT\00203518.dll
c:\recycler\NPROTECT\00203519.dll
c:\recycler\NPROTECT\00203520.dll
c:\recycler\NPROTECT\00203521.dll
c:\recycler\NPROTECT\00203522.exe
c:\recycler\NPROTECT\00203523.dll
c:\recycler\NPROTECT\00203524.dll
c:\recycler\NPROTECT\00203525.dll
c:\recycler\NPROTECT\00203526.dll
c:\recycler\NPROTECT\00203527.cpl
c:\recycler\NPROTECT\00203528.dll
c:\recycler\NPROTECT\00203529.dll
c:\recycler\NPROTECT\00203530.dll
c:\recycler\NPROTECT\00203531.dll
c:\recycler\NPROTECT\00203532.dll
c:\recycler\NPROTECT\00203533.dll
c:\recycler\NPROTECT\00203534.exe
c:\recycler\NPROTECT\00203535.inf
c:\recycler\NPROTECT\00203536.txt
c:\recycler\NPROTECT\00203537.CAT
c:\recycler\NPROTECT\00203538.dll
c:\recycler\NPROTECT\00203539.exe
c:\recycler\NPROTECT\00203540.ver
c:\recycler\NPROTECT\00203541.inf
c:\recycler\NPROTECT\00203542.INF
c:\recycler\NPROTECT\00203543.INF
c:\recycler\NPROTECT\00203544.dll
c:\recycler\NPROTECT\00203545.STA
c:\recycler\NPROTECT\00203546.TXT
c:\recycler\NPROTECT\00203547.STA
c:\recycler\NPROTECT\00203548.STA
c:\recycler\NPROTECT\00203553.KC
c:\recycler\NPROTECT\00203572.edb
c:\recycler\NPROTECT\00203606.CAB
c:\recycler\NPROTECT\00203612.inf
c:\recycler\NPROTECT\00203613.pnf
c:\recycler\NPROTECT\00203614.cat
c:\recycler\NPROTECT\00203615.inf
c:\recycler\NPROTECT\00203616.pnf
c:\recycler\NPROTECT\00203617.cat
c:\recycler\NPROTECT\00203619.dll
c:\recycler\NPROTECT\00203620.exe
c:\recycler\NPROTECT\00203621.inf
c:\recycler\NPROTECT\00203622.txt
c:\recycler\NPROTECT\00203623.cat
c:\recycler\NPROTECT\00203624.dll
c:\recycler\NPROTECT\00203625.exe
c:\recycler\NPROTECT\00203626.url
c:\recycler\NPROTECT\00203627.ver
c:\recycler\NPROTECT\00203628.inf
c:\recycler\NPROTECT\00203629.INF
c:\recycler\NPROTECT\00203630.INF
c:\recycler\NPROTECT\00203631.INF
c:\recycler\NPROTECT\00203632.INF
c:\recycler\NPROTECT\00203633.dll
c:\recycler\NPROTECT\00203634.PSM
c:\recycler\NPROTECT\00203635.STA
c:\recycler\NPROTECT\00203636.STA
c:\recycler\NPROTECT\00203637.STA
c:\recycler\NPROTECT\00203638.edb
c:\recycler\NPROTECT\00203665.SES
c:\recycler\NPROTECT\00203682.mst
c:\recycler\NPROTECT\00203689.LOG
c:\recycler\NPROTECT\00203718.dat
c:\recycler\NPROTECT\00203719.dat
c:\recycler\NPROTECT\00203720.XML
c:\recycler\NPROTECT\00203731.DAT
c:\recycler\NPROTECT\00203732.DAT
c:\recycler\NPROTECT\00203749.DAT
c:\recycler\NPROTECT\00203751.TXT
c:\recycler\NPROTECT\00203752.TXT
c:\recycler\NPROTECT\00203753.TXT
c:\recycler\NPROTECT\00203796.XML
c:\recycler\NPROTECT\00203806.LOG
c:\recycler\NPROTECT\00203820.LNK
c:\recycler\NPROTECT\00203825.TXT
c:\recycler\NPROTECT\00203826.TXT
c:\recycler\NPROTECT\00203827.TXT
c:\recycler\NPROTECT\00203828.TXT
c:\recycler\NPROTECT\00203829.TXT
c:\recycler\NPROTECT\00203830.TXT
c:\recycler\NPROTECT\00203831.TXT
c:\recycler\NPROTECT\00203832.TXT
c:\recycler\NPROTECT\00203833.TXT
c:\recycler\NPROTECT\00203834.TXT
c:\recycler\NPROTECT\00203835.TXT
c:\recycler\NPROTECT\00203836.TXT
c:\recycler\NPROTECT\00203837.TXT
c:\recycler\NPROTECT\00203838.TXT
c:\recycler\NPROTECT\00203839.TXT
c:\recycler\NPROTECT\00203840.DAT
c:\recycler\NPROTECT\00203841.DAT
c:\recycler\NPROTECT\00203842.DAT
c:\recycler\NPROTECT\00203860
c:\recycler\NPROTECT\00203862.pif
c:\recycler\NPROTECT\00203867
c:\recycler\NPROTECT\00203868
c:\recycler\NPROTECT\00203871.DAT
c:\recycler\NPROTECT\00203878
c:\recycler\NPROTECT\00203879.chm
c:\recycler\NPROTECT\00203884
c:\recycler\NPROTECT\00203886
c:\recycler\NPROTECT\00203888
c:\recycler\NPROTECT\00203918
c:\recycler\NPROTECT\00203919
c:\recycler\NPROTECT\00203922
c:\recycler\NPROTECT\00203924
c:\recycler\NPROTECT\00203925
c:\recycler\NPROTECT\00203930.cmd
c:\recycler\NPROTECT\00203933.exe
c:\recycler\NPROTECT\00203934.TXT
c:\recycler\NPROTECT\00203935.exe
c:\recycler\NPROTECT\00203936.TXT
c:\recycler\NPROTECT\00203937.TXT
c:\recycler\NPROTECT\00203938.TXT
c:\recycler\NPROTECT\00203939.bat
c:\recycler\NPROTECT\00203940.exe
c:\recycler\NPROTECT\00203941.TXT
c:\recycler\NPROTECT\00203942.txt
c:\recycler\NPROTECT\00203943.zip
c:\recycler\NPROTECT\00203944.txt
c:\recycler\NPROTECT\00203945.bat
c:\recycler\NPROTECT\00203946.bat
c:\recycler\NPROTECT\00203947.ZIP
c:\recycler\NPROTECT\00203948.HTM
c:\recycler\NPROTECT\00203949.TXT
c:\recycler\NPROTECT\00203950
c:\recycler\NPROTECT\00203951
c:\recycler\NPROTECT\00203952
c:\recycler\NPROTECT\00203956.log
c:\recycler\NPROTECT\00203958
c:\recycler\NPROTECT\00203959.cmd
c:\recycler\NPROTECT\00203963.txt
c:\recycler\NPROTECT\00203964.EXE
c:\recycler\NPROTECT\00203967
c:\recycler\NPROTECT\00203969
c:\recycler\NPROTECT\00203971.CMD
c:\recycler\NPROTECT\00203975
c:\recycler\NPROTECT\00203978
c:\recycler\NPROTECT\00203979
c:\recycler\NPROTECT\00203980
c:\recycler\NPROTECT\00203981
c:\recycler\NPROTECT\00203982
c:\recycler\NPROTECT\00203983
c:\recycler\NPROTECT\00203984
c:\recycler\NPROTECT\00203985
c:\recycler\NPROTECT\00203986
c:\recycler\NPROTECT\00203987
c:\recycler\NPROTECT\00203988
c:\recycler\NPROTECT\00203989
c:\recycler\NPROTECT\00203990
c:\recycler\NPROTECT\00203991
c:\recycler\NPROTECT\00203992
c:\recycler\NPROTECT\00203993
c:\recycler\NPROTECT\00203994
c:\recycler\NPROTECT\00203995
c:\recycler\NPROTECT\00203996
c:\recycler\NPROTECT\00203997
c:\recycler\NPROTECT\00203998
c:\recycler\NPROTECT\00203999
c:\recycler\NPROTECT\00204000
c:\recycler\NPROTECT\00204001
c:\recycler\NPROTECT\00204005
c:\recycler\NPROTECT\00204006
c:\recycler\NPROTECT\00204007
c:\recycler\NPROTECT\00204008.dll
c:\recycler\NPROTECT\00204013.DAT
c:\recycler\NPROTECT\00204014.DAT
c:\recycler\NPROTECT\00204015.DAT
c:\recycler\NPROTECT\00204018
c:\recycler\NPROTECT\00204019
c:\recycler\NPROTECT\00204020
c:\recycler\NPROTECT\00204021
c:\recycler\NPROTECT\00204022
c:\recycler\NPROTECT\00204023
c:\recycler\NPROTECT\00204024
c:\recycler\NPROTECT\00204025
c:\recycler\NPROTECT\00204026
c:\recycler\NPROTECT\00204027
c:\recycler\NPROTECT\00204029.c
c:\recycler\NPROTECT\00204034.dat
c:\recycler\NPROTECT\00204035.DAT
c:\recycler\NPROTECT\00204037
c:\recycler\NPROTECT\00204038
c:\recycler\NPROTECT\00204039
c:\recycler\NPROTECT\00204046.BAT
c:\recycler\NPROTECT\00204049
c:\recycler\NPROTECT\00204051
c:\recycler\NPROTECT\00204052
c:\recycler\NPROTECT\00204053
c:\recycler\NPROTECT\00204054
c:\recycler\NPROTECT\00204055
c:\recycler\NPROTECT\00204056
c:\recycler\NPROTECT\00204057
c:\recycler\NPROTECT\00204058
c:\recycler\NPROTECT\00204059
c:\recycler\NPROTECT\00204060
c:\recycler\NPROTECT\00204061
c:\recycler\NPROTECT\00204062
c:\recycler\NPROTECT\00204064
c:\recycler\NPROTECT\00204067
c:\recycler\NPROTECT\00204068
c:\recycler\NPROTECT\00204069
c:\recycler\NPROTECT\00204070
c:\recycler\NPROTECT\00204071
c:\recycler\NPROTECT\00204072
c:\recycler\NPROTECT\00204073
c:\recycler\NPROTECT\00204074
c:\recycler\NPROTECT\00204075
c:\recycler\NPROTECT\00204076
c:\recycler\NPROTECT\00204077
c:\recycler\NPROTECT\00204078
c:\recycler\NPROTECT\00204079
c:\recycler\NPROTECT\00204080
c:\recycler\NPROTECT\00204081
c:\recycler\NPROTECT\00204082
c:\recycler\NPROTECT\00204083
c:\recycler\NPROTECT\00204084
c:\recycler\NPROTECT\00204085
c:\recycler\NPROTECT\00204086
c:\recycler\NPROTECT\00204087
c:\recycler\NPROTECT\00204088
c:\recycler\NPROTECT\00204089.BAT
c:\recycler\NPROTECT\00204090
c:\recycler\NPROTECT\00204092.CFU
c:\recycler\NPROTECT\00204093
c:\recycler\NPROTECT\00204094.BAT
c:\recycler\NPROTECT\00204095
c:\recycler\NPROTECT\00204096
c:\recycler\NPROTECT\00204097
c:\recycler\NPROTECT\00204098
c:\recycler\NPROTECT\00204099
c:\recycler\NPROTECT\00204100
c:\recycler\NPROTECT\00204101
c:\recycler\NPROTECT\00204102.cfu
c:\recycler\NPROTECT\00204103
c:\recycler\NPROTECT\00204104.cfu
c:\recycler\NPROTECT\00204105
c:\recycler\NPROTECT\00204106.cfu
c:\recycler\NPROTECT\00204107
c:\recycler\NPROTECT\00204108.cfu
c:\recycler\NPROTECT\00204109
c:\recycler\NPROTECT\00204110.CFU
c:\recycler\NPROTECT\00204111
c:\recycler\NPROTECT\00204112.CFU
c:\recycler\NPROTECT\00204113
c:\recycler\NPROTECT\00204114.CFU
c:\recycler\NPROTECT\00204115
c:\recycler\NPROTECT\00204116.CFU
c:\recycler\NPROTECT\00204117
c:\recycler\NPROTECT\00204118.cfu
c:\recycler\NPROTECT\00204119
c:\recycler\NPROTECT\00204120.cfu
c:\recycler\NPROTECT\00204121
c:\recycler\NPROTECT\00204122.CFU
c:\recycler\NPROTECT\00204123
c:\recycler\NPROTECT\00204124.cfu
c:\recycler\NPROTECT\00204125
c:\recycler\NPROTECT\00204126.CFU
c:\recycler\NPROTECT\00204127.sed
c:\recycler\NPROTECT\00204128.RE5
c:\recycler\NPROTECT\00204129.re5
c:\recycler\NPROTECT\00204130.re5
c:\recycler\NPROTECT\00204131.re5
c:\recycler\NPROTECT\00204132.re5
c:\recycler\NPROTECT\00204133.re5
c:\recycler\NPROTECT\00204134.re5
c:\recycler\NPROTECT\00204135.re5
c:\recycler\NPROTECT\00204136.re5
c:\recycler\NPROTECT\00204137.re5
c:\recycler\NPROTECT\00204138.RE5
c:\recycler\NPROTECT\00204139.FOL
c:\recycler\NPROTECT\00204140.FOL
c:\recycler\NPROTECT\00204141.FOL
c:\recycler\NPROTECT\00204142.FOL
c:\recycler\NPROTECT\00204143.FOL
c:\recycler\NPROTECT\00204144.FOL
c:\recycler\NPROTECT\00204145.FOL
c:\recycler\NPROTECT\00204146.FOL
c:\recycler\NPROTECT\00204147.FOL
c:\recycler\NPROTECT\00204148.FOL
c:\recycler\NPROTECT\00204149.FOL
c:\recycler\NPROTECT\00204150.FOL
c:\recycler\NPROTECT\00204151.FOL
c:\recycler\NPROTECT\00204152
c:\recycler\NPROTECT\00204153
c:\recycler\NPROTECT\00204154
c:\recycler\NPROTECT\00204155
c:\recycler\NPROTECT\00204156
c:\recycler\NPROTECT\00204157
c:\recycler\NPROTECT\00204158.dat
c:\recycler\NPROTECT\00204159.DAT
c:\recycler\NPROTECT\00204160
c:\recycler\NPROTECT\00204161
c:\recycler\NPROTECT\00204162
c:\recycler\NPROTECT\00204163
c:\recycler\NPROTECT\00204164
c:\recycler\NPROTECT\00204165
c:\recycler\NPROTECT\00204166
c:\recycler\NPROTECT\00204167.SI_
c:\recycler\NPROTECT\00204168.REG
c:\recycler\NPROTECT\00204170
c:\recycler\NPROTECT\00204171
c:\recycler\NPROTECT\00204172.cmd
c:\recycler\NPROTECT\00204173.CMD
c:\recycler\NPROTECT\00204174.img
c:\recycler\NPROTECT\00204175.img
c:\recycler\NPROTECT\00204176.img
c:\recycler\NPROTECT\00204177.img
c:\recycler\NPROTECT\00204178.img
c:\recycler\NPROTECT\00204179.img
c:\recycler\NPROTECT\00204180.exe
c:\recycler\NPROTECT\00204181.exe
c:\recycler\NPROTECT\00204182
c:\recycler\NPROTECT\00204183
c:\recycler\NPROTECT\00204184
c:\recycler\NPROTECT\00204185
c:\recycler\NPROTECT\00204186
c:\recycler\NPROTECT\00204187
c:\recycler\NPROTECT\00204188
c:\recycler\NPROTECT\00204189
c:\recycler\NPROTECT\00204190
c:\recycler\NPROTECT\00204191
c:\recycler\NPROTECT\00204192
c:\recycler\NPROTECT\00204193.sed
c:\recycler\NPROTECT\00204194.sed
c:\recycler\NPROTECT\00204195.bat
c:\recycler\NPROTECT\00204196.bat
c:\recycler\NPROTECT\00204197
c:\recycler\NPROTECT\00204198
c:\recycler\NPROTECT\00204200
c:\recycler\NPROTECT\00204205
c:\recycler\NPROTECT\00204206
c:\recycler\NPROTECT\00204207
c:\recycler\NPROTECT\00204208
c:\recycler\NPROTECT\00204209.CMD
c:\recycler\NPROTECT\00204210.cmd
c:\recycler\NPROTECT\00204211.dat
c:\recycler\NPROTECT\00204213
c:\recycler\NPROTECT\00204214
c:\recycler\NPROTECT\00204215
c:\recycler\NPROTECT\00204216
c:\recycler\NPROTECT\00204217
c:\recycler\NPROTECT\00204218
c:\recycler\NPROTECT\00204219
c:\recycler\NPROTECT\00204220
c:\recycler\NPROTECT\00204221
c:\recycler\NPROTECT\00204222
c:\recycler\NPROTECT\00204223
c:\recycler\NPROTECT\00204224
c:\recycler\NPROTECT\00204225
c:\recycler\NPROTECT\00204226
c:\recycler\NPROTECT\00204227
c:\recycler\NPROTECT\00204228
c:\recycler\NPROTECT\00204229
c:\recycler\NPROTECT\00204230.VBS
c:\recycler\NPROTECT\00204231
c:\recycler\NPROTECT\00204232
c:\recycler\NPROTECT\00204233
c:\recycler\NPROTECT\00204234
c:\recycler\NPROTECT\00204235
c:\recycler\NPROTECT\00204236.SYS
c:\recycler\NPROTECT\00204237
c:\recycler\NPROTECT\00204238
c:\recycler\NPROTECT\00204239
c:\recycler\NPROTECT\00204240
c:\recycler\NPROTECT\00204243
c:\recycler\NPROTECT\NPROTECT.LOG . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2009-05-21 to 2009-06-21 )))))))))))))))))))))))))))))))
.

2009-06-18 04:13 . 2009-06-18 04:14 -------- d-----w- c:\program files\iTunes
2009-06-18 03:56 . 2009-06-18 03:56 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-16 03:03 . 2009-06-16 03:03 -------- d-----w- c:\program files\Trend Micro
2009-06-14 12:35 . 2009-06-14 12:35 -------- d-----w- c:\program files\Flip Video
2009-06-14 12:35 . 2009-06-14 12:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Flip Video
2009-06-10 11:02 . 2009-06-10 11:02 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-09 22:35 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-06-09 22:35 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-09 22:00 . 2009-06-09 22:00 -------- d-sh--w- c:\documents and settings\Benjamin\PrivacIE
2009-06-09 22:00 . 2009-06-09 22:00 -------- d-----w- c:\documents and settings\Benjamin\Local Settings\Application Data\Conduit
2009-06-09 22:00 . 2009-06-09 22:01 -------- d-----w- c:\documents and settings\Benjamin\Local Settings\Application Data\eMusic
2009-06-09 22:00 . 2009-06-09 22:00 -------- d-sh--w- c:\documents and settings\Benjamin\IETldCache
2009-06-08 03:43 . 2009-06-08 03:43 2904064 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\18154-181625.dll
2009-06-08 03:42 . 2009-06-08 03:42 3616768 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181311-181414.dll
2009-06-08 03:42 . 2009-06-08 03:42 242976 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2009-06-08 03:41 . 2009-06-08 03:41 1536000 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181414-18154.dll
2009-06-08 03:41 . 2009-06-08 03:41 1007616 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181129-181212.dll
2009-06-08 03:41 . 2009-06-08 03:41 811008 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181212-181311.dll
2009-06-08 03:41 . 2009-06-08 03:41 223584 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2009-06-08 03:41 . 2009-06-08 03:41 997 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2009-06-08 03:40 . 2009-06-08 03:40 -------- d-----w- c:\program files\Common Files\AnswerWorks 5.0
2009-06-08 03:40 . 2009-01-09 19:33 1848608 ----a-w- c:\windows\system32\acXMLParser.dll
2009-06-08 03:40 . 2009-01-09 19:33 3523872 ----a-w- c:\windows\system32\cdintf300.dll
2009-06-08 03:39 . 2009-01-09 19:32 25888 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\HaB\Custom\billmind.exe
2009-06-08 03:39 . 2009-01-09 19:32 25888 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\RPM\Custom\billmind.exe
2009-06-08 03:38 . 2009-06-08 03:44 -------- d-----w- c:\program files\Quicken
2009-06-04 21:39 . 2009-06-04 21:39 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\eMusic
2009-05-31 00:49 . 2009-05-31 00:49 -------- d-sh--w- c:\documents and settings\Alaina\PrivacIE
2009-05-31 00:49 . 2009-05-31 00:49 -------- d-----w- c:\documents and settings\Alaina\Local Settings\Application Data\Conduit
2009-05-31 00:49 . 2009-05-31 00:50 -------- d-----w- c:\documents and settings\Alaina\Local Settings\Application Data\eMusic
2009-05-31 00:48 . 2009-05-31 00:48 -------- d-sh--w- c:\documents and settings\Alaina\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2098-01-01 06:00 . 2007-12-20 23:30 9096 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\LUTPReg.dll
2098-01-01 06:00 . 2007-08-22 21:45 9048 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\FWLUReg.dll
2009-06-18 04:39 . 2007-08-28 01:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-06-18 04:26 . 2006-08-17 20:06 -------- d-----w- c:\documents and settings\Jennifer\Application Data\ArcSoft
2009-06-18 04:19 . 2006-08-16 02:55 -------- d-----w- c:\documents and settings\Jennifer\Application Data\Apple Computer
2009-06-18 04:19 . 2009-04-20 12:32 -------- d-----w- c:\program files\Safari
2009-06-18 04:13 . 2006-08-16 02:52 -------- d-----w- c:\program files\iPod
2009-06-18 04:13 . 2007-08-28 01:29 -------- d-----w- c:\program files\Common Files\Apple
2009-06-18 04:07 . 2007-08-28 01:32 -------- d-----w- c:\program files\QuickTime
2009-06-15 23:59 . 2009-05-17 04:26 -------- d-----w- c:\program files\eMusic Download Manager
2009-06-14 12:38 . 2009-03-02 12:37 -------- d-----w- c:\program files\Ascentive
2009-06-14 12:38 . 2006-08-10 20:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-14 12:17 . 2009-03-15 23:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Ascentive
2009-06-14 02:27 . 2008-11-09 13:18 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-08 18:31 . 2006-08-23 03:45 -------- d-----w- c:\program files\Norton SystemWorks
2009-06-08 03:40 . 2006-08-10 20:32 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-07 12:14 . 2009-05-17 04:26 -------- d-----w- c:\program files\eMusic
2009-06-05 16:42 . 2009-04-20 12:38 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 16:42 . 2007-09-19 00:31 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-17 04:59 . 2009-05-17 05:01 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-17 04:59 . 2006-08-10 20:29 -------- d-----w- c:\program files\Java
2009-05-17 04:59 . 2009-05-17 04:59 152576 ----a-w- c:\documents and settings\Tom\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2009-05-17 04:37 . 2006-08-23 03:44 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-17 04:27 . 2009-05-17 04:27 -------- d-----w- c:\documents and settings\Tom\Application Data\eMusic
2009-05-17 04:27 . 2009-05-17 04:27 -------- d-----w- c:\program files\Conduit
2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:44 . 2004-08-10 17:51 344064 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 03:05 . 2009-05-07 03:05 -------- d-----w- c:\program files\Essentials Codec Pack
2009-05-07 02:57 . 2009-05-07 02:56 16036624 ----a-w- c:\documents and settings\Tom\Application Data\Blitware\DriverRobot\downloads\e1aeb2611fc7ef4c5a3aa3193ad9de9a\AUD_allOS_x5511_v5511_PV_IDTGUI_v005.exe
2009-05-07 02:57 . 2009-05-07 02:56 10592136 ----a-w- c:\documents and settings\Tom\Application Data\Blitware\DriverRobot\downloads\b266cd8b92ca7e0636bc4c6a2c4e9420\sp41804.exe
2009-05-07 02:57 . 2009-05-07 02:56 3187424 ----a-w- c:\documents and settings\Tom\Application Data\Blitware\DriverRobot\downloads\50aef00ed1291deac2c04d9acbfe216f\sp40969.exe
2009-05-07 02:53 . 2009-05-07 02:53 -------- d-----w- c:\documents and settings\Tom\Application Data\Blitware
2009-05-07 02:52 . 2009-05-07 02:52 -------- d-----w- c:\program files\Driver Robot
2009-05-05 16:15 . 2009-05-05 16:15 4732800 ----a-w- c:\documents and settings\All Users\Application Data\Flip Video\FlipShare\Updates\FirmwareExec_Windows_en-US_83.06_83.07\FlipVideoFWUpdate.exe
2009-05-04 01:13 . 2009-05-04 01:12 -------- d-----w- c:\documents and settings\Tom\Application Data\W Photo Studio Viewer
2009-05-03 12:20 . 2009-05-03 12:20 -------- d-----w- c:\program files\3ivx
2009-04-17 09:58 . 2004-08-10 17:51 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:26 . 2004-08-10 17:51 583168 ----a-w- c:\windows\system32\rpcrt4.dll
2008-12-29 14:43 . 2006-08-26 01:32 88 --sh--r- c:\windows\system32\9BF8CF38C9.sys
2008-12-29 14:43 . 2006-08-26 01:32 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
2009-06-07 12:14 2094616 ----a-w- c:\program files\eMusic\tbeMu0.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-07-15 1961984]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 68856]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-17 136600]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"NSWosCheck"="c:\program files\Norton SystemWorks\osCheck.exe" [2007-09-18 25472]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2007-08-25 714608]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-07-20 5361464]
"WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2006-08-17 339968]

c:\documents and settings\Tom\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-9-9 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
WD Backup Monitor.lnk - c:\program files\My Book\WD Backup\uBBMonitor.exe [2006-8-17 98304]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\DOM\\Xm.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;c:\windows\system32\drivers\SSFS0BB8.sys [7/1/2007 7:09 AM 20280]
R2 FlipShare Service;FlipShare Service;c:\program files\Flip Video\FlipShare\FlipShareService.exe [5/5/2009 11:19 AM 451904]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/25/2007 12:07 AM 149352]
R2 NProtectService;Norton UnErase Protection;c:\progra~1\NORTON~1\NORTON~1\NPROTECT.EXE [11/3/2005 10:08 PM 95832]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/16/2009 11:40 PM 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [5/29/2007 3:55 PM 23888]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2009-06-21 c:\windows\Tasks\Driver Robot.job
- c:\program files\Driver Robot\DriverRobot.exe [2009-05-07 01:26]

2009-06-21 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Jennifer.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]

2009-06-19 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Tom.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]

2009-06-15 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Norton SystemWorks\OBC.exe [2007-09-18 13:22]

2009-06-18 c:\windows\Tasks\wrSpySweeper_05B829958F5E42C99FE2600C698B73E0.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-18 c:\windows\Tasks\wrSpySweeper_05B829958F5E42C99FE2600C698B73E0.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-21 c:\windows\Tasks\wrSpySweeper_59457A6952A849EEA079E2F6CE08BAF6.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-21 c:\windows\Tasks\wrSpySweeper_59457A6952A849EEA079E2F6CE08BAF6.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-21 c:\windows\Tasks\wrSpySweeper_CD464B7172C344E48429CFE608738C93.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-21 c:\windows\Tasks\wrSpySweeper_CD464B7172C344E48429CFE608738C93.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-21 c:\windows\Tasks\wrSpySweeper_D61FB012AC1D4E01A3F1DFC2352495F2.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-21 c:\windows\Tasks\wrSpySweeper_D61FB012AC1D4E01A3F1DFC2352495F2.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-21 c:\windows\Tasks\wrSpySweeper_FD2009DD7A1246DB8886FB78DEC4CA7B.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]

2009-06-21 c:\windows\Tasks\wrSpySweeper_FD2009DD7A1246DB8886FB78DEC4CA7B.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-09-28 03:54]
.
- - - - ORPHANS REMOVED - - - -

BHO-{A1023BB9-453C-463F-9288-56AE96C52807} - (no file)
HKCU-Run-PC ScanAndSweep - c:\program files\Ascentive\PC ScanAndSweep\PCScanAndSweep.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig?hl=en
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://us.mcafee.com/apps/mpfplus/en-us ... popup=true
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: musicmatch.com\online
TCP: {78F2A078-1F75-4C31-B962-0CE047F7C5E3} = 192.168.1.1
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-21 07:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(964)
c:\windows\system32\WRLogonNTF.dll

- - - - - - - > 'explorer.exe'(1580)
c:\windows\system32\WININET.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
c:\program files\Common Files\Symantec Shared\NPC\2.0\NPCEXT.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Ahead\InCD\InCDsrv.exe
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\progra~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\system32\wbem\unsecapp.exe
c:\progra~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-06-21 7:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-21 12:38

Pre-Run: 53,277,261,824 bytes free
Post-Run: 53,760,008,192 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

1974 --- E O F --- 2009-06-18 08:01
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 21st, 2009, 8:41 am

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:10 AM, on 6/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\PayPal\PayPal Plug-In\RBroker.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/mpfplus/en-us ... popup=true
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: FCTBPos00Pos - {A1023BB9-453C-463F-9288-56AE96C52807} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: (no name) - {BB0CBE93-CD99-45B9-BF11-291F1B260698} - (no file)
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O3 - Toolbar: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://www.cnn.com/diskless/bin/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsup ... gctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInCon ... ontrol.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{78F2A078-1F75-4C31-B962-0CE047F7C5E3}: NameServer = 192.168.1.1
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 11989 bytes
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm

Re: Here is my Hijackthis file. Please help

Unread postby km2357 » June 21st, 2009, 1:28 pm

Step # 1: Add/Remove Programs

Go to Start-Settings-Control Panel, click on Add Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

PC SpeedScan Pro

Reboot your Computer.



Step # 2 Update Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u14.
  • Click on the link to download Windows Offline Installation and save to your desktop. Do NOT use the Sun Download Manager.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Remove the following old versions of Java:

  • Java 2 Runtime Environment, SE v1.4.2_03

    J2SE Runtime Environment 5.0 Update 3

    J2SE Runtime Environment 5.0 Update 11

    Java(TM) 6 Update 11


  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • From your desktop double-click on the download to install the newest version.


Step # 3: Remove Hijackthis Entries

  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):


    R3 - URLSearchHook: (no name) - - (no file)

    O2 - BHO: FCTBPos00Pos - {A1023BB9-453C-463F-9288-56AE96C52807} - (no file)

    O3 - Toolbar: (no name) - {BB0CBE93-CD99-45B9-BF11-291F1B260698} - (no file)


  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application.


Step # 4: Deleting Files/Folders

I need you to delete the folder I have marked in Red(if found):

c:\program files\Ascentive



Step # 5 Download and Run Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.



In your next post/reply, I need to see the following:

1. MalwareBytes' Log
2. A fresh HiJackThis Log
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3007
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 21st, 2009, 8:14 pm

Malwarebytes' Anti-Malware 1.38
Database version: 2319
Windows 5.1.2600 Service Pack 2

6/21/2009 7:13:27 PM
mbam-log-2009-06-21 (19-13-27).txt

Scan type: Quick Scan
Objects scanned: 118342
Time elapsed: 7 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Adware.Ascentive) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\c:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> Quarantined and deleted successfully.
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 21st, 2009, 8:20 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:19:55 PM, on 6/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/mpfplus/en-us ... popup=true
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O3 - Toolbar: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://www.cnn.com/diskless/bin/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsup ... gctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInCon ... ontrol.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{78F2A078-1F75-4C31-B962-0CE047F7C5E3}: NameServer = 192.168.1.1
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 11856 bytes
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm

Re: Here is my Hijackthis file. Please help

Unread postby km2357 » June 22nd, 2009, 1:22 am

Step # 1 Update Adobe Acrobat Reader

There is a newer version of Adobe Acrobat Reader available. (See Note below)

  • First, go to Add/Remove Programs and uninstall all previous versions.
  • Please go to this link Adobe Acrobat Reader Download Link
  • On the right Untick Adobe Phototshop Album Starter Edition if you do not wish to include this in the installation.
  • Click the Continue button
  • Click Run, and click Run again
  • Next click the Install Now button and follow the on screen prompts

Note: Adobe 9.1.2 is a large program and if you prefer a smaller program you can get Foxit 3.0 instead from http://www.foxitsoftware.com/pdf/rd_intro.php

If you decide to install Foxit 3.0 instead of Adobe, do the following during Foxit's Setup/Installation process:

Uncheck the following boxes:

I accept the License Terms and want to install Foxit Toolbar

Make Ask.com my default search

Create desktop, quick launch and start menu icon to eBay



Step # 2: Run Kaspersky Online Scan

Please go to Kaspersky website and perform an online antivirus scan.

  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  9. Please post this log in your next reply.


In your next post/reply, I need to see the following:

1. Kaspersky Log
2. A fresh HiJackThis Log
3. How is your computer doing, any problems?
User avatar
km2357
MRU Master
MRU Master
 
Posts: 3007
Joined: January 30th, 2007, 2:48 pm
Location: California

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 23rd, 2009, 6:14 am

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:13:56 AM, on 6/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\PayPal\PayPal Plug-In\RBroker.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/mpfplus/en-us ... popup=true
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O3 - Toolbar: eMusic Toolbar - {9ee802e8-c931-47ab-b570-aa8f791598ca} - C:\Program Files\eMusic\tbeMu0.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks\osCheck.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://www.cnn.com/diskless/bin/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsup ... gctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInCon ... ontrol.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{78F2A078-1F75-4C31-B962-0CE047F7C5E3}: NameServer = 192.168.1.1
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FlipShare Service - Unknown owner - C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 12252 bytes
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm

Re: Here is my Hijackthis file. Please help

Unread postby cleanmypc » June 23rd, 2009, 6:15 am

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Tuesday, June 23, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Tuesday, June 23, 2009 05:10:03
Records in database: 2382066
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
J:\

Scan statistics:
Files scanned: 96930
Threat name: 4
Infected objects: 6
Suspicious objects: 0
Duration of the scan: 02:10:59


File name / Threat name / Threats count
C:\Documents and Settings\Tom\My Documents\My Videos\DivX Movies\Sexy Blondie Kayden Kross Rides a Big Cock and gets Tits ....avi Infected: Trojan-Downloader.WMA.GetCodec.z 1
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1648119A.tmp Infected: Trojan-Proxy.Win32.Lager.dp 1
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1E9E68F4.tmp Infected: Email-Worm.Win32.Zhelatin.h 1
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1EE25AA8.tmp Infected: Email-Worm.Win32.Zhelatin.h 1
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1F681415.tmp Infected: Email-Worm.Win32.Zhelatin.h 1
C:\Qoobox\Quarantine\C\RECYCLER\NPROTECT\00204217.vir Infected: EICAR-Test-File 1

The selected area was scanned.
cleanmypc
Active Member
 
Posts: 14
Joined: June 15th, 2009, 11:10 pm
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 41 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware