Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Just checking


  • This topic is locked This topic is locked
11 replies to this topic

#1 chevyusa1

chevyusa1

  • Members
  • 111 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 05 February 2005 - 12:42 PM

Just wanted to post my HJT Log, this is after removing 12 go!zilla registry entries, I use Microsoft Antispy Beta. Log follows:

Logfile of HijackThis v1.99.0
Scan saved at 12:37:24 PM, on 2/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\Norton SystemWorks\NORTON~1\NPROTECT.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\PROGRA~1\Norton SystemWorks\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4DE6A5A-6D12-49BD-9F18-30D4DD65FE5F}: NameServer = 204.157.3.13 205.137.48.5
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\Norton SystemWorks\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\Norton SystemWorks\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

BC AdBot (Login to Remove)

 


#2 pskelley

pskelley

  • Members
  • 1,487 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 PM

Posted 05 February 2005 - 01:15 PM

Hi chevyusa1, Welcome to BleepingComputer. Your log is clean. Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/t/2520/how-did-i-get-infected/

Thanks...pskelley
BleepingComputer.com
http://www.bleepingcomputer.com/supportus.php
If you are reading this information...thank a teacher, If you are reading it in English...thank a soldier.
MS-MVP Windows Security 2007-08
Proud Member ASAP
UNITE Member 2006

#3 chevyusa1

chevyusa1
  • Topic Starter

  • Members
  • 111 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 05 February 2005 - 08:23 PM

Thanks pskelley!
well now I have another problem/s, I was following the links provided in the reply on this topic and as suggested I was doing a Bitdefender online scan, all was going well but suddenly during the scan my comp. crashed and rebooted. After reconnecting to the internet I tried to go back to the Bitdefender site and retry the online scan but now the webpage acts just like the Windows update site, it is just blank, will not load! I am completely frustrated with this machine and I really don't want to have to reformat, mainly because I'm too lazy to make backups and do not even know how. sad but true! Can this stuff be fixed without a reformat? Thanks for any help!.....again :thumbsup:

#4 pskelley

pskelley

  • Members
  • 1,487 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 PM

Posted 05 February 2005 - 08:43 PM

Well my friend, I am wondering why you were doing this scan when I had just told you the computer was free of malware? I would not attempt to run that item again, try rebooting a couple of time to see what happens.
pskelley
MS-MVP Windows Security 2007-08
Proud Member ASAP
UNITE Member 2006

#5 chevyusa1

chevyusa1
  • Topic Starter

  • Members
  • 111 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 05 February 2005 - 09:26 PM

Well my friend, I am wondering why you were doing this scan when I had just told you the computer was free of malware? I would not attempt to run that item again, try rebooting a couple of time to see what happens.
pskelley

Not trying to be arguementative, just answering your question.
But I have one for you first: Just because HJT Log is clean means my comp. is totally clean?
I don't think so, HJT missed 12 Gozilla entries....not 1 or evn 2......12!
Norton AV, Spybot S&d, Adaware SE,CWShredder,System Security suite, And a whole list of online scans missed them as well!
While researching my problems with Windows Update page not loading, I found Microsoft Antispyware Beta, I dowloaded and installed it and ran a scan and that is how I found the 12 mentioned registry entries.
Then I posted this new topic with the new HJT log, in your first reply pskelley you provided links for me to peruse, thanks! I clicked on the first 1 and while reading it I noticed that 1 of the free online scans suggested in that topic was BitDefender. Thats probably the only online scan I haven't done in the past couple of weeks or so. So I ran it. That's the only reason. I had no reason to run the scan that found the 12 gozillas either. Well other then the fact that I'm still having problems with my comp!

#6 chevyusa1

chevyusa1
  • Topic Starter

  • Members
  • 111 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 05 February 2005 - 10:07 PM

As advised, I rebooted, actually 3 times. Then I got back online and went to Bitdefender online scan again. This time the scan completed but I couldn't get it to clean what it found. There is a message on the Bitdefender page that says some maleware will not let you get past the scan process in order for bitdefender to clean what it finds. This is what happened to me I suspect. Well I copied the text of what it found so I could post it here. The following is what BitDefender found but could not clean:

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs2.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs2.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>index.dat: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@1071443335[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@1072254829[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@1072572700[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@bleepingcomputer[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@google[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@kount[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@www.mcssl[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@www.paretologic[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>owner@www.paypal[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip=>index.dat: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip=>owner@bleepingcomputer[2].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip=>owner@google[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip=>owner@www.paypal[1].txt: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD1.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD1.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD2.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD2.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw1.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw1.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw2.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw2.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw3.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw3.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSRegedit.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSRegedit.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSRegedit1.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSRegedit1.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSRegedit2.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSRegedit2.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip=>CD Drive.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip=>Track01.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip=>UnHookExec.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer11.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer11.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer12.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer12.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer13.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer13.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer14.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer14.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip=>Administrator.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip=>Desktop.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip=>Docs.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip=>ntuser.dat.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip=>UnHookExec.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip=>update_readme.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer16.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer16.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer17.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer17.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer18.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer18.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer19.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer19.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer20.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer20.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer21.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer21.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip=>backup-20050202-205854-364.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip=>backups.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip=>HijackThis.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip=>startuplist.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer23.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer23.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer24.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer24.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer25.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer25.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>20050121.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>20050201.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>AB LogFile.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>AboutBuster (2).lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>AboutBuster.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>comp.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>Cookies.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>Desktop.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>hijackthis.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>index.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>inf.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>LuResult.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>My Downloads.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>ntuser.dat.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>Owner.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>report.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>Silent Runners.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>unknown.lnk: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip=>sbRecovery.ini: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsRegistry.zip=>sbRecovery.reg: password protected
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsRegistry.zip=>sbRecovery.ini: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>arrow1.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>arrow2.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bck1.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bck2.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt11.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt12.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt13.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt21.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt22.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt23.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt31.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt32.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt33.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt41.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt42.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt43.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt51.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt52.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt53.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt61.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt62.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox1.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox2.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox3.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox4.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>default.skn: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn1.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn2.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn3.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph1.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph2.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph3.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph4.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph5.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph6.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph7.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>main.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>preview.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>sprite1.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>tab1.bmp: password protected
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>tab2.bmp: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>WPWIN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>123.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>1942.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>2200AD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>3DFX.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>3DHOME.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>3DLAND.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>3DMARK.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>A.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>A2W.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>A5.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AB3.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ABC.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Abcflow.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ACCUSET.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ACDSEE32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ACLT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ACME.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ACRODIST.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Acroexch.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>acrord32.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ACROREAD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ACROUK.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Act.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ACTPMNT.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Actwin2.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AD_NET.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ADAPTER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ADDDEPTH.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ADDRBOOK.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ADMIN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ADOBE GAMMA LOADER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ADOBEREG32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ADVANTGE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Adw30.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Agds16.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Agent.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Agent95.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AHD3.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AHD4.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Ai41.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AIRMOS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ALMANAC.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ALMANC32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ALUNSER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AMIFM.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Amipro.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AMS4.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AMW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AMW4.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ANGEL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ANNOUNCE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ANT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ANYCLEAN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AOL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AOLPHX.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AOLTRAY.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AOLUNINS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APP.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APPARCHV.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APPCLEAN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APPDEL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APPLETVIEWER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APPMOVE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APPROACH.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APPTPORT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>APSTUDIO.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Arcbkup.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ARCHIVER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ARDIAL32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ARTGALRY.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ART-SCAN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ARTSHOW4.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ARUPLD32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ASAP.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ASBROWSE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Ascend50.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ASPELL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ASTEROID.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>ATMCNTRL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Atmfm.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AUTMANIA.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AUTO.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AUTOSTRT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AUTOXL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AVCONSOL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AWEDIT32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AWGATE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AWHOST32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AWONL32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AWRAS32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>AWREM32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>B17.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BAB.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BACKIT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BACKLOG.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BACKTRAC.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BACKWEB.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BAILEY.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BALDUR.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BANNER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BASH1.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BATHROOM.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BATTLE2.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BC4000.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BCC.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BCR.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BD40.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Beast.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BGH2.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BGHCFG.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BIBLE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BIGGAME.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BILLMIND.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BINDER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BIZFORMS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BLOODNET.COM: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BODY3WIN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BOOKMARK.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BPBOX.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BRAVO.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BRIDGE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BS9532.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BTNMENU.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BUD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>BYLEAVE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>C&c.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>C7.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>C86.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Cafe.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CANVAS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CAPEZE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CAPPRO32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CAPTURE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CARMEN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CASINO21.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CAW2.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CBW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CCHAT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CCMAIL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CCPLUS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CCREGMOD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CCRITTER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CCWIN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CDISSS.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CENTRAL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CERTCONS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CF_ENG.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CFSCONV.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CG16EH.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CG32EH.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CGMAIN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CGMENU.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CGW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CHANGER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CHEM.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CHEMDRAW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CHESS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CHEXNOW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CHKVXD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CHMAGENT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CHOMP.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CIV.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CKANLYST.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CKRUN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CKRUN.PIF: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CLARION3.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CLIKAPP.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CLINK.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CLIPPER.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CLNSWEEP.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CM4000.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CMAGENT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CMAPPFRM.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CMDLAGNT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CMUSRPFL.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CNFNOT32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CNNTC94.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>COM32UPD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>COMBATFS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>COMCTL32.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>COMPAT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Conf.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CONQUEST.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CONVDSN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Convert.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>COPYDEFS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Coreldrw.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CORELFLW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CORELGAL.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CORELPNT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CPAV.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CPD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CPRTST16.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CPRTST32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CPTEST16.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CPTEST32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CRAYONS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CROSSWD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CRWACC20.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CS.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CS32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSALLOC4.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSALLOC5.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSAPPL.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSAUTOEX.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSBROWSE.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSCDROM.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSCLOCK.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSCMPORT.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSCONFIG.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSDSPLY.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSFDC.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSFLDRV.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSFS.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSGAME.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSHDC.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSHOP.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSHRDRV.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSINET.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSINI.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSKEYBRD.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSLOGPRB.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSLPPORT.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSMEMORY.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSMODEM.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSMONITR.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSMOUSE.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSNET.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSNETCLI.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSNETIC.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSNETSVC.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSNETTRN.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSPRINT.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSREG.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSSOUND.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSUNDO.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSWIN95.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CSWINCMD.OCX: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CUBIC.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CUNEI.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CUPWIN5.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Custom.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CUTFTP32.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>CW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>D3EDIT.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DARKLAND.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Dash.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DATALNK.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DATASAFE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DAZZLE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DB32W.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DBASE.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>Dbasewin.exe: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DC3.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DCOMP.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DCW.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DCWIN.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DD.EXE: password protected
C:\Program Files\Norton SystemWorks\Norton CleanSweep\clnsweep.cfg=>DD3.EXE: password protected
C:\Pr

#7 pskelley

pskelley

  • Members
  • 1,487 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 PM

Posted 06 February 2005 - 07:46 AM

Good morning chevyusa1, I apologize if there was a misunderstanding. To be sure, we both have your computer and getting it clean of malware in mind. I am a volunteer and certainly would not do this for any other reason.

Let's try to understand this a little. First, remember that HJT is close to a miracle. The little utility allows us to see and remove stuff that is bad easily, but it can not be expected to see everything on your computer. It does key to certain areas that are used by malware writers to infect you.

Now having said that, I can also say I use other scans myself besides BitDefender and I am not real familiar with the log it provides. I do believe it is scanning and reporting the result of the quarantine areas of Ad-aware& Spybot. Not being a Norton user I am not sure about what BitDefender is reporting, if you have items quarantined in Norton, you should consider deleting them also. If Norton placed them in quarantine, I would think they would have to be bad? First I would suggest you empty the quarantine area of each of these software programs. After you are positive there is NOTHING quarantined, than scan again to see if that was the reason for those items.

Here is some information I located that might help get rid of any Go!Zilla registry entries that are still in there:

http://www.geocities.com/spywarekilla/how_...yware.html#auto
Step 4: Cleaning up the registry

This step is optional, and should be only performed if you are adept in transversing around the registry. In other words, you need to know the in's and out's of the registry.

Although Spybot and Ad-Aware usually do a clean job in clearing up spyware, sometimes they leave a few traces here and there. Even though these pieces may not be very dangerous, it's much safer to delete them off than let them sit there, since some of them might still be intact.

Finding spyware in the registry is not that hard as it sounds, it's just time consuming.

First, go to run in the start menu. Click "Run", then type in "regedit". You can use another registry editing program if you like (e.g. Reghance by Lavasoft).
Search (Ctrl + F) the entire registry for spyware keywords like "Web3000", "NetSonic", "gozilla" or "go!zilla".
Then, delete these folders (del).
Click find next (usually F3),
Repeat steps 3 and 4 until there are no more found.
Start from step 2 with another keyword. Proceed after all keywords are done.
Under "hkey_current_user" and "hkey_local_machine", find "software" and browse through all of them.
When you find a suspicious company name that you don't know, double click on it to see what software it manufactures. If you didn't install or use this program, and it's not a driver program, you can safely delete off this registry key.
Usually even if you delete off a software key that you need, it will be re-created. That is why you have to remove the spyware program/host or the registry keys will just be created again.

I would be interesting in your findings, and would like to look at a fresh HijackThis once complete. I will not need the BitDefender log.

Thanks...pskelley
BleepingComputer.com
MS-MVP Windows Security 2007-08
Proud Member ASAP
UNITE Member 2006

#8 chevyusa1

chevyusa1
  • Topic Starter

  • Members
  • 111 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 06 February 2005 - 10:32 AM

And a very good morning to you and everyone at BC!
No misunderstanding, I know that the volunteers here at BC are here to help, and I also know that you have our computer health in mind. I not only respect, but also appreciate very much what you all do. Thank you again!
There were alot of Spybot S&D logs and backups as well as Norton Quarantined items, I have now cleared those items and will be following your instructions from previous post directly. I'm one of those people that cannot give up on anything, I know my comp. still has issues and I will not rest until they are fixed even if it means a total reformat. I know I was hacked back in May of '04. I found a "backdoor" on my comp. I can't remember which program found the "backdoor" but I'm thinking it was Norton AV right after I installed it. But my comp. has never been the same since. I also know that the IP address from Nigeria that I sent to Grinler via PM has been attacking me for quite some time now, like maybe a year. I used to have Zone Alarm and that very same IP# used to come up on my ZA alerts several times per day. My Zone Alarm stopped funtioning and got corrupted so I stopped using and uninstalled it. Then a few days ago I get a Security Alert from my Security Center stating that a virus "W32.HLLP.Spreada.B.spy v2.06" was blocked from reaching my comp. and the IP# that it came from is the same one from Nigeria. I have reported this to my ISP, but don't expect much help from them. I also have a PayPal account and I'm an Ebay seller, both of those accounts have had access attempts made and not by me, I have recieved emails from both Ebay and Paypal stating that someone from an IP address other then mine has made attempts to access my account, and I have changed passwords several time at each account. I feel I'm being targeted by someone. This is just info that helps explain my paranoia.
I will post a new HJT Log after I follow your instructions in your previous post.
Thanks again!! :thumbsup:

Edited by chevyusa1, 06 February 2005 - 10:38 AM.


#9 chevyusa1

chevyusa1
  • Topic Starter

  • Members
  • 111 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 06 February 2005 - 01:38 PM

Ok, I downloaded the SBAI and installed it and followed the directions for cleaning up my registry. The problem is, if I remove every entry that has a name that I don't recognize I'm sure to mess something up real bad. I did delete some entries from programs that I had installed but are no longer installed, but there is alot of stuff in the registry that have me confused. Like, why would I have: "Meusesoft/31 for windows 95" in "HKey_Local_Machine\software\microsoft"? I have windows xp not windows 95. Totally confusing :thumbsup:
But that's just one of many that I have no clue about. Here's my newest HJT Log as requested:

Logfile of HijackThis v1.99.0
Scan saved at 1:18:30 PM, on 2/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\Norton SystemWorks\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\sessmgr.exe
C:\PROGRA~1\Norton SystemWorks\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\SYSDOC32.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\Norton SystemWorks\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\Norton SystemWorks\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#10 pskelley

pskelley

  • Members
  • 1,487 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 PM

Posted 06 February 2005 - 01:59 PM

I wish you luck at finding all of the answrs to your questions. Your Log is clean, good luck. :thumbsup: pskelley
MS-MVP Windows Security 2007-08
Proud Member ASAP
UNITE Member 2006

#11 chevyusa1

chevyusa1
  • Topic Starter

  • Members
  • 111 posts
  • OFFLINE
  •  
  • Local time:07:08 PM

Posted 07 February 2005 - 12:08 PM

Thanks! :thumbsup: I doubt I'll find all of them but I'm trying!
I fixed my Windows Update problem. I disabled my Norton AntiVirus completely and all other Norton System Works programs I had running. Then I ran A squared
AntiVirus, it found a few entries and cleaned them. Then I just started restoring defaults to everything I could think of....if "restore defaults" was an option, I did it. Then after rebooting I logged onto the net and clicked on start/all programs/windows update.....the IE box opened and the page loaded with no errors! I even ran a scan for updates with no problems. Works eveytime now!
Unfortunenately the A squared AV program doesn't save a log, or atleast I haven't found it yet, but I will post what it found and removed if I find the log. That way it may help others who may have or get the same problem with Win Update.
Thanks Again!

#12 pskelley

pskelley

  • Members
  • 1,487 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 PM

Posted 16 March 2005 - 10:24 PM

Thank you for visiting BleepingComputer. Since this problem as been resolved, I will close this thread. Thank you, pskelley
MS-MVP Windows Security 2007-08
Proud Member ASAP
UNITE Member 2006




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users