Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

PLease help with malware (Hijack this log)

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: PLease help with malware (Hijack this log)

Unread postby B Still » July 17th, 2008, 7:35 am

OK.

Here are the file names that avast detected was malware:

Number 1.

File name: C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\popup[2].htm
Malware name: HTML:Agent-L[Expl]
Malware type: Exploit
VPS version: 080717-0, 07/17/2008

Number 2.

File name:C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P9LK70\popup[1].htm
Malware name: HTML:Agent-L[Expl]
Malware type: Exploit
VPS version: 080717-0, 07/17/2008

I tried to "Move to chest" for these but an avast window came up that said.

avast! The process cannot access the file because it is being used by another process.
Cannot process "C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\popup[2].htm" file.

So I had to choose OK. Then the original screen came back and I permanently deleted the files.

After the second deletion the two popups came up anyway, here are their addresses.

Number 1.
hxxp://www.partypoker.com/marketing/pop ... wm=2775836

Number 2.
hxxp://b.amrxchange.com/-Logitech-...
Last edited by Shaba on July 17th, 2008, 9:14 am, edited 1 time in total.
Reason: disabled links
B Still
Regular Member
 
Posts: 18
Joined: July 13th, 2008, 7:52 am
Advertisement
Register to Remove

Re: PLease help with malware (Hijack this log)

Unread postby Katana » July 17th, 2008, 8:28 am

OTMoveIt
Please download OTMoveIt2 by OldTimer and save it to your desktop
  • Double-click OTMoveIt2.exe to run it.
  • Copy the lines in the codebox below.
Code: Select all
[kill explorer]
EmptyTemp
C:\Documents and Settings\David\Desktop\SmitfraudFix.exe
C:\Documents and Settings\David\Desktop\SmitfraudFix
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\*.* /s
c:\program files\need2find
c:\windows\smdat32a.sys
c:\windows\smdat32m.sys
C:\WINDOWS\system32\Process.exe
hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\altnetdm
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}
hkey_current_user\software\need2find
[start explorer]

  • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



It may be a big log, if it is then zip it and attach it to your reply.
User avatar
Katana
MRU Teacher Emeritus
 
Posts: 6412
Joined: November 10th, 2006, 5:00 pm
Location: Manchester

Re: PLease help with malware (Hijack this log)

Unread postby B Still » July 17th, 2008, 9:03 am

Im not to savy with the zipping so...

Explorer killed successfully
< EmptyTemp >
File delete failed. C:\DOCUME~1\David\LOCALS~1\Temp\~DF3279.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\David\LOCALS~1\Temp\~DF328B.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\David\LOCALS~1\Temp\~DF5C5E.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1b4.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
C:\Documents and Settings\David\Desktop\SmitfraudFix.exe moved successfully.
C:\Documents and Settings\David\Desktop\SmitfraudFix moved successfully.
< C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\*.* /s >
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini moved successfully.
File move failed. C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\0b8f04652b412a76467224655237668f14600137[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\1216208980351-integrated[1].jnlp moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\afghanistan-girl[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\asap%20%28350%20x%2020%29[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\bodybg[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\CA7BXNVR moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\CAPG1QU2 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\CAQO7MQW moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\CAS3EV02 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\CAVI469N moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\closeup[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\close[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\ebay_ca[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\frntpage[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\itssw[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\logosm[4].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\newmail[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\next[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\next_w[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\prev[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\prev_w[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\results[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\sabupdate[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\tips_w[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\unite_blue[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\unread[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\wabfind[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\01LPAFM1\wab[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\00_H-Background[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\66_221_37_124[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\8314062243[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\admin[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\admin[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\admin[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\amateurreality_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\box_topr_6699cc[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\CA2AC37P moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\CA9IU0PW moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\CAAJJ0L0 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\CAV8PFZQ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\landstep3[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\logo[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\pfam-pubmed-ismb02[1].pdf moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\text_group[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\yourmabs_net[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\[4] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\1RCD0BQG\[5] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\1pixel[4].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\CA8J622K moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\CA9RRQE1 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\FFFC2D06-197C-40E7-8974-1F4A6DDC7B7D[1].flv moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\fortecgicf3294cd[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\mailboxnote[10].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\mailbox[2].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\Process7685943a[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\rbcgi3m01969556bc[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\results[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\school[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\ViewFilteredProducts-SingleVariationTypeFilter;pgid=yYdgaHqkkjVSR0EUPIQsoQ3D0000vune2pkg;sid=dC31UBxnceT1V1QakIq9VfPAin-aRNEiIc86kQF5in-aRA==0911de05[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4GYZTQYS\webmail1_uwindsor_ca[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\CA1PZR98 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\CAJK5H22 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\CAVT88BP moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\cm[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\fortecgi1e844d1a[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\gomsn[1] moved successfully.
File move failed. C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\pop[1].htm scheduled to be moved on reboot.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\sabupdate[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\style[1].css moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\Sword[1].png moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\viewtopic[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\8M515HB3\3848[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\8M515HB3\CATGPV1F moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\8M515HB3\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\8M515HB3\fortecgid00412ad[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\8M515HB3\incmailboxhighlight[5].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\8M515HB3\mailboxvertline[5].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\8M515HB3\MRUExpert-1[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\8M515HB3\remove[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\11514032[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\904560[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\c-PostAd26e76d4c[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\CAG16BUV moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\CAHYSDPC moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\CAIVT947 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\CALTWYD1 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\CAVQEWKJ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\fabfixture728x90[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\GoWireless08[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\main[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\PropertySearch[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\sasdefinitions[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\sas_processlistrelated[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\sas_processlist[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\vi_footer[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[10] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[11] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[4] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[5] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[6] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[7] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[8] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ASV8TG0V\[9] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\CA1X8PKQ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\CAD2UJHF moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\CAUZTY8W moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\get_video[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\incmailboxestree[9].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\mailboxcontact[6].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\mailboxnode[9].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\oelogo1[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\razorob[1].swf moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\st[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\BA599XQT\ViewFilteredProducts-SingleVariationTypeFilter;pgid=yYdgaHqkkjVSR0EUPIQsoQ3D0000RPxpjmg5;sid=vdXlJQkS28HlJ0FvXyqtIOa0z6AOpsRX6Dcq5BQMIiuDZg==bc7b1a16[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\11777[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\bgrdformbuttons[4].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\bgrdnavigationtabon[6].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\bgrdnavigationtab[7].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\CAR71YHV moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\jump2[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\jump2[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\jump2[4].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\studdisclaimer[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\tygt3-256[1].wmv moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2LI7MPA\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\001[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\CA1K54N1 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\CA5RZCAN moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\CAAPJO11 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\CAC9MLXN moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\CAKZ0DEQ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\cassie-soundtracks-01[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\cassie_2[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\dalineup[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\incjumpbuttons[3].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\increfresh[2].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\mailboxdrafts[4].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\mailboxlastnode[7].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\rocsiterrence[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\rocsi[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\rocsi[4].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\settingbody_bg[1].png moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E35P0B63\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\CA8CGRJK moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\CACZ2AXF moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\CAGPD121 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\incrowmarking[7].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\index[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\mailboxout[5].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\mailboxtask[7].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\showit[1].swf moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EGCSQXSI\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\2734090[1].flv moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\3CABF7EATCAYB6NV6CAAWF5RSCATQSL4BCAPPYJ0YCAZ94SK2CAOBBQ0CCAZ183JNCA1JZL07CAAD7IGDCAI06IXGCAGMEYBOCALKFX4DCAZ4GHTRCA1LIF0RCARV8ZVACA6C1H2MCA4BG5OKCA9DL227CAKDSV94 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\6CA9MJAOPCAJ523J8CALKJUATCAGLXRKWCAK5I4V7CAYYLG9UCAEHYEU9CAZHLUDKCA9MLP2LCAS5F7AJCA1FOHF1CAAXQNFSCANX5MGYCAPNI459CACVGXAVCA216JXWCAFMRTYECAR8NTBPCAPM4AXWCAH2SD9G moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\CA2WZ4K2 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\CAAI2RQB moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\CAE04PFA moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\CAK2EY7T moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\dj.vptcptdn[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\ICA3NJWXRCAVHF76OCAR529HPCAGBXWIKCADEML57CA8EVHVTCANCJDQ0CAZRD5D8CACG27JYCAQY6AFTCAIMJV4KCAGE3FBQCAH775XWCA7YE3PTCA5GZWTNCANTM6KKCAFSGYUSCAXKIZ2GCACOJZ7BCAWERI5V moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\LCAG28C0OCA5SKE40CA5CQ7TUCA6ZMFVACADOH6N9CAGH6LWUCAB8RQRBCA774JPACAAU0GSGCA02GPAYCARY7DPLCAC2B68QCAQ2EXKXCA2SOUGNCAY3S673CAVR41MHCA0C4W48CARE4LDXCAY5FS8JCATEP1M3 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\sas_processlistrelated[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\sas_processlist[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\WCA3N9JWHCAVF3QRCCA54UFHXCA9GASX2CAYGJPE2CAY4LS0XCAJT6ZZ1CAA93IMXCAX0PIHKCAUNQRYBCA0P3OEVCAKLDE7ACAO882J8CA2PLPDGCARN0UKHCAMK2XEICAIPMUQ1CAJAJWH4CA4LQKRICAF4ZZ1C moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\ZCA2XGUBUCAG3VJ35CA4Q0HUFCAH55WZ2CA67325CCA26AJJNCAU2KYR4CA52MVQ0CA01NZKACAQ89KDMCAGKGWGFCA4BUTR3CA8PQC51CA3TSKH8CAP35GGGCAJ5JOMKCAJXUSR6CAEU4FLDCA1QLJDUCAILF4ET moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[10] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[11] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[4] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[5] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[6] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[7] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[8] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EN0YEYXM\[9] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\CAWOHEOU moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\dss[1].exe moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\ebay_ca[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\fortecgi6be9bf9d[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\IconSortArrow1[7].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\icon_post_target_unread[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\incbrowserdetection[7].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\Kinesin[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\newthread[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\remove[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\results[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\H57BJKI1\viewtopic[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\1b8a5d667f1d1f6f0c1c154e855a371e3a5b3189[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\CA1GZ8WG moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\CA2PDGRJ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\CA8W75A3 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\favicon[6].ico moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\fortecgi63052bde[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\fortecgi6be1bf9d[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\fortecgi9e7e8998[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\incbuttonrollovers[6].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\incrows[4].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\oelogo2[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\processFormb6158425[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\runonce2[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\JDW8VB1Q\ViewFilteredProducts-SingleVariationTypeFilter;pgid=yYdgaHqkkjVSR0EUPIQsoQ3D0000I2crDi6u;sid=NUxgFS8WHblgFGdr6s4oEMCzFwbwy-JTYK6v1DIIXn4-Qw==b6a4ede7[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\10_romance[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\135484_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\66_221_37_124[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\admin[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\admin[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\admin[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\admin[4].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\amateurreality_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\banners2[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\CARFH6NZ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\CARTYA0N moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\coachelouise_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\content[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\dnrs_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\fxopen_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\google-tree_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\inline_url_keywords[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\jump2[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\jump2[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\Multisite[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\Multisite[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\Multisite[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\Multisite[4].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\Multisite[5].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\Multisite[6].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\stats[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\stats[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\stats[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\top[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\track[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\track[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\track[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\virtualcitypoker_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\wattlegold_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\wtid[1].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\wt_v1[1].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\wt_v1[2].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\[4] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\[5] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\[6] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\[7] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\KBWGQ9UG\[8] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\11514032[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\11514032[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\11514032[4].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\301-704f[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\904560[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\BCA4B41RXCA09BEVPCASU9L7SCABFD3T9CADHBWCOCA8F5B6YCAGYPN4CCAHIG0MZCAZSTV3OCAHMW5NICAI1MU1YCAHJ2VWHCA3VSC8TCAIGC5N2CAJ2TZR0CATNA0QBCAN33MQWCAPEP6AWCAH1DCO4CAMGBJAZ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\CA2EHKZT moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\CAFKWGEB moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\DCA4S9L90CAL13ZW6CAS8N79CCAMP6L2QCAXNQZ8HCAIOGKXRCAXZK7W1CAARDDT0CAQ48C7KCA0JPYF6CA9C0B1BCA8SIX1NCASVVXL1CAL2Q8PUCAFN20Y1CAEAD7NACAGLM964CANJPQPQCAM2MIJ3CAF4TZCS moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\dj.zuidfxms[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\PCAMJ4SEPCAPKN3D1CA2L7TB7CAI4NIBUCAWR8R64CAIZEQDICA4WCOHXCA7GKGV5CAOPMOJKCADBALM2CAWBAUVACAE71DISCA8WOD5YCA67GPADCALN35NJCAY2A8FBCAKXFVDCCA4QZ8DMCANBOPGNCA27HDWK moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\QCAX6TAI0CA69LBM3CAXKRP2FCAWNPZKHCAY5WGCWCAI7QQ9FCA4S3ECTCABB6XV7CAUODW7DCAZ4WCVYCA0RMMNGCA42OM14CAZ1LA3PCATW2KXICA4D8XY8CAOUEMKBCALY1MTCCA521WUPCADH81DSCAW53RRD moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\rbcgi3m0184bc7706[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\sas_processlistrelated[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\sas_processlist[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\sm_lifestyle[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\styles[1].css moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\WeatherService[1].swf moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\YCAVPD63VCAOVVFP1CAH6MAF2CAA0UBDKCABTETOLCAW9MIY2CAYSH1ERCAAIMP1ECAPLEHNFCAC7R91FCAKEDUK5CAM9KW3UCADBT21WCAMLZ3I2CAZJJBAOCASAK1F0CARBY7RLCA6OQD5VCAARFKFWCA29KTRV moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[10] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[11] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[4] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[5] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[6] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[7] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[8] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MV9IP6B3\[9] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\135484_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\66_221_37_124[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\66_221_37_124[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\66_221_37_124[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\admin[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\admin[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\admin[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\buyersint_com[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\CA414JXW moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\CA7XSW72 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\CAAUZG63 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\CAMJK7VB moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\CAV464WI moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\cm[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\content[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\dj.hwehnpzi[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\dj.kbxjcggk[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\js_flat_1_0[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\jump2[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\Local1998%20new%20pension%20presentation[1].ppt moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\stats[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\stats[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\wtid[1].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NA59VGAI\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\admin[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\admin[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\banners[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\CA62Y6OP moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\CADN0ZKG moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\CAEOC9MX moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\cm[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\DSCN0036[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\fatkid-1[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\fortecgie5d20cbd[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\incimagesubmit[6].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\incresizeframe[2].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\jump2[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\mailboxappointment[4].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\muscle_cell[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\results[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\sd[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\sliding_filaments[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\ViewFilteredProducts-SingleVariationTypeFilter0911de05[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\ViewProductDetail-Start[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NOAXVKLI\WidgetDeliveryService[1].ashx moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\8CAL7ADNSCAWL4PKACA1M7VXACAZ63Y6UCAZQVYE5CABAK378CAQTGR37CA0NMBDTCA5O5Z9LCA4RZ3EYCAE2T03XCA281TTGCARRUZ2TCACYL841CAI5S92LCA5Y09VJCACXPSNPCATRS4AFCAXPRMJVCAGM0VC7 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\904560[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\904560[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\CA2VT1SL moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\CAO2DO6L moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\CAXT5MTJ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\DCAN63B3KCAL4XUBQCAGNJ3M0CAA5AC28CA4Z0QRVCALUPYKYCA67HIBVCAC03V3NCAXW2D00CA5X3O16CAPSQJFDCAF1ZG2XCAL6V551CAYM5FDACAZ1RN1VCAOHC1UCCANLS9MFCAJHLOJZCAWF0DGVCA0IT0CR moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\Disclaimer[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\login[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\sas_processlistrelated[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\sas_processlist[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\vi_beaver_en[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[10] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[11] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[4] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[5] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[6] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[7] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[8] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\O3RMBWWP\[9] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\3CA0L0YY8CAMA1XZGCA6MM2J9CAONF577CA2TAUYNCA4UQ5E4CA2QUQ3ECAFH37ZYCAAA6TIZCAFNYB52CAHHL9N9CAZUS4GUCA3EE2H1CAOF31Q5CAHTHH6QCA4ZC1DXCAF7UBMYCAS04WWECARKU9E1CASOXFYG moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\4CA2L2OMMCADFQ5ATCA8RK5YUCAC8KNH8CA3WJXK8CAWRQ277CABG6YWQCA07D27ECAZXZBI3CA88OD9BCAV8KPBCCA0I7J5TCABQF99BCAC8O2B5CACOVPQWCAQFYYIDCAUEAXWZCASPC3EGCANFQ2Q1CA523IGS moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\5CA4RY7QQCAZTM0DXCAYETMQXCA93ZED4CACU4M86CA09UOT5CAYAOMKUCAARVU97CAQY6IDXCAGOCL2CCAKYO5W7CAW3JBJ4CA50HUFJCARQOHNVCANNOH8XCAC6ZUNJCAZR500FCAKFYOPZCAKAZCHECA0F1O6A moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\66_221_37_124[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\66_221_37_124[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\6CA0762Z6CAR9J4N8CA1B2IZFCAOQ9VZRCAF19IU8CAQ5PMM2CAXORDW3CA7538EKCAP4LEKRCAPXQOJUCAOFJA2XCAK3UFZJCAVBTMQDCA7ZO3X9CAK3N56LCAUQT4KRCA5QO9O3CA06SEWCCAGC6YSKCAF3FV3I moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\8314062243[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\8CA7JNWI2CAE2E9WUCA03C5G6CAW0A5NRCAG68775CAYDJ13DCAIY23YJCAB43NNTCACP0GZQCASX8RB7CAZ7OJWUCA9GAEA3CAIOQ1K7CA1B9A9TCACDMDL2CAR6TK5FCARF0KVUCAFM3LROCA06LAFFCAKB8849 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\8CAOBYS4HCAVYCU9JCAPQIB5CCAHLP5YZCAY6WMIOCA4RNQWMCAF6EFLBCAQ683PSCAFE1KSKCA42LAAWCAWT3UMZCAYXUBYTCAOU5IONCAR9JRT9CAMDZKDGCAZ1UG8OCAOGIDWOCAF5AZH3CA24SQ16CAZ6P3YU moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\9002-50420-2042-8[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\9CAZP32R9CAILNR7OCAFTMRLBCAML09FLCAXRTNVACAWMGF67CADDOCG4CAIYMV26CAYMIY7WCAA2TF5OCA1MPMDFCA914X3ECA6EXW7CCAQ3BS8ZCAL3IB61CAOB761BCAZ2FBZ1CA7HLOBTCA2PPLLECAPSU1NE moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\ACAYLZMA8CAEXFC00CA4J606WCA5XZN04CAZOI5X6CAS2MRP2CA7OEU1JCA6KFYEICARDMJA3CA7TVR9ACA4WJSUHCAYPKMJECAK2F3IRCAPENXE0CAWNZV4XCAJVYNYMCA86ZSCQCA18IB8PCAYFJX9FCAEVYCSV moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\admin[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\admin[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\admin[4].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\CA031BN3 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\CA1V5PUQ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\CAE3J4ID moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\CAFMXHF9 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\env_subnav[1].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\FCAPE6N53CAUGDVONCAFAZBH9CAG9DVH4CAENX2J5CA30LEIWCAZWLI6MCALKCH2PCAFR9Q75CAGLOB83CA68EEISCAVD6ZU0CAT6UCEWCA7X9KQ4CAV2SFRTCA29782RCAMBR464CASDUAZGCA2YKEB9CAO6IC4N moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\FCAUP50H8CAWKGRURCAM0VPGLCAAQBN9FCACP91PBCA5K031WCA5Q30XGCAULNXCDCA1I31W2CAN4RXC6CAHYFUA1CAO2HKBWCAQ320XSCAB3DVQLCAR0F7H1CATI2XOJCA7JK4Q9CASFTGE3CAF2403ZCAEPCB12 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\ICACNH3WLCAWM5MHPCABAZ84PCAJURF2KCAIKC4FYCA29WV7JCASLDIFECA9V1YVACA1WC3OUCADSNOV9CA0A5KBBCA4XXP9RCAP2FWI0CAACSMMICAL9DCNKCAVWT0WECA9J0P7ECAHCIZQ4CAQEVKK5CA3T0POV moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\ICON-1[1].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\inline_keywords[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\jump2[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\jump2[2].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\jump2[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\jump2[5].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\KCA3WSXXCCA6TB2TPCA0HZW0ECANRDVBBCAJFXW9ZCANQHBQQCAPFUWH4CA3IPSRECABUUH8PCAYRV06OCAEFKHSKCAV71B9OCA47ISCQCAQ2Y483CAAYJV2JCAXA2ZMOCA2MYGG2CAJ9NURCCAHLHUQXCAW81NBJ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\MCAZ6S3URCASAFSSECA19UPGFCAE1XUGWCAO31C0NCAFC3P9PCA5YMFUICAJDB5S8CAW236HMCABVVJNDCAOCGED1CA4AP8JCCA51TNQ4CA4Y26QTCABZH03XCAEQD2TZCA319VY1CAY92JSJCAAY55V4CAPLPQWQ moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\RCAAZ7GQUCAFLT1XECA4Y26PWCAOI6768CA23WLMCCALH0F3DCA00NR05CA8TRTZOCASY2Q6GCAESS0LWCATQRKQWCA4WGLVSCA4TI2FACAREFW00CAE4XSIPCAS7UM9FCAKTXAPNCAUD4GICCAX2GD23CAXXMG00 moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\stats[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\UCAJO9RUOCA61T2TGCAUVLX9OCA599ZLUCAHAFS83CASAWY15CA88RSH3CA76HQPXCARIYMRLCAEVD45XCAYDWPARCA4US4PXCA1CHEO5CAETGXV3CAN7Y38MCAC2LSP8CAUQ03ZLCAAP7FMGCAF9H0Z7CAQZNCTD moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\UCAYZ5TC9CA2HBEU2CA5THNO3CA7AN0OECAQGD5DBCAN714GECA8CR1AFCAO0TWCGCAILN36NCA7OKDU3CAKZSPLFCAR7T8MFCA6TN82MCAF89654CAK7GA72CAB41CX5CA2JD40RCALIJJTMCAI6YAD8CAYR5JHP moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\WCAE88Y28CAZ5S583CAGRDW0CCAUOG0N2CAOXG3E6CAHA1ZOOCAGYSDSSCAWSFYBHCAS7EP3TCA0UH4FUCAIDG3G9CAFP09Y3CALK3E22CAV2ZCQVCAN0CL8ICARSCSA2CA80BM6SCA43WWGXCAXY7G1LCAGAF9WX moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\wtid[1].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\YCAN7IKISCA7M7A03CAW6GOFOCADIVT0SCAV9R65WCAPDFSU3CA0PP2P6CAC67S6XCAUAPR16CAQSZ8R5CA0SVHK8CASLPGNYCA3QDI3LCAOVK7VFCAX95C1DCAHKMEUGCACJJP21CAWNG16LCAUV99A4CAJ1N9PP moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\YCASTH3ONCA74LQKOCADF6DE9CADD2KB0CAPJ4G9ZCAA604ROCAUCDKZECAWXOGE7CATPQNVSCAVZD6TKCA25LVYXCAK9J69LCAN8HTZTCA0N4P4YCAU58T6YCAJF4SUPCAYIGRU3CAMNN4BNCAL2AM9DCA5M3L0B moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[10] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[11] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[2] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[3] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[4] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[5] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[6] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[7] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[8] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\QV8FF6VG\[9] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\1216209695865-integrated[1].jnlp moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\CA22FVLE moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\CA5IM1YT moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\CADNWSPU moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\CAI2HEJX moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\CASTPBIN moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\CAYQ0FXT moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\content[1] moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\desktop.ini moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\fig13-4[1].jpg moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\fortecgi03b9b293[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\horizontaldivider[7].gif moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\jump2[3].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\log_ut_err[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\Master[1].png moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\results[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\validation[1].js moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\viewtopic[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\viewtopic[2].htm moved successfully.
File move failed. C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\viewtopic[4].htm scheduled to be moved on reboot.
c:\program files\need2find\bar\Settings moved successfully.
c:\program files\need2find\bar\History moved successfully.
c:\program files\need2find\bar moved successfully.
c:\program files\need2find moved successfully.
c:\windows\smdat32a.sys moved successfully.
c:\windows\smdat32m.sys moved successfully.
C:\WINDOWS\system32\Process.exe moved successfully.
< hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\altnetdm >
Registry key hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\altnetdm\\ deleted successfully.
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0} >
Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}\\ deleted successfully.
< hkey_current_user\software\need2find >
Registry key hkey_current_user\software\need2find\\ not found.
Explorer started successfully
File/Folder not found.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07172008_084155

Files moved on Reboot...
File C:\DOCUME~1\David\LOCALS~1\Temp\~DF3279.tmp not found!
File C:\DOCUME~1\David\LOCALS~1\Temp\~DF328B.tmp not found!
C:\DOCUME~1\David\LOCALS~1\Temp\~DF5C5E.tmp moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_1b4.dat not found!
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\4W8Y2CNO\pop[1].htm moved successfully.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\Y7P8LK70\viewtopic[4].htm moved successfully.
B Still
Regular Member
 
Posts: 18
Joined: July 13th, 2008, 7:52 am

Re: PLease help with malware (Hijack this log)

Unread postby Katana » July 17th, 2008, 10:12 am

Well, that should have moved the problem :)

Let's give it a couple of day's and see if you get any more pop ups.
Let me know how it goes.
User avatar
Katana
MRU Teacher Emeritus
 
Posts: 6412
Joined: November 10th, 2006, 5:00 pm
Location: Manchester

Re: PLease help with malware (Hijack this log)

Unread postby B Still » July 17th, 2008, 2:56 pm

Thanks for all the help.

What is going on that caused this?


David.
B Still
Regular Member
 
Posts: 18
Joined: July 13th, 2008, 7:52 am

Re: PLease help with malware (Hijack this log)

Unread postby Katana » July 17th, 2008, 3:25 pm

It looks like it was a couple of files in your Temporary Internet files that were causing the problem.

It's a good idea to clean them out every so often anyway :)
User avatar
Katana
MRU Teacher Emeritus
 
Posts: 6412
Joined: November 10th, 2006, 5:00 pm
Location: Manchester

Re: PLease help with malware (Hijack this log)

Unread postby B Still » July 17th, 2008, 8:06 pm

Hello katana,

Some bad news.

Avast detected some malware.

Malware 1.

File name: C:\Documents and Settings\David\Local Settings\Tempory Internet Files\Content.IE5\1RCD0BQG\popup[1].htm
Malware name: HTML:Agent-L [Expl]
Malware type: Exploit
VPS version: 080717, 07/17/2008

Malware 2.

File name: C:\Documents and Settings\David\Local Settings\Tempory Internet Files\Content.IE5\4GYZTQYS\popup[1].htm
Malware name: HTML:Agent-L [Expl]
Malware type: Exploit
VPS version: 080717, 07/17/2008

The first warning came; once again I could not move the file but only delete it.
Then the second one came and I deleted that.

Then after this these two pop ups came.

http://www.mansioncasino.com/welcome/in ... l?SID=2183
http://b.amrxchange.com/-Logitech-...
B Still
Regular Member
 
Posts: 18
Joined: July 13th, 2008, 7:52 am

Re: PLease help with malware (Hijack this log)

Unread postby Katana » July 17th, 2008, 8:34 pm

Hmm .... The files are still in your Temp Internet folders,

Where have you been surfing since you used OTMoveIT ?


ATF Cleaner by Atribune
  • Please Download ATF Cleaner
  • Double click ATF.exe
  • Put a check mark next to the items with an X
      Windows Temp X
      Current User Temp X
      All Users Temp X
      Cookies
      Temporary Internet Files X
      History
      Prefetch
      Java Cache X
      Recycle Bin
      Select All

  • Now click Empty Selected then Exit
User avatar
Katana
MRU Teacher Emeritus
 
Posts: 6412
Joined: November 10th, 2006, 5:00 pm
Location: Manchester

Re: PLease help with malware (Hijack this log)

Unread postby B Still » July 18th, 2008, 8:25 am

Hello Katana,

I used the ATF Cleaner last night.

Now, this morning I have the popup problem still here.

First this pop up came up that avast did not detect.
http://www.wixawin.com/ca/ads/choosePin ... 8698628099

Then avast! detected this malware...

File name:C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\03RMBWWP\popup[1].htm
Malware name: HTML:Agent-L[Expl]
Malware type: Exploit
VPS version: 080718, 07/18/2008

I deleted this.

This avast! detected this malware right after...

File name:C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\E2L17MPA\popup[1].htm
Malware name: HTML:Agent-L[Expl]
Malware type: Exploit
VPS version: 080718, 07/18/2008

I deleted this.


After this, these two popups came up..

http://www.partypoker.com/marketing/pop ... wm=2775836

http://b.amrxchange.com/-Logitech-...
B Still
Regular Member
 
Posts: 18
Joined: July 13th, 2008, 7:52 am

Re: PLease help with malware (Hijack this log)

Unread postby Katana » July 18th, 2008, 9:35 am

Have you installed any free programs/screensavers at any time ?
When did this problem start happening?
Did you install any programs just prior to this ?

Download and Run ComboFix (by sUBs)
Please visit this webpage for instructions for downloading and running ComboFix:

Bleeping Computer ComboFix Tutorial

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper
User avatar
Katana
MRU Teacher Emeritus
 
Posts: 6412
Joined: November 10th, 2006, 5:00 pm
Location: Manchester

Re: PLease help with malware (Hijack this log)

Unread postby B Still » July 18th, 2008, 10:07 am

I have never downloaded a screensaver.
The only programs that I remember installing were the Anti-spyware, Anti-Malware and Avast!.

Combofix log.

ComboFix 08-07-17.4 - David 2008-07-18 9:57:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1464 [GMT -4:00]
Running from: C:\Documents and Settings\David\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\David\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\Fonts\acrsec.fon

.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.

2008-07-17 08:41 . 2008-07-17 08:41 <DIR> d-------- C:\_OTMoveIt
2008-07-17 06:06 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-07-16 08:11 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-16 08:10 . 2008-07-16 08:10 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-16 07:58 . 2008-07-16 08:03 <DIR> d-------- C:\Documents and Settings\David\.SunDownloadManager
2008-07-16 07:55 . 2008-07-16 07:55 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-16 07:51 . 2008-07-16 08:13 <DIR> d-------- C:\Program Files\NOS
2008-07-16 07:51 . 2008-07-16 08:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NOS
2008-07-16 05:56 . 2008-07-16 05:56 <DIR> d-------- C:\Deckard
2008-07-07 09:25 . 2008-07-07 09:25 <DIR> d-------- C:\Program Files\Alwil Software
2008-07-07 07:35 . 2008-07-17 15:24 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-07 07:35 . 2008-07-07 07:35 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-06 18:47 . 2008-07-06 18:47 <DIR> d-------- C:\Program Files\FLVHosting
2008-07-06 17:33 . 2008-07-06 17:39 <DIR> d-------- C:\Program Files\The Human Genome Project
2008-07-06 07:40 . 2008-07-06 20:27 <DIR> d-------- C:\Hijackthis log
2008-07-06 07:34 . 2008-07-06 07:34 <DIR> d-------- C:\Program Files\Panda Security
2008-07-06 07:31 . 2008-07-06 07:31 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-06 07:31 . 2008-07-06 07:31 <DIR> d-------- C:\Documents and Settings\David\Application Data\Malwarebytes
2008-07-06 07:31 . 2008-07-06 07:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-06 07:31 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-06 07:31 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-05 18:28 . 2008-07-05 18:28 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-05 18:28 . 2008-07-05 18:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-05 18:25 . 2008-07-05 18:25 <DIR> d-------- C:\Program Files\CCleaner
2008-07-01 06:18 . 2008-07-01 06:18 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-07-01 06:18 . 2008-07-01 06:19 <DIR> d-------- C:\Program Files\Avi Player
2008-07-01 06:18 . 2008-07-01 06:18 36 ---h----- C:\WINDOWS\system32\swk.ini
2008-06-28 18:18 . 2008-07-15 18:58 <DIR> d-------- C:\MBofC
2008-06-28 18:18 . 2008-06-28 18:18 <DIR> d-------- C:\MBoC5 (E)
2008-06-26 12:58 . 2008-07-14 11:08 <DIR> d-------- C:\Program Files\MBoC5
2008-06-26 12:58 . 2008-06-26 12:58 737,280 --a------ C:\WINDOWS\iun6002.exe
2008-06-20 13:41 . 2008-06-20 13:41 245,248 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 06:44 . 2008-06-20 06:44 138,368 -----c--- C:\WINDOWS\system32\dllcache\afd.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-16 12:11 --------- d-----w C:\Program Files\Java
2008-07-16 11:55 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-05 22:27 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-05 22:06 --------- d-----w C:\Program Files\Sonic
2008-07-01 10:18 --------- d-----w C:\Program Files\Common Files\Real
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-17 23:02 --------- d-----w C:\Documents and Settings\David\Application Data\AdobeUM
2008-06-13 22:35 4,680 ----a-w C:\WINDOWS\system32\tmp.reg
2008-06-13 20:44 --------- d-----w C:\Program Files\Trend Micro
2008-06-13 20:40 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-13 20:27 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-06-13 20:27 --------- d-----w C:\Documents and Settings\David\Application Data\SUPERAntiSpyware.com
2008-06-13 20:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-13 20:11 --------- d-----w C:\Program Files\Arensus-1.1.7
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-04 17:55 --------- d-----w C:\Documents and Settings\David\Application Data\U3
2008-05-29 13:35 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-05-19 01:40 82,944 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-05-19 01:40 82,944 ----a-w C:\WINDOWS\system32\404Fix.exe
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 04:55 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2007-07-13 21:50 235,551 ----a-w C:\Program Files\Friday 13-3.pdf
2007-06-28 18:31 23,474 ----a-w C:\Program Files\completing the square.pdf
2007-05-22 11:33 1,035 ----a-w C:\Program Files\INSTALL.LOG
2007-07-26 20:01 114,688 ----a-w C:\Program Files\internet explorer\plugins\ChimeShim.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 04:32 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 08:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
"Avi Player"="C:\Program Files\Avi Player\AviPlayer.exe" [2007-09-05 04:38 629760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 17:56 64512]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 09:20 122940]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 20:13 122880]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2006-02-02 16:11 73728]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-08-25 17:47 356352]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2004-08-17 15:37 184320]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 04:02 761948]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-02 01:38 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-02 01:32 696320]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 00:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 00:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 00:17 118784]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 01:14 155648]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 14:19 69632]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36 256576]
"ScanSoft OmniPage SE 4.0-reminder"="C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" [2005-06-03 16:29 729088]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-07-01 06:17 185896]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 19:19 79224]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-04 18:59 16206848 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 19:50 88204 C:\WINDOWS\agrsmmsg.exe]
"TPSMain"="TPSMain.exe" [2005-05-31 22:00 282624 C:\WINDOWS\system32\TPSMain.exe]

C:\Documents and Settings\David\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2004-06-12 01:57:52 59080]
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54 98632]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2006-01-29 20:57:47 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 19:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 19:16]
R2 MSSQL$CSSQL05;SQL Server (CSSQL05);C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 09:29]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{419c189f-bd8b-11dc-8203-0018de68a3d2}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8438757d-6acc-11dc-81da-0018de68a3d2}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-07-11 14:10:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-18 09:58:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-18 9:59:04
ComboFix-quarantined-files.txt 2008-07-18 13:58:59

Pre-Run: 85,284,892,672 bytes free
Post-Run: 85,355,819,008 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

171 --- E O F --- 2008-07-10 10:05:10


Hijack this log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:01:48, on 7/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Avi Player\AviPlayer.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ScanSoft OmniPage SE 4.0-reminder] "C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Avi Player] "C:\Program Files\Avi Player\AviPlayer.exe" hmw
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .edu/Chemistry/chem227/nucleicfunction/transcription/: C:\Program Files\Internet Explorer\PLUGINS\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan ... stubie.cab
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testge ... nstall.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Fac ... oader3.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Fac ... der4_5.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe

--
End of file - 11054 bytes
B Still
Regular Member
 
Posts: 18
Joined: July 13th, 2008, 7:52 am

Re: PLease help with malware (Hijack this log)

Unread postby Katana » July 18th, 2008, 12:28 pm

OTMoveIt

  • Double-click OTMoveIt2.exe to run it.
  • Copy the lines in the codebox below.
Code: Select all
C:\Documents and Settings\David\Local Settings\Tempory Internet Files\Content.IE5\*.* /s
C:\WINDOWS\system32\swk.ini

  • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Fix With HJT

Close all other windows and then start HiJack This
Click Do A System Scan Only
When it has finished scanning put a check next to the following lines IF still present
O4 - HKCU\..\Run: [Avi Player] "C:\Program Files\Avi Player\AviPlayer.exe" hmw

- Close ALL open windows (especially Internet Explorer!)-
Now click Fix checked
Click yes to any prompts
Close HijackThis

Now reboot and let's see if you get any more popups.
User avatar
Katana
MRU Teacher Emeritus
 
Posts: 6412
Joined: November 10th, 2006, 5:00 pm
Location: Manchester

Re: PLease help with malware (Hijack this log)

Unread postby B Still » July 18th, 2008, 5:22 pm

Here is the OTMoveIT2 log.

< C:\Documents and Settings\David\Local Settings\Tempory Internet Files\Content.IE5\*.* /s >
File/Folder C:\Documents and Settings\David\Local Settings\Tempory Internet Files\Content.IE5\*.* not found.
C:\WINDOWS\system32\swk.ini moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07182008_171258

I did everything else and rebooted.
B Still
Regular Member
 
Posts: 18
Joined: July 13th, 2008, 7:52 am

Re: PLease help with malware (Hijack this log)

Unread postby Katana » July 18th, 2008, 5:40 pm

Let me know as soon as you get a pop up
User avatar
Katana
MRU Teacher Emeritus
 
Posts: 6412
Joined: November 10th, 2006, 5:00 pm
Location: Manchester

Re: PLease help with malware (Hijack this log)

Unread postby B Still » July 19th, 2008, 8:30 am

Hello Katana,

Thanks for the all the help so far.

Everything seems to be good since the last adjustment.

I will let you know as soon as there is a popup if one comes.
B Still
Regular Member
 
Posts: 18
Joined: July 13th, 2008, 7:52 am
Advertisement
Register to Remove

PreviousNext

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 491 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware