Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack Log - Laptop computer


  • Please log in to reply
14 replies to this topic

#1 chugg

chugg

  • Members
  • 581 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 15 January 2008 - 11:43 AM

Ok this is my 2nd hijack log. I have another one on my other computer just fyi. This is a lapstop. I allowed my assistant to use this computer and it did not have any protection and he really messed it up with viruses I think. Thank you in advance for all of your help. In the end I would like to set up a remote desktop to my desktop computer.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:04 AM, on 1/16/2000
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
c:\program files\verizon wireless\venturi\Client\ventc.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\WinAntiSpyware 2007\was7.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 03
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [cPadAlarm] C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
O4 - HKLM\..\Run: [uwas7cw] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe" -c
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1143645882896
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1143645963102
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
O23 - Service: Venturi Client (Venturi2) - Venturi Wireless - c:\program files\verizon wireless\venturi\Client\ventc.exe

--
End of file - 8574 bytes

BC AdBot (Login to Remove)

 


m

#2 bamajim

bamajim

  • Members
  • 894 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 22 January 2008 - 02:32 PM

chugg

Sorry for the delay.

Please download Combofix and save to your desktop:Note: It is important that it is saved directly to your desktop
Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the contents of the C:\ComboFix.txt into your next reply.
Note: Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.

Posted Image
Microsoft MVP - Windows Security

#3 chugg

chugg
  • Topic Starter

  • Members
  • 581 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 24 January 2008 - 11:55 PM

Bamajim,
Thank you for helping. This computer is kinda bad. I had an assistant that used it and its pretty jacked up now cause i never had virus protection. I followed your instructions and downloaded combofix. When I double click combofix on my desktop a blue window pops up and runs a scan. at the end of teh scan it says preparing log. Then the window goes away and no log pops up and i cant find one anywhere. What should I do?

#4 bamajim

bamajim

  • Members
  • 894 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 25 January 2008 - 10:06 AM

chugg

The log is by default located at C:\Combofix.txt. See if you can find it there.
Some heavily infected machines do present problems. If the Combofix log cannot be found, rerun Combofix and post the results of the new Combofix log.
If no luck there, then Reboot into Safe mode and run it from there.
Posted Image
Microsoft MVP - Windows Security

#5 chugg

chugg
  • Topic Starter

  • Members
  • 581 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 25 January 2008 - 08:05 PM

I hope this is what you meant below.


ComboFix 08-01-23.2 - Mike 2008-01-24 21:46:42.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.266 [GMT -7:00]
Running from: C:\Documents and Settings\Mike\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\All Users\Application Data\winantispyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\Craig\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\Craig\Application Data\WinAntiSpyware 2007\Logs\update.log
C:\Documents and Settings\Craig\err.log
C:\Documents and Settings\Guest\err.log
C:\Documents and Settings\Mike\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\Mike\Application Data\winantispyware 2007\Logs\update.log
C:\Documents and Settings\Mike\err.log
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\winantispyware 2007
C:\Program Files\WinAntiSpyware 2007\Activate.dat
C:\Program Files\winantispyware 2007\appupdate.dat
C:\Program Files\winantispyware 2007\AsAgents.dll
C:\Program Files\WinAntiSpyware 2007\AsAgents.xml
C:\Program Files\WinAntiSpyware 2007\atl71.dll
C:\Program Files\WinAntiSpyware 2007\AutoProcess.dat
C:\Program Files\winantispyware 2007\bnlink.dat
C:\Program Files\WinAntiSpyware 2007\database\enemies.dat
C:\Program Files\WinAntiSpyware 2007\database\knownfiles.dat
C:\Program Files\WinAntiSpyware 2007\database\TEBase.dat
C:\Program Files\winantispyware 2007\database\vbpv.dat
C:\Program Files\winantispyware 2007\dbupdate.dat
C:\Program Files\winantispyware 2007\diagnosis.dat
C:\Program Files\winantispyware 2007\fopnl.dll
C:\Program Files\winantispyware 2007\InstHelp.exe
C:\Program Files\winantispyware 2007\InstUp.exe
C:\Program Files\WinAntiSpyware 2007\lapv.dat
C:\Program Files\winantispyware 2007\license.rtf
C:\Program Files\winantispyware 2007\manual.pdf
C:\Program Files\WinAntiSpyware 2007\manual.url
C:\Program Files\WinAntiSpyware 2007\mfc71.dll
C:\Program Files\WinAntiSpyware 2007\monstate.dat
C:\Program Files\WinAntiSpyware 2007\msvcp71.dll
C:\Program Files\winantispyware 2007\msvcr71.dll
C:\Program Files\winantispyware 2007\ps.dat
C:\Program Files\winantispyware 2007\pv.dat
C:\Program Files\WinAntiSpyware 2007\quaratine.dat\#post_quarantine
C:\Program Files\WinAntiSpyware 2007\readme.rtf
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\61e7d112045f44f32c1fc08e\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\61e7d112045f44f32c1fc08e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\61e7d112045f44f32c1fc08e\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\79b0fbe849514fb480df5184\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\79b0fbe849514fb480df5184\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\79b0fbe849514fb480df5184\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\a8b6a4b8282a40485dfd59b4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\a8b6a4b8282a40485dfd59b4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\a8b6a4b8282a40485dfd59b4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\b7c267c409d444dbb54164bc\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\b7c267c409d444dbb54164bc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\2c7a49f6c8624ea75136df93\b7c267c409d444dbb54164bc\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\1c4ff0f01c4244278bb49587\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\1c4ff0f01c4244278bb49587\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\1c4ff0f01c4244278bb49587\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\2c683970d7ad4105ad1709a5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\2c683970d7ad4105ad1709a5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\2c683970d7ad4105ad1709a5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\83a2d0993e264d3982bdebb1\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\83a2d0993e264d3982bdebb1\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\83a2d0993e264d3982bdebb1\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\e7983be1da07427dac096fbf\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\e7983be1da07427dac096fbf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\497c38c0649446ddd00b59b5\e7983be1da07427dac096fbf\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\003eee157e2644cbacbb9db1\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\003eee157e2644cbacbb9db1\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\003eee157e2644cbacbb9db1\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\0b5de97ac4b24a16549b4e9c\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\0b5de97ac4b24a16549b4e9c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\0b5de97ac4b24a16549b4e9c\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1119944a61c24dc7a45815b5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1119944a61c24dc7a45815b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1119944a61c24dc7a45815b5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\11c71b515db84246a6a4a0b3\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\11c71b515db84246a6a4a0b3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\11c71b515db84246a6a4a0b3\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\13d37263f9934773b92f0c94\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\13d37263f9934773b92f0c94\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\13d37263f9934773b92f0c94\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\13f1aa4993a0442f978ddba4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\13f1aa4993a0442f978ddba4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\13f1aa4993a0442f978ddba4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\13f1aa4993a0442f978ddba4\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1663d6204118410c36140c83\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1663d6204118410c36140c83\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1663d6204118410c36140c83\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1663d6204118410c36140c83\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\196bccc9958f4732c2021baf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\196bccc9958f4732c2021baf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\196bccc9958f4732c2021baf\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\196bccc9958f4732c2021baf\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1f5d4dd7c47c4a2d5d3612a3\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1f5d4dd7c47c4a2d5d3612a3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1f5d4dd7c47c4a2d5d3612a3\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\1f5d4dd7c47c4a2d5d3612a3\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\22acc93757ae4c1378db84b5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\22acc93757ae4c1378db84b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\22acc93757ae4c1378db84b5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\22acc93757ae4c1378db84b5\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\25ce114a8c6a44722344d5ac\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\25ce114a8c6a44722344d5ac\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\25ce114a8c6a44722344d5ac\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\25ce114a8c6a44722344d5ac\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2a167a41956147759141bd8c\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2a167a41956147759141bd8c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2a167a41956147759141bd8c\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2a167a41956147759141bd8c\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2ce491848e924e6ee5550db0\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2ce491848e924e6ee5550db0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2ce491848e924e6ee5550db0\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2e677af1a5df48b4a185f28e\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2e677af1a5df48b4a185f28e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\2e677af1a5df48b4a185f28e\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\33f8814821084b9b79cbeabd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\33f8814821084b9b79cbeabd\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\33f8814821084b9b79cbeabd\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\33f8814821084b9b79cbeabd\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\344b7712ddca4c7a2c753288\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\344b7712ddca4c7a2c753288\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\344b7712ddca4c7a2c753288\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\3668db2ccbc944c617407580\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\3668db2ccbc944c617407580\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\3668db2ccbc944c617407580\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\3e51554e79b94897d1d35f86\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\3e51554e79b94897d1d35f86\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\3e51554e79b94897d1d35f86\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\426154be52b64137e81bf2a1\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\426154be52b64137e81bf2a1\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\426154be52b64137e81bf2a1\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\426154be52b64137e81bf2a1\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\4a186ada5d504bb838026b9f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\4a186ada5d504bb838026b9f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\4a186ada5d504bb838026b9f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\4b124866819f4eb5b6698984\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\4b124866819f4eb5b6698984\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\4b124866819f4eb5b6698984\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\575cc82c3f31471ebc0a6fb8\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\575cc82c3f31471ebc0a6fb8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\575cc82c3f31471ebc0a6fb8\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5b85aef5f33d4a9e01faa58a\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5b85aef5f33d4a9e01faa58a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5b85aef5f33d4a9e01faa58a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5b85aef5f33d4a9e01faa58a\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5c9e90d6bbbb463bff40709c\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5c9e90d6bbbb463bff40709c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5c9e90d6bbbb463bff40709c\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5d5081e477804b0e3166bdbe\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5d5081e477804b0e3166bdbe\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5d5081e477804b0e3166bdbe\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5d5081e477804b0e3166bdbe\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5f6611270d344007227c26b8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5f6611270d344007227c26b8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\5f6611270d344007227c26b8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\60c8aecf8e304877a2375bb8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\60c8aecf8e304877a2375bb8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\60c8aecf8e304877a2375bb8\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\62550355b9284dc5baad909c\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\62550355b9284dc5baad909c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\62550355b9284dc5baad909c\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\6661c25ea9c6463fb6977c9a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\6661c25ea9c6463fb6977c9a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\6661c25ea9c6463fb6977c9a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\66ad56f2f3bc4862724ddeab\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\66ad56f2f3bc4862724ddeab\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\66ad56f2f3bc4862724ddeab\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\67e6de121f8446dbb248449d\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\67e6de121f8446dbb248449d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\67e6de121f8446dbb248449d\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\67e6de121f8446dbb248449d\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\6bd76338ba4644cb0995cea4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\6bd76338ba4644cb0995cea4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\6bd76338ba4644cb0995cea4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\716c04ea188f4a414cffafaf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\716c04ea188f4a414cffafaf\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\716c04ea188f4a414cffafaf\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\7175dbafafc64688702c7596\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\7175dbafafc64688702c7596\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\7175dbafafc64688702c7596\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\7175dbafafc64688702c7596\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\79287a202fa54eae6232aa83\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\79287a202fa54eae6232aa83\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\79287a202fa54eae6232aa83\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\7d71385ef87b4d5dc193a59c\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\7d71385ef87b4d5dc193a59c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\7d71385ef87b4d5dc193a59c\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\84426795cb8f4dbc3d0d5080\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\84426795cb8f4dbc3d0d5080\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\84426795cb8f4dbc3d0d5080\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\85b77d9d6b1b437313e529b1\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\85b77d9d6b1b437313e529b1\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\85b77d9d6b1b437313e529b1\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\85b77d9d6b1b437313e529b1\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\862ba17620df4fbc0c9e379c\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\862ba17620df4fbc0c9e379c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\862ba17620df4fbc0c9e379c\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\8d27ca471dbd43813fe7a785\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\8d27ca471dbd43813fe7a785\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\8d27ca471dbd43813fe7a785\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\91a8bcfe96094a298a5a978a\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\91a8bcfe96094a298a5a978a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\91a8bcfe96094a298a5a978a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\a54b253fceee4294232b1398\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\a54b253fceee4294232b1398\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\a54b253fceee4294232b1398\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\a54b253fceee4294232b1398\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\a62319f627c64ed330ee17b5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\a62319f627c64ed330ee17b5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\a62319f627c64ed330ee17b5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\a62319f627c64ed330ee17b5\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\b1f505a59c6c4a42d35510a3\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\b1f505a59c6c4a42d35510a3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\b1f505a59c6c4a42d35510a3\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\b95ee225689d4d5369313f8c\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\b95ee225689d4d5369313f8c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\b95ee225689d4d5369313f8c\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\b95ee225689d4d5369313f8c\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c0571b06ede3470c9663559b\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c0571b06ede3470c9663559b\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c0571b06ede3470c9663559b\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c7d72ac562f44abc6468b2b9\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c7d72ac562f44abc6468b2b9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c7d72ac562f44abc6468b2b9\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c9cfd1adf4c64e597df416a1\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c9cfd1adf4c64e597df416a1\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c9cfd1adf4c64e597df416a1\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c9cfd1adf4c64e597df416a1\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c9e858c34cb245816bc165a3\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c9e858c34cb245816bc165a3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\c9e858c34cb245816bc165a3\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\d060c2ff03b14d3cae312197\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\d060c2ff03b14d3cae312197\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\d060c2ff03b14d3cae312197\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\d7d076eab59a47ab0929578f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\d7d076eab59a47ab0929578f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\d7d076eab59a47ab0929578f\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\d7d076eab59a47ab0929578f\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\da12ab1790d84cfc250511bd\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\da12ab1790d84cfc250511bd\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\da12ab1790d84cfc250511bd\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\da12ab1790d84cfc250511bd\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\da1f73dab2c84a63d5887797\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\da1f73dab2c84a63d5887797\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\da1f73dab2c84a63d5887797\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\db82a8c3fc18448018699b85\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\db82a8c3fc18448018699b85\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\db82a8c3fc18448018699b85\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\dbe3054e110a465f92fdca9f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\dbe3054e110a465f92fdca9f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\dbe3054e110a465f92fdca9f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\dce2d98081014a0812f76397\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\dce2d98081014a0812f76397\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\dce2d98081014a0812f76397\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\ddabf0cb4aa74864dbea4187\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\ddabf0cb4aa74864dbea4187\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\ddabf0cb4aa74864dbea4187\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\ddabf0cb4aa74864dbea4187\Mike
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\e3214d2dac42412e235541ad\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\e3214d2dac42412e235541ad\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\e3214d2dac42412e235541ad\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\e3214d2dac42412e235541ad\Mike
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\e52d6683407e4b8c664de192\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\e52d6683407e4b8c664de192\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\e52d6683407e4b8c664de192\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\ea5f7ea34a6448b3e754a18b\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\ea5f7ea34a6448b3e754a18b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\ea5f7ea34a6448b3e754a18b\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\eabea19a46894a861df54792\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\eabea19a46894a861df54792\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\eabea19a46894a861df54792\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\f471ec2bf39849782c445f81\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\f471ec2bf39849782c445f81\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\f471ec2bf39849782c445f81\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\f75d642815fb47457f241da6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\f75d642815fb47457f241da6\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\1e5ea956f03744b00dc6e282\9f0a0d8d712641e8320f7b9d\f75d642815fb47457f241da6\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\024d58b27acf47bd85dc65a7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\024d58b27acf47bd85dc65a7\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\0489cab562c8471d74920a8c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\0489cab562c8471d74920a8c\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\0ea4acd54f9444c53ab37ea2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\0ea4acd54f9444c53ab37ea2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\12cf9bfc0fd34f1633d59487\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\12cf9bfc0fd34f1633d59487\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\16154fab7d244777e985e094\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\16154fab7d244777e985e094\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\1e2f2deed9d049cffcad6b9e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\1e2f2deed9d049cffcad6b9e\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\1f3faed0d0bd4d0886091abf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\1f3faed0d0bd4d0886091abf\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\20cd98524a714a87976241ac\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\20cd98524a714a87976241ac\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\22cb0a3ab7a64fb6fd5a31b9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\22cb0a3ab7a64fb6fd5a31b9\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\2a548dee9f664e903a421793\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\2a548dee9f664e903a421793\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\337a8ae9555940a5428731a9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\337a8ae9555940a5428731a9\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\386e5b3c040f4617a20754b6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\386e5b3c040f4617a20754b6\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\3fa70cadedb34525293a5e86\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\3fa70cadedb34525293a5e86\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\45eb1c32a18a497587725c9c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\45eb1c32a18a497587725c9c\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\4ae3779058384a7628861e9a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\4ae3779058384a7628861e9a\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\4e16f76682f1469e87237d90\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\4e16f76682f1469e87237d90\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\4fb854893efa4eccc05e5db8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\4fb854893efa4eccc05e5db8\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\546a109994cc444e6fe77096\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\546a109994cc444e6fe77096\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\5a66f0c62fb7463087a8cca6\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\5a66f0c62fb7463087a8cca6\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\5cb8e13e8d03460ec7bf2a8d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\5cb8e13e8d03460ec7bf2a8d\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\62b6b680470942513a328792\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\62b6b680470942513a328792\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\63f17728f13a4f1e9f28dbac\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\63f17728f13a4f1e9f28dbac\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\674c13795d614c9277c09d8e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\674c13795d614c9277c09d8e\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\67da4150e2e74f3f8ddf73b0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\67da4150e2e74f3f8ddf73b0\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\68a74495844946f17bed7a9b\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\68a74495844946f17bed7a9b\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\72ac7f902a694b6b4db0c9aa\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\72ac7f902a694b6b4db0c9aa\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\7b51d51e01244fb2368088a2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\7b51d51e01244fb2368088a2\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\8228096a20b8423714e5d5aa\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\8228096a20b8423714e5d5aa\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\8455dae31cfa44e739695197\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\8455dae31cfa44e739695197\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\88698035d7aa48a01b1200a3\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\88698035d7aa48a01b1200a3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\88698035d7aa48a01b1200a3\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\9a2960ee7d63475922ccfab7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\9a2960ee7d63475922ccfab7\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\9d65821027b34991c72728aa\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\9d65821027b34991c72728aa\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\ad93dcda199d4cbce0c217bc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\ad93dcda199d4cbce0c217bc\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\ae4689919005410aad9117aa\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\ae4689919005410aad9117aa\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\aef48ed612d3400307b82ba1\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\aef48ed612d3400307b82ba1\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\b1152e120e6348265468beb6\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\b1152e120e6348265468beb6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\b1152e120e6348265468beb6\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\bb16e29f420f406a7a39c9a4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\bb16e29f420f406a7a39c9a4\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\c4cc5764df174e3d33da82b7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\c4cc5764df174e3d33da82b7\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\c5ddf697ad12480c6c406d8c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\c5ddf697ad12480c6c406d8c\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\c7abd1f50090467aa0567092\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\c7abd1f50090467aa0567092\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\cd9cb9c4b8e64832040107b7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\cd9cb9c4b8e64832040107b7\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\cedcf73291f94b6744c48a9a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\cedcf73291f94b6744c48a9a\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\d30ef14a21884efa1db83b91\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\d30ef14a21884efa1db83b91\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\de52416b1c4744b040d420a3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\de52416b1c4744b040d420a3\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\e9a090220f614a90468d15bb\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\e9a090220f614a90468d15bb\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\f15281ab651b4fda981b829c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\f15281ab651b4fda981b829c\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\f9af1e10ea8e41ef3a9730ae\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\f9af1e10ea8e41ef3a9730ae\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\fda8e3f42e50487b63245d93\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\fda8e3f42e50487b63245d93\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\fec0f75f7b8841b65cdea58d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\fec0f75f7b8841b65cdea58d\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\ffb443fdb1b740b1e7b8e7b0\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\ffb443fdb1b740b1e7b8e7b0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\31337005cb254bc0e247ac80\ffb443fdb1b740b1e7b8e7b0\#startup
C:\Program Files\WinAntiSpyware 2007\scanlog.xml
C:\Program Files\winantispyware 2007\settings.ini
C:\Program Files\WinAntiSpyware 2007\shellext.dll
C:\Program Files\winantispyware 2007\shellext.xml
C:\Program Files\winantispyware 2007\Summary.dat
C:\Program Files\winantispyware 2007\support.url
C:\Program Files\WinAntiSpyware 2007\tasks.dat
C:\Program Files\winantispyware 2007\threatnet.dat
C:\Program Files\winantispyware 2007\threatnet.ini
C:\Program Files\WinAntiSpyware 2007\unins000.dat
C:\Program Files\winantispyware 2007\unins000.exe
C:\Program Files\winantispyware 2007\uninstall.ico
C:\Program Files\winantispyware 2007\UnWizard.exe
C:\Program Files\winantispyware 2007\unwizard.xml
C:\Program Files\WinAntiSpyware 2007\up.dat
C:\Program Files\WinAntiSpyware 2007\UpdateData\upd0025062000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd0208072000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd0230062000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd0328062000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd0703072000.dat
C:\Program Files\WinAntiSpyware 2007\UpdateData\upd0708072000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd0729062000.dat
C:\Program Files\WinAntiSpyware 2007\UpdateData\upd1005072000.dat
C:\Program Files\WinAntiSpyware 2007\UpdateData\upd1108072000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd1109072000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd1302072000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd1307072000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd1521012000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd1707072000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd1721012000.dat
C:\Program Files\WinAntiSpyware 2007\UpdateData\upd1726062000.dat
C:\Program Files\WinAntiSpyware 2007\UpdateData\upd2017072000.dat
C:\Program Files\winantispyware 2007\UpdateData\upd2101072000.dat
C:\Program Files\WinAntiSpyware 2007\UpdateData\upd2207072000.dat
C:\Program Files\winantispyware 2007\updater.dat
C:\Program Files\winantispyware 2007\was7.exe
C:\Program Files\WinAntiSpyware 2007\WAS7.url
C:\Program Files\WinAntiSpyware 2007\WAS7.xml
C:\WINDOWS\system32\drivers\ApiMon.sys
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\stera.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_FOPN
-------\ApiMon
-------\fopn




((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 04:13 --------- d-----w C:\Program Files\Microsoft Windows OneCare Live
2007-10-28 00:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
.

((((((((((((((((((((((((((((( snapshot@2008-01-23_23.43.09.72 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-12 23:12:25 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB928843\spmsg.dll
+ 2005-10-12 23:12:26 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB928843\spuninst.exe
+ 2005-10-12 23:12:25 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB928843\update\spcustom.dll
+ 2005-10-12 23:12:29 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB928843\update\update.exe
+ 2005-10-12 23:12:34 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB928843\update\updspapi.dll
- 2006-08-17 05:29:06 1,257,472 ----a-w C:\WINDOWS\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2008-01-25 03:53:22 1,265,664 ----a-w C:\WINDOWS\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2006-08-15 08:19:29 1,224,704 ----a-w C:\WINDOWS\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2008-01-25 03:53:24 1,232,896 ----a-w C:\WINDOWS\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2008-01-25 03:55:19 118,784 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_79083979\CustomMarshalers.dll
+ 2008-01-25 03:53:54 61,440 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_fa2215f5\CustomMarshalers.dll
+ 2008-01-25 03:55:04 3,391,488 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_a4ced835\mscorlib.dll
+ 2008-01-25 03:56:07 8,908,800 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_d0436830\mscorlib.dll
+ 2008-01-25 03:55:56 3,395,584 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_3019b200\System.Design.dll
+ 2008-01-25 03:54:46 1,470,464 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_84efb1d6\System.Design.dll
+ 2008-01-25 03:53:59 90,112 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_2f71d063\System.Drawing.Design.dll
+ 2008-01-25 03:55:20 192,512 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_8d481740\System.Drawing.Design.dll
+ 2008-01-25 03:56:00 2,244,608 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_b8697c6a\System.Drawing.dll
+ 2008-01-25 03:54:56 835,584 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_c1d4324d\System.Drawing.dll
+ 2008-01-25 03:55:30 7,884,800 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_0f8c3d9e\System.Windows.Forms.dll
+ 2008-01-25 03:54:13 3,018,752 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_8ea25a33\System.Windows.Forms.dll
+ 2008-01-25 03:54:31 2,088,960 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_88a4e04e\System.Xml.dll
+ 2008-01-25 03:55:46 5,513,216 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_c813c9b6\System.Xml.dll
+ 2008-01-25 03:55:18 4,788,224 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_aca57ea6\System.dll
+ 2008-01-25 03:53:52 1,966,080 ----a-w C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_ee52b5cb\System.dll
- 2000-03-29 08:00:04 167,936 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2008-01-25 03:49:32 167,936 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
- 2000-03-29 08:00:05 81,920 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
+ 2008-01-25 03:49:33 81,920 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
- 2000-03-29 08:00:04 34,304 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2008-01-25 03:49:32 34,304 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2000-03-29 08:00:05 8,192 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2008-01-25 03:49:33 8,192 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2000-03-29 08:00:05 3,584 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2008-01-25 03:49:33 3,584 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2000-03-29 08:00:05 114,688 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2008-01-25 03:49:33 114,688 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2000-03-29 08:00:04 16,384 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2008-01-25 03:49:32 16,384 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2000-03-29 08:00:04 30,720 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
+ 2008-01-25 03:49:32 30,720 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2000-03-29 08:00:05 22,528 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2008-01-25 03:49:33 22,528 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2000-03-29 08:00:04 45,056 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2008-01-25 03:49:32 45,056 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2000-03-29 08:00:04 90,112 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2008-01-25 03:49:32 90,112 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2000-02-19 09:53:42 12,288 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-01-25 03:47:44 12,288 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2000-02-19 09:53:42 135,168 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-01-25 03:47:44 135,168 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2000-02-19 09:53:42 11,264 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-01-25 03:47:45 11,264 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2000-02-19 09:53:42 27,136 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-01-25 03:47:45 27,136 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2000-02-19 09:53:42 4,096 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-01-25 03:47:45 4,096 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2000-02-19 09:53:42 794,624 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-01-25 03:47:45 794,624 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2000-02-19 09:53:42 23,040 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-01-25 03:47:46 23,040 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2000-02-19 09:53:42 286,720 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-01-25 03:47:44 286,720 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2000-02-19 09:53:42 409,600 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-01-25 03:47:44 409,600 ----a-r C:\WINDOWS\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-01-25 03:44:17 32,768 ----a-r C:\WINDOWS\Installer\{C04E32E0-0416-434D-AFB9-6969D703A9EF}\icon.exe
- 2004-07-15 08:49:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2007-04-14 04:30:52 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2004-07-15 08:49:22 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2007-04-14 04:30:52 32,768 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2004-07-15 07:32:22 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2007-04-14 03:57:52 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2003-02-21 02:09:14 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2007-04-14 03:57:58 86,016 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2004-07-15 07:25:06 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2007-04-14 03:56:30 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2004-07-15 07:33:04 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2007-04-14 03:58:00 102,400 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2004-07-15 21:29:02 2,138,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2007-04-14 03:50:46 2,142,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2003-02-21 02:09:18 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2007-04-14 03:58:02 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2004-07-15 07:26:52 2,510,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2007-04-14 03:57:00 2,523,136 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
- 2004-07-15 07:28:34 2,502,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2007-04-14 03:57:28 2,514,944 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2004-08-10 23:20:00 106,496 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2007-01-15 23:11:26 73,728 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2004-07-15 08:49:16 258,048 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_aspnet_isapi.dll
+ 2004-07-15 07:32:22 81,920 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_CORPerfMonExt.dll
+ 2004-07-15 07:24:30 282,624 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_fusion.dll
+ 2004-07-15 07:25:06 315,392 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_mscorjit.dll
+ 2004-07-15 21:29:02 2,138,112 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_mscorlib.dll
+ 2003-02-21 02:09:18 77,824 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_mscorsn.dll
+ 2004-07-15 07:26:52 2,510,848 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_mscorsvr.dll
+ 2004-07-15 07:28:34 2,502,656 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_mscorwks.dll
+ 2003-02-21 11:42:22 348,160 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_msvcr71.dll
+ 2004-07-15 07:34:50 94,208 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\SHADOW4048\_PerfCounter.dll
- 2004-07-15 21:31:16 1,224,704 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2007-04-14 04:35:38 1,232,896 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2004-10-08 13:20:12 1,257,472 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2007-04-14 04:35:46 1,265,664 ----a-w C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2005-01-28 20:44:28 224,768 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2007-10-28 00:40:06 227,328 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
- 2006-04-29 13:07:48 5,533,696 -c--a-w C:\WINDOWS\system32\dllcache\wmp.dll
+ 2007-04-30 15:20:24 5,537,792 -c--a-w C:\WINDOWS\system32\dllcache\wmp.dll
- 2005-01-28 20:44:28 2,370,296 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2006-12-07 05:29:34 2,374,472 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
- 2006-10-04 20:03:45 9,639,336 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-01-02 17:21:38 17,642,616 ----a-w C:\WINDOWS\system32\MRT.exe
- 2005-09-23 14:28:52 270,848 ----a-w C:\WINDOWS\system32\mscoree.dll
+ 2006-12-22 19:28:14 271,360 ----a-w C:\WINDOWS\system32\mscoree.dll
- 2006-09-13 00:51:42 1,245,184 ----a-w C:\WINDOWS\system32\msxml4.dll
+ 2007-05-08 22:03:04 1,275,392 ----a-w C:\WINDOWS\system32\msxml4.dll
- 2005-09-23 14:29:00 6,144 ----a-w C:\WINDOWS\system32\mui\0409\mscorees.dll
+ 2006-12-22 20:02:36 6,144 ----a-w C:\WINDOWS\system32\mui\0409\mscorees.dll
- 2006-09-07 00:43:16 14,048 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-10-27 23:39:36 13,536 ------w C:\WINDOWS\system32\spmsg.dll
- 2006-09-07 00:43:16 22,752 ----a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2005-06-28 17:21:34 22,752 ----a-w C:\WINDOWS\system32\spupdsvc.exe
- 2006-04-29 13:07:48 5,533,696 ----a-w C:\WINDOWS\system32\wmp.dll
+ 2007-04-30 15:20:24 5,537,792 ----a-w C:\WINDOWS\system32\wmp.dll
- 2005-01-28 20:44:28 2,370,296 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-12-07 05:29:34 2,374,472 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2007-05-08 22:06:44 1,275,392 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 19:44 1200128]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"TFNF5"="TFNF5.exe" [2002-06-26 14:43 73728 C:\WINDOWS\system32\TFNF5.exe]
"Tpwrtray"="TPWRTRAY.EXE" [2002-03-19 20:38 217088 C:\WINDOWS\system32\TPWRTRAY.EXE]
"TosHKCW.exe"="C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2002-01-22 18:20 49152]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 10:29 40960]
"TDispVol"="TDispVol.exe" [2002-03-02 12:40 98304 C:\WINDOWS\system32\TDispVol.exe]
"nwiz"="nwiz.exe" [2002-08-15 13:14 438272 C:\WINDOWS\system32\nwiz.exe]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2002-07-09 11:13 126976]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-08-16 10:43 126976]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-08-16 16:18 557056]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2006-07-14 16:54 202032]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-02-10 16:27 1420560]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 15:45 278528]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03 36975]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-05 22:29 180269]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 00:56 158208]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2000-02-19 01:17 155648]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSMPSVC]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00THotkey]
--a------ 2002-04-15 18:35 249856 C:\WINDOWS\System32\00THotkey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cPadAlarm]
--a------ 2002-07-22 15:55 143360 C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2002-05-30 17:23 163840 C:\Program Files\ltmoh\Ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 09:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
--a------ 2001-11-14 03:37 147456 c:\toshiba\ivp\ism\pinger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2000-02-19 01:17 155648 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TcmTray]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFncKy]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TMESBS.EXE]
--a------ 2002-08-02 12:36 77824 C:\Program Files\TOSHIBA\TME3\TMESBS32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-06-07 14:08 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

R0 TVALDX;Toshiba ACPI-Based Value Added Logical Device Extension Driver;C:\WINDOWS\system32\DRIVERS\TVALDX.SYS [2001-08-17 14:27]
R0 TVALG;Toshiba Value Added Logical and General Purpose Device Driver;C:\WINDOWS\system32\DRIVERS\TVALG.SYS [2001-09-13 19:53]
R2 Tmesbs;Tmesbs32;"C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" [2002-08-02 12:36]
R3 tsdhd;TOSHIBA SD Card Host Controller Driver;C:\WINDOWS\system32\DRIVERS\tsdhd.sys [2002-04-04 19:12]
S3 pciSd;pciSd;C:\WINDOWS\system32\DRIVERS\tossdpci.sys [2002-01-07 19:16]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\pwi_bus.sys [2005-05-04 09:59]
S3 pwi_mdfl;Curitel PC Card Filter;C:\WINDOWS\system32\DRIVERS\pwi_mdfl.sys [2005-05-04 10:00]
S3 pwi_mdm;Curitel PC Card Drivers;C:\WINDOWS\system32\DRIVERS\pwi_mdm.sys [2005-05-04 10:00]
S3 pwi_oflt;Curitel PC Card OHCI Filter;C:\WINDOWS\system32\DRIVERS\pwi_oflt.sys [2005-05-04 10:01]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\pwi_serd.sys [2005-05-04 10:01]
S3 SMNDIS5;SMNDIS5 NDIS Protocol Driver;C:\PROGRA~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS [2005-03-29 18:09]
S3 toslane;Toshiba BT-LANE;C:\WINDOWS\system32\DRIVERS\TOSRFLAN.sys [2002-02-07 16:24]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2002-08-08 05:59]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93d0d251-c5ac-11da-a4ae-00022d58f892}]
\Shell\AutoRun\command - F:\JDSecure\Windows\JDSecure31.exe

.
Contents of the 'Scheduled Tasks' folder
"2000-01-25 04:17:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe-Scan -ScanType config -Privileges restricted
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-24 21:48:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
-> C:\WINDOWS\system32\TDispVol.dll
.

Edited by chugg, 25 January 2008 - 08:08 PM.


#6 bamajim

bamajim

  • Members
  • 894 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 25 January 2008 - 08:53 PM

chugg

Tha's it. Rerun Hijackthis and post a fresh Hijackhtis log
Posted Image
Microsoft MVP - Windows Security

#7 chugg

chugg
  • Topic Starter

  • Members
  • 581 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 26 January 2008 - 10:01 PM

i am getting all kinds of error popups when i restart my cpu. here is the log. please bear with my typing. i broke my hand last nite. also, please let me know when i can set up a remote desktop.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:59, on 2008-01-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MSMPSVC.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
c:\program files\verizon wireless\venturi\Client\ventc.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\system32\TDispVol.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-4179051517-135449575-3207847200-501\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Guest')
O4 - HKUS\S-1-5-21-4179051517-135449575-3207847200-501\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Guest')
O4 - HKUS\S-1-5-21-4179051517-135449575-3207847200-501\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Guest')
O4 - HKUS\S-1-5-21-4179051517-135449575-3207847200-501\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe" (User 'Guest')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/...nSSWebAgent.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1143645882896
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1143645963102
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
O23 - Service: Venturi Client (Venturi2) - Venturi Wireless - c:\program files\verizon wireless\venturi\Client\ventc.exe

--
End of file - 7156 bytes

Edited by chugg, 26 January 2008 - 10:04 PM.


#8 bamajim

bamajim

  • Members
  • 894 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 28 January 2008 - 10:53 AM

chugg

Sorry to hear about your hand.

i am getting all kinds of error popups when i restart my cpu. here is the log. please bear with my typing. i broke my hand last nite. also, please let me know when i can set up a remote desktop.
What kind of error pop ups? Be specific as possible, what do they say, etc.

Let's hold off on the remote desktop untill we are sure this PC is clean
Posted Image
Microsoft MVP - Windows Security

#9 chugg

chugg
  • Topic Starter

  • Members
  • 581 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 28 January 2008 - 02:25 PM

ok the popus are as follows.

1- windows live care once system is not working or has been stopped.

2- microsoft box saying the same thing

3- windows defender- application failed to initialize 0x800106ba. a problem caused windows defender service to stop.

4- touchED error retrieval of THotkey failed error code 0x00031402, 0x00000002

5- system configuration utility- you have used the system configuration utility to make changes to the way windows starts.
when i click ok there then a system config utility pops up and it wants me to restart my computer every time to let the changes i never made take effect.

Edited by chugg, 28 January 2008 - 02:28 PM.


#10 bamajim

bamajim

  • Members
  • 894 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 29 January 2008 - 09:02 AM

chugg

Those appear to be operating system problems, not infection related.

1. Do you have the XP OS (XP operating System) disk thgat came witht he PC, we are going to need it.

2. Rerun Combofix and post a fresh Combofix log
Posted Image
Microsoft MVP - Windows Security

#11 chugg

chugg
  • Topic Starter

  • Members
  • 581 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 04 February 2008 - 09:49 PM

I do not have that disc. Im sorry. I dont think the cpu came with it. Here is the log. Sorry it took so long. I had some things to deal with. Once again thanks for your help.'

ComboFix 08-02.05.3 - Mike 2008-02-04 19:45:06.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.241 [GMT -7:00]
Running from: C:\Documents and Settings\Mike\Desktop\ComboFixnew.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-05 to 2008-02-05 )))))))))))))))))))))))))))))))
.

2008-01-24 20:43 . 2007-07-09 06:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 02:09 --------- d-----w C:\Program Files\Microsoft Windows OneCare Live
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2006-07-18 08:04 28,416 ----a-w C:\Documents and Settings\Mike\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 19:44 1200128]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"TFNF5"="TFNF5.exe" [2002-06-26 14:43 73728 C:\WINDOWS\system32\TFNF5.exe]
"Tpwrtray"="TPWRTRAY.EXE" [2002-03-19 20:38 217088 C:\WINDOWS\system32\TPWRTRAY.EXE]
"TosHKCW.exe"="C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2002-01-22 18:20 49152]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 10:29 40960]
"TDispVol"="TDispVol.exe" [2002-03-02 12:40 98304 C:\WINDOWS\system32\TDispVol.exe]
"nwiz"="nwiz.exe" [2002-08-15 13:14 438272 C:\WINDOWS\system32\nwiz.exe]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2002-07-09 11:13 126976]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-08-16 10:43 126976]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-08-16 16:18 557056]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2006-07-14 16:54 202032]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-02-10 16:27 1420560]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 15:45 278528]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03 36975]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-05 22:29 180269]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 00:56 158208]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2000-02-19 01:17 155648]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00THotkey]
--a------ 2002-04-15 18:35 249856 C:\WINDOWS\System32\00THotkey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cPadAlarm]
--a------ 2002-07-22 15:55 143360 C:\Program Files\Synaptics\SynTP\cPad\AlarmWatcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2002-05-30 17:23 163840 C:\Program Files\ltmoh\Ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 09:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
--a------ 2001-11-14 03:37 147456 c:\toshiba\ivp\ism\pinger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2000-02-19 01:17 155648 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TcmTray]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFncKy]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TMESBS.EXE]
--a------ 2002-08-02 12:36 77824 C:\Program Files\TOSHIBA\TME3\TMESBS32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-06-07 14:08 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

R0 TVALDX;Toshiba ACPI-Based Value Added Logical Device Extension Driver;C:\WINDOWS\system32\DRIVERS\TVALDX.SYS [2001-08-17 14:27]
R0 TVALG;Toshiba Value Added Logical and General Purpose Device Driver;C:\WINDOWS\system32\DRIVERS\TVALG.SYS [2001-09-13 19:53]
R2 Tmesbs;Tmesbs32;"C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" [2002-08-02 12:36]
R3 tsdhd;TOSHIBA SD Card Host Controller Driver;C:\WINDOWS\system32\DRIVERS\tsdhd.sys [2002-04-04 19:12]
S3 pciSd;pciSd;C:\WINDOWS\system32\DRIVERS\tossdpci.sys [2002-01-07 19:16]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\pwi_bus.sys [2005-05-04 09:59]
S3 pwi_mdfl;Curitel PC Card Filter;C:\WINDOWS\system32\DRIVERS\pwi_mdfl.sys [2005-05-04 10:00]
S3 pwi_mdm;Curitel PC Card Drivers;C:\WINDOWS\system32\DRIVERS\pwi_mdm.sys [2005-05-04 10:00]
S3 pwi_oflt;Curitel PC Card OHCI Filter;C:\WINDOWS\system32\DRIVERS\pwi_oflt.sys [2005-05-04 10:01]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\pwi_serd.sys [2005-05-04 10:01]
S3 toslane;Toshiba BT-LANE;C:\WINDOWS\system32\DRIVERS\TOSRFLAN.sys [2002-02-07 16:24]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2002-08-08 05:59]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{93d0d251-c5ac-11da-a4ae-00022d58f892}]
\Shell\AutoRun\command - F:\JDSecure\Windows\JDSecure31.exe

.
Contents of the 'Scheduled Tasks' folder
"2000-01-25 04:17:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe-Scan -ScanType config -Privileges restricted
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-04 19:46:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\system32\TDispVol.dll
.
Completion time: 2008-02-04 19:47:48
ComboFix-quarantined-files.txt 2008-02-05 02:47:44
.
2008-01-26 01:17:06 --- E O F ---

#12 bamajim

bamajim

  • Members
  • 894 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 05 February 2008 - 08:10 AM

chugg

I don't see anyting else malware spyware related causing your problem. Let's do this go back into msconfig and re -enable everything you have disabled. Reboot your PC

1. See how that effects the error messages you are receiving

2. Post a fresh Hijackthis log
Posted Image
Microsoft MVP - Windows Security

#13 chugg

chugg
  • Topic Starter

  • Members
  • 581 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 05 February 2008 - 02:33 PM

chugg

I don't see anyting else malware spyware related causing your problem. Let's do this go back into msconfig and re -enable everything you have disabled. Reboot your PC

1. See how that effects the error messages you are receiving

2. Post a fresh Hijackthis log



im sorry but I am not that advanced so I am not sure how to get into msconfig. Also, can you please help me ad what I need to keep my computer safe as far as virus protection and such. If I have to go somewhere else to do this let me know. But on my other computer they did this for me on the hijack forum. Once again thanks for your help.

#14 bamajim

bamajim

  • Members
  • 894 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 05 February 2008 - 02:46 PM

chugg

No problem. To reset msconfig.

Click Start ->> Run ->> type in msconfig ->> O.K.
When the msconfig window opens, under the General tab
Hilight the Normal Start up radio button.
Then Select Apply then O.K.
Close the configuration utility window and reboot your PC

You may now remove/delete/uninstall the tools we used to clean your PC

Now that your log is clean

There are some final notes:
Disable and Enable System RestoreLets create a clean System Restore point
the instructions are here
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:Download the latest version of
Java Runtime Environment (JRE) 6.u4.
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the "Download" button to the right.
Check the box that says: "Accept License Agreement".
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u4-windowsi586-p.exe to install the newest version.
Update your Anti Virus Software

Use and maintain a Firewall There is a list HEREAll of which are free
Download and install SiteHound by Firetrust for protection against malicious websites.

Pick the version that matches your browser

Visit Microsoft's Windows Update Site Frequently for critical updates

Backup your Important Documents and Files on a regular basisTo a disc or a USB key, not your Hardrive
You may want to read this article"So how did I get infected in the first place" by Tony Klein

surf safe
Posted Image
Microsoft MVP - Windows Security

#15 chugg

chugg
  • Topic Starter

  • Members
  • 581 posts
  • OFFLINE
  •  
  • Local time:01:54 PM

Posted 10 February 2008 - 11:28 PM

Thanks so much bamajim. I followed all of your instructions as directed and when I got to the part of getting sitehound this is where I got stuck. No matter what email address I put in it says it already exists and I cannot go any further. I will figure it out somehow though. Thanks again!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users