Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Combofix Log?


  • This topic is locked This topic is locked
18 replies to this topic

#1 crystal13

crystal13

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 25 February 2008 - 09:19 PM

I do not know what is wrong with my computer. I did a boot scan with Avast, and found these: Error42146 {Installer archive is corrupted.}
Error42136 {CHM archive is corrupted.}
Error42127 {CAB archive is corrupted.}
At that point I did a search for the first error and ended up on this site. I clicked on something that I think said OLD TRJ, I think. Then I followed the instruction to
install and run ComboFix. This is the log report:

ComboFix 08-02-25.3 - Crystal 2008-02-25 16:53:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.141 [GMT -6:00]
Running from: C:\Documents and Settings\Crystal\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Starware358
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\celebrity_news.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\celebrity_search.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\findithotxp.png
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\finditxp.png
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\Highlight.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\HighlightHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\highlighthotxp.png
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\highlightxp.png
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\logo.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\buttons\logoxp.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\contexts\Error.xml
C:\Documents and Settings\All Users\Application Data\Starware358\contexts\related.xml
C:\Documents and Settings\All Users\Application Data\Starware358\contexts\Travel.xml
C:\Documents and Settings\All Users\Application Data\Starware358\EntertainmentMarketingSP\images\active\EntertainmentMarketingSP0.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\Games\images\active\Games0.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\Movies\images\active\Movies0.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp
C:\Documents and Settings\All Users\Application Data\Starware358\SimpleUpdate\ProductMessagingConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware358\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware358\SimpleUpdate\SimpleUpdateConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware358\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware358\SimpleUpdate\TimerManagerConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware358\SimpleUpdate\TimerManagerConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware358\U0002F6F8.exe
C:\Documents and Settings\All Users\Application Data\Starware358\U00684D4B.exe
C:\Documents and Settings\All Users\Application Data\Starware358\U00687FA5.exe
C:\Documents and Settings\Crystal\Application Data\SpamBlocker
C:\Documents and Settings\GREGORY\Application Data\SpamBlocker
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\eskin\empty_bg_st.htm
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\eskin\FileManager.txt
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\SpamBlockerUtility.log
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185646222.log
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185920822.log
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1020167.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1020614.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1047045.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1049983.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1055780.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1055998.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1056077.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1056251.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1057411.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1058131.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1064004.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1064372.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1065181.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1066422.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1066790.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1066887.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1069351.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1139319.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1168802.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1218864.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\122069.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1224397.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\134294.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1383704.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1383771.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1384431.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1384887.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1385232.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1385452.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1385540.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1386829.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1387083.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1387730.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1390273.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1390361.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1395210.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1396657.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1400879.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1400989.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1401131.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1401151.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1404802.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1405982.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1410769.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\144984.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\145716.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1544781.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\160699.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1622734.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\166334.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\1806006.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\203378.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2091273.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2208948.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2272093.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2314430.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2381894.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2530568.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2590073.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\263482.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2682264.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2739593.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\277994.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2881352.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2883915.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2884323.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2884426.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2884488.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2894799.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2899625.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2899627.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2899632.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2899639.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\2901962.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3251993.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3305670.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3323218.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\334490.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3346417.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3348393.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3362058.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3367176.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\337842.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\342101.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3421493.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3427200.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3429068.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3442551.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\344723.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\346907.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3472949.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3487369.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\350739.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\358861.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3719779.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3720897.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3731753.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3756141.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3781228.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3783086.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3852400.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3852903.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3858799.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3862708.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3866044.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3866435.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3866552.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3874857.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\3893180.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\40291.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\427607.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\444801.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\48657.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\494774.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\496517.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\508530.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\600583.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\625696.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\654741.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\687752.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\692688.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\694907.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\702068.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\723565.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\724427.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\737654.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\740953.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\761357.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\777882.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\799442.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\805478.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\818228.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\84108.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\859800.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\890068.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\896451.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\928450.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\965522.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\975207.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\976123.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\988740.sdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\domains.txt
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1000029502
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1000047768
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1000048656
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1000067006
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\100902
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\10110
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\10157
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\10685
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\10756
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\10807
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\10858
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\11213
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\116250
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\11637
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\116977
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\117759
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\118874
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\11891
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\12486
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1258
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\126889
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\127499
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13119
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13129
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\131920
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13546
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13562
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13608
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13615
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13617
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13634
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\13939
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\141880
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\14207
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\142323
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\14271
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\14435
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1458
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\146936
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1489
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1491
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1492
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15024
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15026
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15039
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15046
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1509
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15090
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15135
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15162
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15171
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15198
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15333
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\153363
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15473
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15532
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15541
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15596
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15611
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15622
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15643
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1587
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\15870
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1590
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\159328
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\160200
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16072
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16087
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16173
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16176
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16197
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16204
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16210
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16211
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16539
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16612
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1670
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16774
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\168167
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16971
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\16975
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\17025
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\17040
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\1725
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\17519
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\176749
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\177983
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\17805
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\179646
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\18314
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\18383
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\18391
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\184591
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\18571
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\187147
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\18721
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\18909
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\19052
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\19153
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\193206
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\193255
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\193613
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\195461
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\19624
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\19650
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\19677
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\19814
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\198406
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\19943
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\199881
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20106
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20128
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20202
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\2021
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\202699
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20357
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20365
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20478
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20517
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20535
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20549
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20570
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\205886
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20613
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\207953
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20898
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20935
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\20980
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\210198
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\210442
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\21060
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\21119
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\211491
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\21384
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\21698
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\2181
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\21846
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\21889
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22000
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\220566
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22094
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22258
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22265
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22272
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\223385
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\223452
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22364
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22383
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22657
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\227417
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22809
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\228508
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\22913
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\233324
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\23849
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\23889
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\23923
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\23928
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\241510
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\24267
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\243859
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\24625
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\24996
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25031
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25043
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\250532
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\2508
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25134
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\251438
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\251492
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\252276
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25424
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25469
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25471
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25502
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25509
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\257023
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25708
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25735
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25803
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\25911
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26030
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26077
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26125
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26256
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26340
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\264564
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26656
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26664
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26927
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\26932
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\27414
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\27416
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\27503
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\27505
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\277907
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\278063
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\281430
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\28147
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\28207
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\282887
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\28383
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\286256
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\28728
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\28812
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\288733
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\2888
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\290893
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29115
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29135
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29297
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29308
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29425
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29479
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29512
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29633
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29642
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29683
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\29693
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\297237
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\297362
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\3009
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\30431
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\30455
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\30457
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\30458
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\30860
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\31262
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\31391
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\31409
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\31537
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\31551
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32122
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32137
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32148
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32242
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32255
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32290
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32418
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\325323
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32541
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32547
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32614
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32639
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32812
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32830
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32835
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\32851
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\33137
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\33146
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\33362
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\3338
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\33697
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\33880
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\33912
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\3405
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34107
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34118
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34140
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34156
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34174
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34186
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\342303
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34237
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34250
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34267
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34381
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\34952
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35000
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35006
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35015
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35047
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35150
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35463
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35554
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35737
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35804
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\35941
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\36079
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\361427
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\36598
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\36834
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\36837
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\36844
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\36847
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\36971
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\369949
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\37135
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\37207
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\372500
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\376575
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\3796
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\382344
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\38333
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\386635
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\386983
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\38868
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\39245
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\39689
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\398397
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\39850
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\39896
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\39897
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\39947
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\399678
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\40012
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\401323
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\401332
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\40212
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\40256
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\40260
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\402844
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\40999
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41115
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41215
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41364
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41421
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41528
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41556
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41558
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41588
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41875
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\41999
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\42208
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\422123
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\423535
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\42372
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\42376
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\42425
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\42627
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\427148
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\42751
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\42915
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43120
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43142
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43184
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43377
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43384
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43395
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43638
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43715
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43719
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43807
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43811
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4382
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43907
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\43979
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44100
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44228
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44229
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44274
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44293
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44300
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4442
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44458
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44462
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44484
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44496
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\445700
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44789
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4487
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44878
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\44915
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4500
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\450215
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\453218
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\455641
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\455904
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\456535
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\45709
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\45837
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\46021
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4670
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4692
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4753
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\475788
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\47638
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4765
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\477253
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4822
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\482360
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\488149
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\489917
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\491939
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\49587
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\49622
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\49623
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\4967
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\50056
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\507892
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\50887
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\50905
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\51194
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\51374
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\51495
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\515123
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\516057
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\51683
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\51824
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\51875
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\51988
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\52081
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\52253
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\52335
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\526389
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\527634
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\528235
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\528766
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\531510
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\53310
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\53312
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\53481
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\5358
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\53595
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\538263
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\53933
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\5409
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\541369
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54189
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54385
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54469
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54473
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54579
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\547723
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\54979
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\5535
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\55907
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\56113
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\56412
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\56644
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\56726
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\567746
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\56815
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\569524
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\57137
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\572769
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\572891
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\578150
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\578458
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\57878
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\57904
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\57962
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\58197
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\58913
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\58946
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\58960
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\58965
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\58973
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\59234
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\59243
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\595216
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\59576
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\59827
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\59844
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\59872
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6002
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\60421
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\604347
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\60739
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\60785
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\60804
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\60841
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\611216
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61167
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61207
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\612971
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61304
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61367
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61455
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61779
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61795
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61837
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61853
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\61894
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\622354
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\625366
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6292
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6304
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\63264
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6368
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\63806
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\63882
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64404
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64429
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64451
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64467
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64484
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64502
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64517
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64605
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64703
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\64737
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\65019
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\65021
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6546
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6552
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6556
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6562
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\65814
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\65929
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\65933
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6616
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\66228
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\664008
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\66493
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6680
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\66836
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\66852
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67150
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67209
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67215
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67226
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67464
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67466
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67491
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6751
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\67564
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68016
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68021
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68031
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68076
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68148
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68370
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68707
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6873
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68787
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\68942
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\6915
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\691616
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\69201
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\69235
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\69261
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\69263
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\69308
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\69325
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\69556
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\696522
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\702282
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70309
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70447
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70451
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70463
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\705223
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\705434
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\705457
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\705538
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70611
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70614
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70650
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70692
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70773
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70823
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\70981
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\71340
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\71361
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\71531
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72097
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72123
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72748
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\727607
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\727608
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72786
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72807
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72846
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72882
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72889
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\72912
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\73119
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\73218
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\734041
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\73620
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\737665
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\73840
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\738418
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\73905
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\73948
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\741901
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\742100
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\74398
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\74400
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744408
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744431
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744513
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744617
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744627
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744736
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744742
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744758
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744775
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744789
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744813
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744827
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744864
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744869
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744881
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744926
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744930
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744952
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\744977
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745002
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\74503
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745060
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745073
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745115
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745124
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745148
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745175
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745201
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745261
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745263
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745285
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745304
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745331
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745356
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745428
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745433
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745434
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745490
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745732
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745751
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745869
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\745992
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\746017
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\746039
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\747293
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\747716
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\747936
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\74798
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748176
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748329
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748368
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748372
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748380
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748381
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748402
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748437
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\748893
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\750156
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\75089
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\751237
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\751241
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\7518
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\7521
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\752900
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\753198
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\753199
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\753250
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\753277
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\76119
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\76184
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\7652
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\77712
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\78237
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\78592
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\78778
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\7887
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\78920
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79079
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79246
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79257
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79432
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79596
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79683
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79721
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79806
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79824
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79972
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\79989
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\80193
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\80567
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\80657
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\80663
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\80670
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\81293
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\81551
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\81830
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82011
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82126
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82180
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82278
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82292
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82557
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82638
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\82646
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\8271
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\8290
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\8306
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83139
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83216
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83706
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83718
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83732
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83743
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83757
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\83777
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\8443
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\84573
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\84677
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85365
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85381
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85522
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85547
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85568
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85588
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\85952
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86023
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86090
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86100
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86140
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86258
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86379
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86587
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\86837
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\873
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87385
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87389
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87439
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87476
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87499
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87584
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87587
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87594
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87843
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87908
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87994
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\87995
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\88533
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\88586
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\890
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\89075
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\89200
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\8941
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\89462
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\89623
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90008
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90088
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90098
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90149
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90311
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90358
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90826
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90833
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\90835
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\91224
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\91231
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\91238
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\91565
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\916
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\91986
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\92855
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\92886
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\92930
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93110
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\9313
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93192
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\9332
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93682
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93899
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93908
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93909
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93911
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\93921
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\94230
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\94272
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\94392
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\94407
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\94789
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95610
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95615
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95678
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95704
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95710
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95716
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95725
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95779
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95798
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95803
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95825
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95828
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\95917
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\96638
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\9665
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\9672
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\96961
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\97134
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\97498
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\97499
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\97675
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\9770
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\97734
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\97964
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\98351
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\98707
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\99008
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\99071
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\9935
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\99533
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML\99795
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\ustat\3600.dat
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\ads.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\btntrans.idx
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\btntrans1.dat
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\business_promo.htm
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\buttondir.txt
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\components.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\cursors.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_1000.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_2000.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_3000.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_bar.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_bbar1.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_logos.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_buttons_other.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\d_icons_weather.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\default.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz1.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz10.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz11.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz12.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz13.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz14.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz15.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz16.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz17.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz18.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz19.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz2.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz20.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz3.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz4.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz5.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz6.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz7.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz8.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_bidz9.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_categorize.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_comparison.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_em_PROFL_CA_flow_b_IEB.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_explorer-Mails.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_explorer-people.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_fastutilities.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_favorites.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_Games.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_Hide.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_hotbarcom.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_Hotmail.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_hsskin.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_jemster.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_jemsterie.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_jemsteruk.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_jobsearch.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_Mails.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_new.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_premium.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_reun.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_ringtones.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_searchfor.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_searchgo.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_weather.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Default_yellowpages.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\email-t1-bg.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\hb_ie_menu.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\hotbar-premium-hotbar-premium.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\hotbar-premium.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\hotbar_promo.htm
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\icons2.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\ie_games_icon.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\ie_video.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\keywords.idx
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\keywords1.dat
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\layout.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\linkpathlegal.txt
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\progress.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\s_icons_buttons.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\sales_buttons.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\sbu_icon.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\t2_bg.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\theweb.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\top7.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\Top7_theweb.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\tsd_bg.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1\weathericon.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\ads.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\btntrans.idx
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\btntrans1.dat
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\business_promo.htm
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\buttondir.txt
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\components.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\cursors.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_1000.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_2000.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_3000.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_bar.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_bbar1.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_logos.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_buttons_other.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\d_icons_weather.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\default.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz1.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz10.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz11.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz12.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz13.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz14.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz15.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz16.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz17.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz18.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz19.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz2.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz20.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz3.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz4.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz5.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz6.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz7.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz8.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_bidz9.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_categorize.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_comparison.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_em_PROFL_CA_flow_b_IEB.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_explorer-Mails.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_explorer-people.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_fastutilities.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_favorites.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Games.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Hide.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_hotbarcom.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Hotmail.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_hsskin.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemster.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemsterie.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jemsteruk.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_jobsearch.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_Mails.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_new.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_premium.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_reun.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_ringtones.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_searchfor.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_searchgo.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_weather.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Default_yellowpages.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\email-def-511724-9595.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\email-t1-bg.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hb_ie_menu.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar-premium-hotbar-premium.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar-premium.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\hotbar_promo.htm
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\icons2.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\ie_games_icon.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\ie_video.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\keywords.idx
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\keywords1.dat
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\layout.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\linkpathlegal.txt
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\progress.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\s_icons_buttons.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\sales_buttons.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\sbu_icon.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\t2_bg.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\theweb.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\top7.cdf
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\Top7_theweb.mnu
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\tsd_bg.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2\weathericon.res
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\ads.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\BtnTrans.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\BtnTrans1.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\business_promo.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\buttondir.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\cursors.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_1000.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_2000.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_3000.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_bar.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_logos.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_buttons_other.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\d_icons_weather.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\default.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\hb_ie_menu.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\hotbar-premium.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\hotbar_promo.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\icons2.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\ie_games_icon.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\ie_video.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\keywords.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\keywords1.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\layout.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\progress.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\s_icons_buttons.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\samplegroups2.txt
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\samplegroups2.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\sbu_icon.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\t2_bg.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\top7.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\tsd_bg.xip
C:\Documents and Settings\GREGORY\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad\weathericon.xip
C:\Documents and Settings\GREGORY\Application Data\Starware358
C:\Documents and Settings\GREGORY\Application Data\Starware358\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\CelebrityNews\CelebrityNewsOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\CelebrityNews\CelebrityNewsOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\CelebritySearch\CelebritySearchOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\CelebritySearch\CelebritySearchOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\Configurator\Configurator.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\Configurator\Configurator.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\Games\GamesOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\Games\GamesOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\Layouts\PitchLayout.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\Layouts\PitchLayout.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\Layouts\ToolbarLayout.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\Manager\ManagerOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\Movies\MoviesOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\Movies\MoviesOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\SearchAssistPlus\SearchAssistPlusOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\SearchAssistPlus\SearchAssistPlusOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\SearchMatch\SearchMatchOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\SearchMatch\SearchMatchOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\GREGORY\Application Data\Starware358\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\GREGORY\Application Data\Starware358\TravelSearch\TravelSearchOptions.xml.backup
C:\Documents and Settings\GREGORY\Desktop\MalwareAlarm.lnk
C:\Documents and Settings\GREGORY\My Documents\MANTEC~1
C:\Documents and Settings\GREGORY\Start Menu\Programs\MalwareAlarm
C:\Documents and Settings\GREGORY\Start Menu\Programs\MalwareAlarm\MalwareAlarm.lnk
C:\Documents and Settings\GREGORY\Start Menu\Programs\MalwareAlarm\Uninstall.lnk
C:\Program Files\AVSystemCare
C:\Program Files\AVSystemCare\history.db
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\001B2084.urr
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\Helper
C:\Program Files\Helper\1202834467.dll
C:\Program Files\Hotbar
C:\Program Files\inetget2
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\ISM
C:\Program Files\ISM\BndDrive7.dll
C:\Program Files\ISM2
C:\Program Files\ISM2\adhydraupd.exe
C:\Program Files\ISM2\dictionary.gz
C:\Program Files\ISM2\ISMPack5.exe
C:\Program Files\ISM2\targets.gz
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Cache\00043A85
C:\Program Files\MyWebSearch\bar\Cache\0007222C
C:\Program Files\MyWebSearch\bar\Cache\00076E86
C:\Program Files\MyWebSearch\bar\Cache\000870F3
C:\Program Files\MyWebSearch\bar\Cache\001B3380
C:\Program Files\MyWebSearch\bar\Cache\001B3A37
C:\Program Files\MyWebSearch\bar\Cache\001B3BBD.bin
C:\Program Files\MyWebSearch\bar\Cache\001B3CE6.bin
C:\Program Files\MyWebSearch\bar\Cache\001B3D82.bin
C:\Program Files\MyWebSearch\bar\Cache\001B3E1F.bin
C:\Program Files\MyWebSearch\bar\Cache\006175E3.bin
C:\Program Files\MyWebSearch\bar\Cache\006177A9.bin
C:\Program Files\MyWebSearch\bar\Cache\006179CB.bin
C:\Program Files\MyWebSearch\bar\Cache\00617B04
C:\Program Files\MyWebSearch\bar\Cache\00644688
C:\Program Files\MyWebSearch\bar\Cache\00C43A9E
C:\Program Files\MyWebSearch\bar\Cache\0200FF64
C:\Program Files\MyWebSearch\bar\Cache\073E1812.bin
C:\Program Files\MyWebSearch\bar\Cache\073E19F6.bin
C:\Program Files\MyWebSearch\bar\Cache\073E1AF0.bin
C:\Program Files\MyWebSearch\bar\Cache\073E1C96
C:\Program Files\MyWebSearch\bar\Cache\0D26319B
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\Program Files\newdotnet
C:\Program Files\newdotnet\readme.html
C:\Program Files\spamblockerutility
C:\Program Files\spamblockerutility\Bin\4.8.4.0\1_Trash.wav
C:\Program Files\spamblockerutility\Bin\4.8.4.0\2_Balloon.wav
C:\Program Files\spamblockerutility\Bin\4.8.4.0\3_Shot Gun.wav
C:\Program Files\spamblockerutility\Bin\4.8.4.0\ASAPCom.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\dBenderC.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\Redemption.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\SBClientSinkPS.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\SBOLExp.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\SBOLExt.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\SBSrvPS.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\SBTrayAppPS.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\SBUIRes.dll
C:\Program Files\spamblockerutility\Bin\4.8.4.0\SBUISkin.dll
C:\Program Files\spamblockerutility\Bin\SbUninst.exe
C:\Program Files\spamblockerutility\SBTV\sbtv_kyf.dat
C:\Program Files\spamblockerutility\SBTV\sbtvau.dat
C:\Program Files\Starware358
C:\Program Files\Starware358\bin\Starware358.dll
C:\UGA6P
C:\WINDOWS\cookies.ini
C:\WINDOWS\NDNuninstall6_98.exe
C:\WINDOWS\system32\abeeg.bak1
C:\WINDOWS\system32\abeeg.ini
C:\WINDOWS\system32\amhsrksg.ini
C:\WINDOWS\system32\conf.dat
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\fbmecdyk.ini
C:\WINDOWS\system32\grykmvwy.ini
C:\WINDOWS\system32\gskrshma.dll
C:\WINDOWS\system32\ixpwcvxa.ini
C:\WINDOWS\system32\jhexftep.dllbox
C:\WINDOWS\system32\jjllm.bak1
C:\WINDOWS\system32\jjllm.bak2
C:\WINDOWS\system32\jjllm.ini
C:\WINDOWS\system32\jjllm.ini2
C:\WINDOWS\system32\mlljg.dll
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\ojguddpa.ini
C:\WINDOWS\system32\ppqss.bak1
C:\WINDOWS\system32\rqtwa.bak1
C:\WINDOWS\system32\rqtwa.bak2
C:\WINDOWS\system32\rqtwa.ini
C:\WINDOWS\system32\wrakvouq.ini
C:\WINDOWS\system32\xnxonvnf.ini
C:\WINDOWS\system32\xxywvst.dll
C:\WINDOWS\system32\ywvmkyrg.dll
C:\WINDOWS\wr.txt
C:\WINDOWS\xpupdate.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_FOPF


((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.

2008-02-25 10:44 . 2008-02-25 10:44 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Flock
2008-02-25 10:42 . 2008-02-25 10:43 <DIR> d-------- C:\Program Files\Flock
2008-02-23 22:09 . 2008-02-23 22:09 <DIR> d-------- C:\_OTMoveIt
2008-02-23 03:14 . 2007-06-08 09:47 13,312 --a------ C:\WINDOWS\system32\drivers\nnrnstdi.sys
2008-02-23 03:14 . 2007-06-08 09:47 8,832 --a------ C:\WINDOWS\system32\drivers\km_filter.sys
2008-02-23 03:09 . 2008-02-23 03:09 <DIR> d-------- C:\Program Files\NetRatingsNetSight
2008-02-23 03:09 . 2007-11-16 18:55 49,152 --a------ C:\WINDOWS\nswatchdog.exe
2008-02-23 00:16 . 2008-02-23 00:16 <DIR> d-------- C:\Program Files\ACW
2008-02-22 23:21 . 2008-02-22 23:23 <DIR> d-------- C:\DVD RAM.temp
2008-02-22 23:11 . 2008-02-22 23:11 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Sonic
2008-02-22 19:54 . 2008-02-22 19:54 65,536 --a------ C:\WINDOWS\system32\drivers\Audio3D.dll
2008-02-22 19:54 . 2008-02-22 19:54 65,536 --a------ C:\WINDOWS\system32\Audio3D.dll
2008-02-22 19:54 . 2008-02-22 19:54 65,536 --a------ C:\WINDOWS\system32\a3d.dll
2008-02-22 19:45 . 2008-02-22 19:45 764,416 --a------ C:\WINDOWS\system32\drivers\crlds3d.dll
2008-02-22 18:40 . 2005-05-03 18:43 69,632 -ra------ C:\WINDOWS\Alcmtr.exe
2008-02-22 18:39 . 2007-12-21 18:01 139,264 --a------ C:\WINDOWS\system32\drivers\RtlCPAPI.dll
2008-02-22 15:34 . 2008-02-22 15:34 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Talkback
2008-02-19 15:02 . 2008-02-19 15:02 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\Uniblue
2008-02-19 00:37 . 2008-02-19 00:37 <DIR> d-------- C:\Program Files\Realtek
2008-02-19 00:37 . 2008-02-19 00:37 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\WinBatch
2008-02-19 00:37 . 2007-07-26 17:09 520,192 --a------ C:\WINDOWS\RtlExUpd.dll
2008-02-19 00:37 . 2008-02-19 00:37 315,392 --a------ C:\WINDOWS\HideWin.exe
2008-02-19 00:02 . 2008-02-19 00:02 3,635 --a------ C:\WINDOWS\machine.ver
2008-02-18 20:31 . 2008-02-18 20:31 <DIR> d-------- C:\Program Files\AML Products
2008-02-18 13:25 . 2008-02-18 13:25 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Template
2008-02-17 22:52 . 2008-02-17 23:26 <DIR> d-------- C:\Program Files\PhotoFiltre
2008-02-17 22:16 . 2008-02-17 22:44 <DIR> d-------- C:\Program Files\Serif
2008-02-17 21:48 . 2008-02-17 21:48 29,900 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-02-16 22:35 . 2008-02-17 11:53 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\Smart PC Solutions
2008-02-15 21:50 . 2008-02-16 01:53 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Morpheus
2008-02-14 13:28 . 2008-02-14 13:28 <DIR> d-------- C:\PC Diagnostic.temp
2008-02-14 11:28 . 2008-02-14 11:33 <DIR> d-------- C:\Program Files\Error Repair Professional
2008-02-14 11:00 . 2008-02-14 11:00 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-14 10:59 . 2008-02-14 10:59 <DIR> d-------- C:\Program Files\Common Files\ErrClean
2008-02-14 10:17 . 2007-12-04 06:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-02-14 10:17 . 2007-12-04 08:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-14 10:17 . 2007-12-04 08:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-14 10:17 . 2007-12-04 08:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-14 10:16 . 2007-12-04 07:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-02-14 10:16 . 2004-01-09 03:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-02-14 10:16 . 2007-12-04 08:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-14 10:16 . 2007-12-04 08:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-14 09:57 . 2008-02-14 09:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Support.com
2008-02-14 07:44 . 2008-02-14 07:44 <DIR> d-------- C:\Program Files\FastAccessDSL
2008-02-14 07:44 . 2008-02-14 09:57 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
2008-02-12 12:04 . 2008-02-12 12:04 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\Talkback
2008-02-12 11:41 . 2008-02-12 11:41 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\GameHouse
2008-02-12 11:41 . 2008-02-12 11:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-02-12 10:38 . 2008-02-12 10:52 2 --a------ C:\-802011832
2008-02-12 10:37 . 2008-02-12 10:37 256,000 --a------ C:\WINDOWS\system32\adduser32.dll
2008-02-12 10:37 . 2008-02-12 10:51 58,368 --a------ C:\wpohl.exe
2008-02-12 10:37 . 2008-02-12 10:37 54,762 --a------ C:\WINDOWS\system32\jkghje.dll
2008-02-11 12:50 . 2008-02-24 14:36 <DIR> d-------- C:\Program Files\MalwareAlarm
2008-02-11 11:42 . 2008-02-11 11:42 <DIR> d---s---- C:\Documents and Settings\Crystal\UserData
2008-02-10 23:17 . 2008-02-10 23:17 <DIR> d-------- C:\WINDOWS\Motive
2008-02-10 23:17 . 2008-02-10 23:17 <DIR> d-------- C:\Program Files\BellSouth Application Management
2008-02-10 23:06 . 2008-02-14 09:57 <DIR> d-------- C:\Program Files\Support.com
2008-02-10 23:06 . 2005-08-31 14:14 1,230,336 --a------ C:\WINDOWS\system32\msxml4.dll
2008-02-10 23:06 . 2005-08-31 14:14 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-02-10 23:06 . 2005-08-31 14:14 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-02-10 22:54 . 2008-02-13 23:56 <DIR> d-------- C:\Program Files\BellSouth
2008-02-10 22:54 . 2003-07-01 11:35 90,112 --a------ C:\WINDOWS\system32\BJPPPoEInstaller.dll
2008-02-10 22:54 . 2003-05-10 15:19 29,228 --a------ C:\WINDOWS\system32\drivers\VWAN2K.sys
2008-02-10 22:54 . 2003-05-10 15:18 16,690 --a------ C:\WINDOWS\system32\drivers\VPROT2K.sys
2008-02-10 12:37 . 2008-02-10 12:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2008-02-10 12:37 . 2005-07-12 00:28 69,632 --a------ C:\WINDOWS\system32\MCCDevice.dll
2008-02-10 12:37 . 2005-07-12 00:28 6,048 --a------ C:\WINDOWS\system32\MCC16.dll
2008-02-10 12:36 . 2008-02-10 22:50 <DIR> d-------- C:\Program Files\Common Files\Motive
2008-02-10 12:36 . 2008-02-10 12:36 19,300,426 --a------ C:\BellSouthIW.re~
2008-02-10 12:36 . 2002-02-13 19:53 6,345 -ra------ C:\WINDOWS\system32\DevMngr.vxd
2008-02-09 21:34 . 2008-02-09 21:34 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-02-09 21:34 . 2008-02-09 21:34 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\toshiba
2008-02-09 21:34 . 2008-02-09 21:34 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-09 21:34 . 2008-02-09 21:34 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterVideo
2008-02-09 21:34 . 2008-02-09 21:34 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-02-09 21:33 . 2008-02-09 21:33 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Yahoo!
2008-02-09 21:31 . 2008-02-09 21:31 <DIR> d-------- C:\Documents and Settings\Crystal\WINDOWS
2008-02-09 21:31 . 2008-02-09 21:31 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\toshiba
2008-02-09 21:31 . 2008-02-09 21:31 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Symantec
2008-02-09 21:31 . 2008-02-09 21:31 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\InterVideo
2008-02-09 21:31 . 2008-02-09 21:31 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\InterTrust
2008-02-09 20:39 . 2008-02-09 21:31 <DIR> d-------- C:\Program Files\Norton AntiVirus
2008-01-25 16:32 . 2008-02-09 21:33 <DIR> d-------- C:\Casino

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 06:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-14 23:04 4,676,096 ----a-r C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-02-14 17:17 --------- d-----w C:\Program Files\ErrClean
2008-02-14 05:19 --------- d-----w C:\Program Files\ParadisePokerNet
2008-02-13 20:31 16,857,600 ----a-r C:\WINDOWS\RTHDCPL.exe
2008-02-12 23:10 --------- d-----w C:\Program Files\Yahoo!
2008-02-11 17:57 --------- d-----w C:\Program Files\Google
2008-02-11 05:18 67,042 ----a-w C:\Program Files\INSTALL.LOG
2008-02-10 23:46 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-02-10 03:33 --------- d-----w C:\Program Files\UBNet
2008-02-10 03:33 --------- d-----w C:\Documents and Settings\GREGORY\Application Data\Netscape
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\aolshare
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\aolback
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\AOL
2008-02-10 03:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-10 03:31 --------- d-----w C:\Program Files\Webshots
2008-02-10 03:31 --------- d-----w C:\Program Files\Photo Viewer
2008-02-10 03:28 --------- d-----w C:\Program Files\Sony Ericsson
2008-02-10 03:28 --------- d-----w C:\Documents and Settings\Crystal\Application Data\ArcSoft
2007-12-09 04:03 30,720 ---h--r C:\WINDOWS\CdaC13BA.EXE
2007-12-09 04:03 112,128 ---h--r C:\WINDOWS\CdaC14BA.DLL
2006-01-26 21:49 6,572 ----a-w C:\Program Files\Warez P2P ClientIPGUARD.LOG
.

------- Sigcheck -------

8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
----a-w 14,336 2004-08-04 12:00:00 C:\WINDOWS\system32\svchost.exe

de2db164bbb35db061af0997e4499054 C:\WINDOWS\system32\user32.dll
-c--a-w 577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
-c----w 577,024 2004-08-04 12:00:00 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
----a-w 577,024 2005-03-02 18:09:30 C:\WINDOWS\system32\user32.dll

2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
----a-w 82,944 2004-08-04 12:00:00 C:\WINDOWS\system32\ws2_32.dll

2b4db890936430c71419037039502752 C:\WINDOWS\system32\wininet.dll
-c--a-w 657,920 2005-01-27 17:08:42 C:\WINDOWS\$hf_mig$\KB867282\SP2QFE\wininet.dll
-c--a-w 658,944 2005-05-02 20:57:24 C:\WINDOWS\$hf_mig$\KB883939\SP2QFE\wininet.dll
-c--a-w 657,920 2005-03-10 07:43:23 C:\WINDOWS\$hf_mig$\KB890923\SP2QFE\wininet.dll
-c--a-w 660,480 2005-09-02 23:53:41 C:\WINDOWS\$hf_mig$\KB896688\SP2QFE\wininet.dll
-c--a-w 659,456 2005-07-03 02:09:33 C:\WINDOWS\$hf_mig$\KB896727\SP2QFE\wininet.dll
----a-w 661,504 2005-10-21 03:38:08 C:\WINDOWS\$hf_mig$\KB905915\SP2QFE\wininet.dll
----a-w 663,552 2006-03-04 03:58:52 C:\WINDOWS\$hf_mig$\KB912812\SP2QFE\wininet.dll
----a-w 663,552 2006-05-10 05:25:22 C:\WINDOWS\$hf_mig$\KB916281\SP2QFE\wininet.dll
----a-w 664,576 2006-06-23 11:25:31 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
-c----w 656,384 2004-08-04 12:00:00 C:\WINDOWS\$NtUninstallKB867282$\wininet.dll
-c----w 656,896 2005-03-10 08:02:35 C:\WINDOWS\$NtUninstallKB883939$\wininet.dll
-c----w 656,896 2005-01-27 17:13:18 C:\WINDOWS\$NtUninstallKB890923$\wininet.dll
-c----w 658,432 2005-07-03 02:11:30 C:\WINDOWS\$NtUninstallKB896688$\wininet.dll
-c----w 657,920 2005-05-02 20:52:36 C:\WINDOWS\$NtUninstallKB896727$\wininet.dll
-c----w 658,432 2005-09-02 23:52:06 C:\WINDOWS\$NtUninstallKB905915$\wininet.dll
-c----w 658,432 2005-10-21 03:39:30 C:\WINDOWS\$NtUninstallKB912812$\wininet.dll
-c----w 658,432 2006-03-04 03:33:45 C:\WINDOWS\$NtUninstallKB916281$\wininet.dll
-c----w 658,432 2006-05-10 05:23:03 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
----a-w 658,944 2006-06-23 11:02:52 C:\WINDOWS\system32\wininet.dll
-c----w 658,944 2006-06-23 11:02:52 C:\WINDOWS\system32\dllcache\wininet.dll

1dbf125862891817f374f407626967f4 C:\WINDOWS\system32\drivers\tcpip.sys
-c--a-w 359,936 2005-05-25 19:07:12 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
----a-w 360,448 2006-01-13 17:07:08 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
----a-w 360,576 2006-04-20 12:18:35 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
-c----w 359,040 2004-08-04 12:00:00 C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
-c----w 359,808 2005-05-25 19:04:02 C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
-c----w 359,808 2006-01-13 02:28:14 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
-c--a-w 359,808 2006-04-20 11:51:50 C:\WINDOWS\system32\dllcache\tcpip.sys
----a-w 359,808 2006-04-20 11:51:50 C:\WINDOWS\system32\drivers\tcpip.sys

01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
----a-w 502,272 2004-08-04 12:00:00 C:\WINDOWS\system32\winlogon.exe

558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
----a-w 182,912 2004-08-04 12:00:00 C:\WINDOWS\system32\drivers\ndis.sys

4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
----a-w 29,056 2004-08-04 12:00:00 C:\WINDOWS\system32\drivers\ip6fw.sys

81013f36b21c7f72cf784cc6731e0002 C:\WINDOWS\system32\ntkrnlpa.exe
-c--a-w 2,056,832 2005-03-02 00:36:40 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
-c----w 2,056,832 2004-08-04 12:00:00 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
-c----w 2,056,832 2005-03-02 00:34:40 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
----a-w 2,056,832 2005-03-02 00:34:40 C:\WINDOWS\system32\ntkrnlpa.exe

4d4cf2c14550a4b7718e94a6e581856e C:\WINDOWS\system32\ntoskrnl.exe
-c--a-w 2,179,456 2005-03-02 01:04:22 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
-c----w 2,180,992 2004-08-04 12:00:00 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
-c----w 2,179,328 2005-03-02 00:59:53 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
----a-w 2,179,328 2005-03-02 00:59:53 C:\WINDOWS\system32\ntoskrnl.exe

a0732187050030ae399b241436565e64 C:\WINDOWS\explorer.exe
----a-w 1,032,192 2004-08-04 12:00:00 C:\WINDOWS\explorer.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2BCE3224-D277-413E-A16D-DCE4B8AA32DB}]
C:\WINDOWS\system32\geeba.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 04:24 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 16:10 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GC75-Manager-Class"="C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe" [2004-04-08 04:36 766045]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-08-19 18:44 77824]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-11 13:07 185896]
"AirCardEnabler"="C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe" [2003-04-16 08:21 151552]
"HostManager"="C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe" [2006-09-25 18:52 50736]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 14:14 1277952]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00 79224]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [2005-03-17 16:37 151552]
"NielsenOnline"="C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2007-11-16 18:55 45056]

C:\Documents and Settings\GREGORY\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-11 17:40:29 45056]

C:\Documents and Settings\Crystal\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-11 17:40:29 45056]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2004-08-19 17:18:56 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WinMain"= {C231CF11-134F-3552-44AC-E685D962C63C} - C:\WINDOWS\system32\adduser32.dll [2008-02-12 10:37 256000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jhexftep]
jhexftep.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
backup=C:\WINDOWS\pss\RAMASST.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2004-02-20 16:00 88363 C:\WINDOWS\agrsmmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2003-10-30 17:46 192512 C:\Program Files\Apoint2K\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-06-10 22:10 339968 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boobcopyfraghold]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CastInter]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CeEKEY]
--a------ 2004-08-06 16:14 643072 C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CeEPOWER]
--a------ 2004-08-19 19:14 135168 C:\Program Files\TOSHIBA\Power Management\CePMTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 06:00 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2004-07-14 03:04 122939 C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzButton]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2003-11-18 02:11 118784 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2003-11-18 02:24 155648 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2003-09-26 16:43 184320 C:\Program Files\ltmoh\Ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NDSTray.exe]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
--a------ 2004-02-03 15:47 1089589 C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
--a------ 2005-03-17 16:37 151552 c:\toshiba\ivp\ism\pinger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2004-08-19 18:44 77824 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2004-03-02 14:45 135168 C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
--a------ 2003-09-05 04:24 65536 C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPNF]
--a------ 2004-07-28 17:23 53248 C:\Program Files\TOSHIBA\TouchPad\TPTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
--a------ 2004-11-10 22:15 111816 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoomingHook]
--a------ 2004-07-14 17:07 24576 c:\WINDOWS\System32\ZoomingHook.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Flock\\flock\\flock.exe"=

R1 nnrnstdi;nnrnstdi;C:\WINDOWS\system32\drivers\nnrnstdi.sys [2007-06-08 09:47]
R2 VProt2k;BroadJump PPPoE Helper Protocol;C:\WINDOWS\system32\DRIVERS\VProt2k.SYS [2003-05-10 15:18]
R3 km_filter;km_filter;C:\WINDOWS\system32\drivers\km_filter.sys [2007-06-08 09:47]
R3 VWan2k;BroadJump PPPoE Adapter;C:\WINDOWS\system32\DRIVERS\VWan2k.SYS [2003-05-10 15:19]
S3 ACGPRS;Sierra Wireless GPRS Adapter;C:\WINDOWS\system32\DRIVERS\acgprs.sys [2004-05-19 15:26]
S3 SEWModem;Sony Ericsson Wireless Modem;C:\WINDOWS\system32\DRIVERS\GC75.sys [2004-04-25 23:42]
S3 SEWWNIC;Sony Ericsson Wireless WAN Adapter;C:\WINDOWS\system32\DRIVERS\GC75Net.sys [2004-04-25 23:42]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 17:14:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Webshots\Webshots.scr
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-02-25 17:17:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-25 23:17:32
Crystal

BC AdBot (Login to Remove)

 


#2 ken545

ken545

    Malware Response Team


  • Malware Response Team
  • 1,685 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Space Coast of Florida
  • Local time:01:04 PM

Posted 14 March 2008 - 05:08 PM

Hello crystal13

Welcome to the Bleeping Computer Malware Removal Forum, sorry about the delay, but the amount of people posting with infected computers is through the roof and sometimes we can't get to logs as fast as we would like to. It looks like your post was overlooked and I apologize for that. If you have not resolved your issue and still need assistance I need you to post a Hijackthis log.



Download Trendmicros Hijackthis to your desktop.
Double click it to install
Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All.....Edit > Copy and Paste the new log into this thread by using the Post Reply and not start a New Thread.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.

mvp_host.pngConsumer Security 2007-2008-2009-2010-2011-2012-2013-2014



donate.gif Please consider a donation to help me keep up my fight against malware.

 

Just a reminder that threads will be closed if no response in 3 days


#3 crystal13

crystal13
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 14 March 2008 - 07:43 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:40:18 PM, on 3/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
C:\Program Files\Support.com\BellSouth\hcenter.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\WINDOWS\System32\ZoomingHook.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Webshots\Webshots.scr
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - > - (no file)
O2 - BHO: (no name) - 8 - (no file)
O2 - BHO: (no name) - C31B-401F-89BC-4CBB25E853D7} - (no file)
O2 - BHO: (no name) - h@ - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: (no name) - {2BCE3224-D277-413E-A16D-DCE4B8AA32DB} - C:\WINDOWS\system32\geeba.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - = - (no file)
O2 - BHO: (no name) - @ - (no file)
O2 - BHO: (no name) - $ - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [GC75-Manager-Class] "C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AirCardEnabler] C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [PINGER] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [ZoomingHook] c:\WINDOWS\System32\ZoomingHook.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: jhexftep - jhexftep.dll (file missing)
O21 - SSODL: WinMain - {C231CF11-134F-3552-44AC-E685D962C63C} - C:\WINDOWS\system32\adduser32.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsubleepa Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)

--
End of file - 12683 bytes
Crystal

#4 ken545

ken545

    Malware Response Team


  • Malware Response Team
  • 1,685 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Space Coast of Florida
  • Local time:01:04 PM

Posted 15 March 2008 - 08:53 AM

Good Morning crystal, :thumbsup:

You have a bit of a mess going on, this is what we need to do. First off you have two Anti Virus programs running and that is not recommended as with all the system resources they use it can slow down your system, give false positive warnings and the list goes on, its your call but you need to uninstall one of them via the Add Remove Programs in the Control Panel. You have Avast and Symantec.

Viewpoint Manager Service <--This program has installed without your knowledge or consent , uses system resources and unless you use it is not needed for anything and this too can be uninstalled via the Add Remove Programs.


I need you to disable the TeaTimer in Spybot Search and Destroy as it will interfere with any changes we are going to make. Keep it disabled until we are done.



Disable the TeaTimer, you can re enable it when were done if you wish
  • Run Spybot-S&D in Advanced Mode.
  • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
  • On the left hand side, Click on Tools
  • Then click on the Resident Icon in the List
  • Uncheck "Resident TeaTimer" and OK any prompts.
  • Restart your computer.<--You need to do this for it to take effect


Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - > - (no file)
O2 - BHO: (no name) - 8 - (no file)
O2 - BHO: (no name) - C31B-401F-89BC-4CBB25E853D7} - (no file)
O2 - BHO: (no name) - h@ - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {2BCE3224-D277-413E-A16D-DCE4B8AA32DB} - C:\WINDOWS\system32\geeba.dll (file missing)

O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe

O20 - Winlogon Notify: jhexftep - jhexftep.dll (file missing)

O21 - SSODL: WinMain - {C231CF11-134F-3552-44AC-E685D962C63C} - C:\WINDOWS\system32\adduser32.dll (file missing)






Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.


Now drag Combofix to the trash and download a new copy as it updated on a regular basis. Set it up this way , run it.

Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net

2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.



This is what I need to see.

1. Malwarebytes log
2. Combofix log
3. New HJT log

mvp_host.pngConsumer Security 2007-2008-2009-2010-2011-2012-2013-2014



donate.gif Please consider a donation to help me keep up my fight against malware.

 

Just a reminder that threads will be closed if no response in 3 days


#5 crystal13

crystal13
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 15 March 2008 - 04:39 PM

Thank you so very much for your help! I have done everything you have said, up to where it says to download updated ComboFix, for some reason when I try to save it will not allow me to save it. The box that usually has a spot to click save is not there to click on, Not sure if it's the links you have provided or what. So I can't get past that part and don't want to do anything to mess it up. Please help! I do have the Malware bytes log, didn't know if I should go ahead and post that yet or not.
thanks again!
Crystal
Crystal

#6 ken545

ken545

    Malware Response Team


  • Malware Response Team
  • 1,685 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Space Coast of Florida
  • Local time:01:04 PM

Posted 15 March 2008 - 04:47 PM

Hi, The Combofix links are fine, it must be something on your end as it let you download HJT and Malwarebytes with no problem. Go ahead and post the Malwarebytes log and a New HJT log and I will give you some other links for Combofix.

Combofix
Here

mvp_host.pngConsumer Security 2007-2008-2009-2010-2011-2012-2013-2014



donate.gif Please consider a donation to help me keep up my fight against malware.

 

Just a reminder that threads will be closed if no response in 3 days


#7 crystal13

crystal13
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 15 March 2008 - 06:04 PM

Sorry, please disregard my last message, I found combofix and here are all 3 logs you requested. Thanks!


Malwarebytes' Anti-Malware 1.08
Database version: 493

Scan type: Quick Scan
Objects scanned: 32101
Time elapsed: 8 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 18
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 24
Files Infected: 34

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RABCO (Adware.RABCO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\RABCO (Adware.RABCO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\RABCO (Adware.RABCO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RABCO (Adware.RABCO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ugac (Rogue.PCSecureSystem) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weather Services (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SpamBlockerUtility 4.8.4 (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\iDlo01 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Casino (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaoh's Casino (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaohs Casino Multi-player (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaoh's Casino\games (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaoh's Casino\games\1_bj (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaoh's Casino\games\8_vp (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\TrustedAntivirus (Rogue.TrustedAntivirus) -> Quarantined and deleted successfully.
C:\TrustedAntivirus (Rogue.TrustedProtection) -> Quarantined and deleted successfully.
C:\TrustedAntivirus\AVQuar (Rogue.TrustedProtection) -> Quarantined and deleted successfully.
C:\Program Files\ErrClean (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\ErrClean (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Program Files\RABCO (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\The Weather Channel\Desktop Weather (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\AVSystemCare (Rogue.AVSystemcare) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\AVSystemCare\Logs (Rogue.AVSystemcare) -> Quarantined and deleted successfully.
C:\Documents and Settings\Crystal\Application Data\TrustedAntivirus (Rogue.TrustedAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Crystal\Application Data\TrustedAntivirus\Logs (Rogue.TrustedAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\errclean (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\errclean\Data (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\errclean (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\errclean\Logs (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Rabio (Adware.Rabio) -> Quarantined and deleted successfully.

Files Infected:
C:\TEMP\stdF0224.exe (Trojan.DownLoader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\iDlo01\iDlo011065.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Casino\Pharaoh's Casino\Casino.cfg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaoh's Casino\main.cfg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaoh's Casino\games\1_bj\BJack.cfg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaoh's Casino\games\8_vp\VPoker.cfg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaohs Casino Multi-player\c2table.db (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaohs Casino Multi-player\c2user.db (Adware.Casino) -> Quarantined and deleted successfully.
C:\Casino\Pharaohs Casino Multi-player\options.cfg (Adware.Casino) -> Quarantined and deleted successfully.
C:\Program Files\TrustedAntivirus\history.db (Rogue.TrustedAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\ErrClean\swupd.log (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Program Files\RABCO\ExecutionDll.dll (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Program Files\RABCO\RABCO.dll.intermediate.manifest (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Program Files\RABCO\RABCOse.info (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Program Files\RABCO\RABCOse.original (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Program Files\RABCO\Setup.log (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Program Files\RABCO\un_RABCOSetup_16230.exe (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Program Files\RABCO\un_RABCOSetup_16230.txt (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Program Files\RABCO\X_RABCOse.log (Adware.RABCO) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\The Weather Channel\Desktop Weather\Help.lnk (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\The Weather Channel\Desktop Weather\Settings.lnk (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\The Weather Channel\Desktop Weather\The Weather Channel Desktop.lnk (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\The Weather Channel\Desktop Weather\Uninstall.lnk (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\AVSystemCare\avtasks.dat (Rogue.AVSystemcare) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\AVSystemCare\Logs\av.log (Rogue.AVSystemcare) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\AVSystemCare\Logs\ga6Support.log (Rogue.AVSystemcare) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\AVSystemCare\Logs\update.log (Rogue.AVSystemcare) -> Quarantined and deleted successfully.
C:\Documents and Settings\Crystal\Application Data\TrustedAntivirus\Logs\threats.log (Rogue.TrustedAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Crystal\Application Data\TrustedAntivirus\Logs\update.log (Rogue.TrustedAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\errclean\Data\ac (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\errclean\Data\em (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\errclean\Data\oid (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\errclean\Data\user (Rogue.Errclean) -> Quarantined and deleted successfully.
C:\Documents and Settings\GREGORY\Application Data\errclean\Logs\update.log (Rogue.Errclean) -> Quarantined and deleted successfully.







ComboFix 08-03-14.4 - Crystal 2008-03-15 17:21:53.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.178 [GMT -5:00]
Running from: C:\Documents and Settings\Crystal\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\WINDOWS\BMd301767b.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\kmd.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\LEGACY_DHLP
-------\wer32


((((((((((((((((((((((((( Files Created from 2008-02-15 to 2008-03-15 )))))))))))))))))))))))))))))))
.

2008-03-15 14:36 . 2008-03-15 14:36 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-15 14:36 . 2008-03-15 14:36 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-03-15 14:36 . 2008-03-15 14:36 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Malwarebytes
2008-03-15 14:36 . 2008-03-15 14:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-15 13:17 . 2008-03-15 13:17 <DIR> d-------- C:\Program Files\Common Files\HP
2008-03-15 13:17 . 2008-03-15 13:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-03-15 13:15 . 2008-03-15 13:15 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-03-15 13:13 . 2008-03-15 13:13 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-03-15 13:12 . 2005-03-07 23:43 51,120 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-03-15 13:12 . 2005-03-07 23:43 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-03-15 13:11 . 2005-03-07 23:43 21,744 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-03-15 13:10 . 2004-09-29 12:12 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2008-03-15 13:10 . 2004-09-29 12:15 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2008-03-15 13:10 . 2004-09-29 12:09 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2008-03-15 13:10 . 2004-09-29 12:14 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2008-03-15 13:10 . 2004-09-29 12:08 61,440 --a------ C:\WINDOWS\system32\HPZinw12.exe
2008-03-15 13:10 . 2004-09-29 12:09 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2008-03-15 13:08 . 2008-03-15 13:17 <DIR> d-------- C:\Program Files\HP
2008-03-15 13:03 . 2008-03-15 13:03 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\HP
2008-03-15 13:03 . 2008-03-15 13:21 112,924 --a------ C:\WINDOWS\hpoins07.dat
2008-03-15 13:03 . 2005-05-24 01:52 21,124 --------- C:\WINDOWS\hpomdl07.dat
2008-03-07 20:02 . 2008-03-15 17:31 3,870,752 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-07 20:02 . 2008-03-15 17:27 46,388 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-07 20:00 . 2008-03-07 20:00 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2008-03-07 19:57 . 2008-03-07 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-07 19:57 . 2007-11-14 17:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-03-07 19:57 . 2008-03-07 20:00 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-07 19:56 . 2008-03-07 19:56 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-07 19:29 . 2008-03-15 17:11 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-03-07 00:39 . 2008-03-07 21:03 <DIR> d-------- C:\Program Files\Gutterball 2
2008-03-06 22:20 . 2008-03-07 00:34 <DIR> d-------- C:\Program Files\Saints & Sinners Bowling
2008-03-06 22:19 . 2008-03-06 22:19 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-03-06 17:43 . 2008-03-06 17:43 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-06 13:35 . 2008-03-06 13:36 <DIR> d-------- C:\Documents and Settings\Crystal\.housecall6.6
2008-03-06 01:01 . 2008-03-06 01:02 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-06 01:01 . 2008-03-06 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-05 22:30 . 2008-03-05 22:30 <DIR> d-------- C:\Program Files\Lavasoft
2008-03-05 22:30 . 2008-03-05 22:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-05 22:09 . 2007-12-04 08:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-05 22:09 . 2004-01-09 04:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-05 22:09 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-05 22:09 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-05 22:09 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-05 22:09 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-05 22:09 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-05 22:09 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-05 15:50 . 2008-03-15 17:29 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-05 15:50 . 2008-03-15 17:26 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-05 15:49 . 2008-03-05 15:49 0 --a------ C:\WINDOWS\CePMTray.INI
2008-03-05 15:48 . 2008-03-05 15:48 0 --a------ C:\WINDOWS\TPTray.INI
2008-03-04 21:59 . 2008-03-14 22:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-03-04 19:47 . 2007-12-06 21:21 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-04 19:47 . 2007-06-30 22:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-04 19:47 . 2007-06-30 22:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-04 19:47 . 2007-12-06 21:21 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-04 19:47 . 2007-12-06 21:21 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-04 19:47 . 2007-12-06 21:21 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-04 19:47 . 2007-12-06 21:21 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-04 19:47 . 2007-12-06 21:21 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-04 19:47 . 2007-12-06 06:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-04 19:39 . 2007-08-13 19:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-03-04 19:27 . 2008-03-04 19:27 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\MySpace
2008-03-04 16:19 . 2008-03-04 16:19 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-03-04 16:17 . 2005-02-23 15:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-03-04 11:14 . 2008-01-12 19:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-04 11:14 . 2008-01-15 10:54 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-04 11:14 . 2008-01-15 06:28 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-03 18:54 . 2008-03-05 15:33 <DIR> d-------- C:\Program Files\MySpace
2008-03-03 18:54 . 2008-03-03 18:54 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\MySpace
2008-03-03 13:07 . 2008-03-03 13:07 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-03-03 12:56 . 2008-03-03 12:56 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-03-02 21:59 . 2007-07-09 08:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-03-02 21:43 . 2008-03-02 21:43 <DIR> d--h----- C:\WINDOWS\PIF
2008-03-02 21:33 . 2007-07-30 20:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-03-02 21:33 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-03-02 21:33 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-02 21:33 . 2007-07-30 20:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-03-02 20:47 . 2008-03-15 13:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-02 20:45 . 2008-03-15 13:48 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-02 20:43 . 2005-05-03 13:58 78,848 --a------ C:\WINDOWS\system32\msiexec.exe
2008-03-02 20:43 . 2005-05-03 13:58 78,848 --a--c--- C:\WINDOWS\system32\dllcache\msiexec.exe
2008-03-02 20:40 . 2008-03-02 20:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-02 20:22 . 2008-03-15 14:17 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-02-26 17:14 . 2008-02-26 17:14 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\Flock
2008-02-25 19:21 . 2008-02-25 19:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-25 11:44 . 2008-02-25 11:44 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Flock
2008-02-25 11:42 . 2008-02-25 11:43 <DIR> d-------- C:\Program Files\Flock
2008-02-23 23:09 . 2008-02-23 23:09 <DIR> d-------- C:\_OTMoveIt
2008-02-23 04:14 . 2007-06-08 10:47 13,312 --a------ C:\WINDOWS\system32\drivers\nnrnstdi.sys
2008-02-23 04:14 . 2007-06-08 10:47 8,832 --a------ C:\WINDOWS\system32\drivers\km_filter.sys
2008-02-23 04:09 . 2008-02-23 04:09 <DIR> d-------- C:\Program Files\NetRatingsNetSight
2008-02-23 04:09 . 2007-11-16 19:55 49,152 --a------ C:\WINDOWS\nswatchdog.exe
2008-02-23 01:16 . 2008-02-23 01:16 <DIR> d-------- C:\Program Files\ACW
2008-02-23 00:21 . 2008-02-23 00:23 <DIR> d-------- C:\DVD RAM.temp
2008-02-23 00:11 . 2008-02-23 00:11 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Sonic
2008-02-22 20:54 . 2008-02-22 20:54 65,536 --a------ C:\WINDOWS\system32\drivers\Audio3D.dll
2008-02-22 20:54 . 2008-02-22 20:54 65,536 --a------ C:\WINDOWS\system32\Audio3D.dll
2008-02-22 20:54 . 2008-02-22 20:54 65,536 --a------ C:\WINDOWS\system32\a3d.dll
2008-02-22 20:45 . 2008-02-22 20:45 764,416 --a------ C:\WINDOWS\system32\drivers\crlds3d.dll
2008-02-22 19:40 . 2005-05-03 19:43 69,632 -ra------ C:\WINDOWS\Alcmtr.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-15 19:09 --------- d-----w C:\Program Files\Viewpoint
2008-03-12 03:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-05 19:14 --------- d-----w C:\Program Files\Google
2008-03-04 21:32 --------- d-----w C:\Documents and Settings\Crystal\Application Data\ArcSoft
2008-03-04 21:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-04 21:19 --------- d-----w C:\Program Files\ArcSoft
2008-02-14 23:04 4,676,096 ----a-r C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-02-14 17:33 --------- d-----w C:\Program Files\Error Repair Professional
2008-02-14 17:00 --------- d-----r C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-14 15:57 --------- d-----w C:\Program Files\Support.com
2008-02-14 15:57 --------- d-----w C:\Program Files\Common Files\SupportSoft
2008-02-14 15:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Support.com
2008-02-14 13:44 --------- d-----w C:\Program Files\FastAccessDSL
2008-02-14 05:56 --------- d-----w C:\Program Files\BellSouth
2008-02-13 20:31 16,857,600 ----a-r C:\WINDOWS\RTHDCPL.exe
2008-02-12 23:10 --------- d-----w C:\Program Files\Yahoo!
2008-02-12 18:04 --------- d-----w C:\Documents and Settings\GREGORY\Application Data\Talkback
2008-02-12 17:41 --------- d-----w C:\Documents and Settings\GREGORY\Application Data\GameHouse
2008-02-12 17:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-02-11 05:18 67,042 ----a-w C:\Program Files\INSTALL.LOG
2008-02-11 05:17 --------- d-----w C:\Program Files\BellSouth Application Management
2008-02-11 04:50 --------- d-----w C:\Program Files\Common Files\Motive
2008-02-10 23:46 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-02-10 18:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-02-10 03:34 --------- d-----w C:\Documents and Settings\Administrator\Application Data\toshiba
2008-02-10 03:34 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-10 03:34 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InterVideo
2008-02-10 03:34 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-02-10 03:33 --------- d-----w C:\Program Files\UBNet
2008-02-10 03:33 --------- d-----w C:\Documents and Settings\GREGORY\Application Data\Netscape
2008-02-10 03:33 --------- d-----w C:\Documents and Settings\Crystal\Application Data\Yahoo!
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\aolshare
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\aolback
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\AOL
2008-02-10 03:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-10 03:31 --------- d-----w C:\Program Files\Webshots
2008-02-10 03:31 --------- d-----w C:\Program Files\Photo Viewer
2008-02-10 03:31 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-10 03:31 --------- d-----w C:\Documents and Settings\Crystal\Application Data\toshiba
2008-02-10 03:31 --------- d-----w C:\Documents and Settings\Crystal\Application Data\Symantec
2008-02-10 03:31 --------- d-----w C:\Documents and Settings\Crystal\Application Data\InterVideo
2008-02-10 03:31 --------- d-----w C:\Documents and Settings\Crystal\Application Data\InterTrust
2008-02-10 03:28 --------- d-----w C:\Program Files\Sony Ericsson
2006-01-26 21:49 6,572 ----a-w C:\Program Files\Warez P2P ClientIPGUARD.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 05:24 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 17:10 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GC75-Manager-Class"="C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe" [2004-04-08 05:36 766045]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-08-19 19:44 77824]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-11 14:07 185896]
"AirCardEnabler"="C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe" [2003-04-16 09:21 151552]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 15:14 1277952]
"PINGER"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 17:37 151552]
"ZoomingHook"="c:\WINDOWS\System32\ZoomingHook.exe" [2004-07-14 18:07 24576]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-07-28 18:23 53248]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-03-02 15:45 135168]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-02-03 16:47 1089589]
"NDSTray.exe"="NDSTray.exe" []
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-09-26 17:43 184320]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-11-18 03:24 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-11-18 03:11 118784]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-07-14 04:04 122939]
"CeEPOWER"="C:\Program Files\TOSHIBA\Power Management\CePMTray.exe" [2004-08-19 20:14 135168]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2004-08-06 17:14 643072]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 23:10 339968]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-30 18:46 192512]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 17:00 88363 C:\WINDOWS\agrsmmsg.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 17:05 919016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Notebook Maximizer"="C:\Program Files\Notebook Maximizer\maximizer_startup.exe" [2004-05-25 16:35 28672]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]

C:\Documents and Settings\GREGORY\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-11 18:40:29 45056]

C:\Documents and Settings\Crystal\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-11 18:40:29 45056]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-03-04 21:59:19 125624]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2004-08-19 18:18:56 155648]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
backup=C:\WINDOWS\pss\RAMASST.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boobcopyfraghold]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CastInter]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzButton]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Flock\\flock\\flock.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

R1 nnrnstdi;nnrnstdi;C:\WINDOWS\system32\drivers\nnrnstdi.sys [2007-06-08 10:47]
R2 VProt2k;BroadJump PPPoE Helper Protocol;C:\WINDOWS\system32\DRIVERS\VProt2k.SYS [2003-05-10 16:18]
R3 km_filter;km_filter;C:\WINDOWS\system32\drivers\km_filter.sys [2007-06-08 10:47]
R3 VWan2k;BroadJump PPPoE Adapter;C:\WINDOWS\system32\DRIVERS\VWan2k.SYS [2003-05-10 16:19]
S3 ACGPRS;Sierra Wireless GPRS Adapter;C:\WINDOWS\system32\DRIVERS\acgprs.sys [2004-05-19 16:26]
S3 SEWModem;Sony Ericsson Wireless Modem;C:\WINDOWS\system32\DRIVERS\GC75.sys [2004-04-26 00:42]
S3 SEWWNIC;Sony Ericsson Wireless WAN Adapter;C:\WINDOWS\system32\DRIVERS\GC75Net.sys [2004-04-26 00:42]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-15 17:31:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Webshots\Webshots.scr
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2008-03-15 17:36:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-15 22:36:21
ComboFix2.txt 2008-03-06 02:47:18
ComboFix3.txt 2008-02-27 07:05:54
ComboFix4.txt 2008-02-27 06:56:56
ComboFix5.txt 2008-02-25 23:17:37
.
2008-03-13 04:05:43 --- E O F ---





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:46:13 PM, on 3/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
C:\Program Files\Support.com\BellSouth\hcenter.exe
C:\WINDOWS\System32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Webshots\Webshots.scr
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - = - (no file)
O2 - BHO: (no name) - @ - (no file)
O2 - BHO: (no name) - $ - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [GC75-Manager-Class] "C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AirCardEnabler] C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [PINGER] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [ZoomingHook] c:\WINDOWS\System32\ZoomingHook.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsubleepa Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)

--
End of file - 10750 bytes
Crystal

#8 ken545

ken545

    Malware Response Team


  • Malware Response Team
  • 1,685 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Space Coast of Florida
  • Local time:01:04 PM

Posted 15 March 2008 - 07:36 PM

Hello,

Remove these with HJT
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - = - (no file)
O2 - BHO: (no name) - @ - (no file)
O2 - BHO: (no name) - $ - (no file)



Run this free online scan using Internet Explorer:
Kaspersky Online Virus Scanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan: Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Post the log along with a New HJT Log into your next reply.


These are in your startup folder, do you know what they are related to.
CastInter
Boobcopyfraghold

mvp_host.pngConsumer Security 2007-2008-2009-2010-2011-2012-2013-2014



donate.gif Please consider a donation to help me keep up my fight against malware.

 

Just a reminder that threads will be closed if no response in 3 days


#9 crystal13

crystal13
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 15 March 2008 - 11:06 PM

I do not know what these are related to:CastInter
Boobcopyfraghold



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:01:18 PM, on 3/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
C:\Program Files\Support.com\BellSouth\hcenter.exe
C:\WINDOWS\System32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Webshots\Webshots.scr
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [GC75-Manager-Class] "C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AirCardEnabler] C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [PINGER] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [ZoomingHook] c:\WINDOWS\System32\ZoomingHook.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsubleepa Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)

--
End of file - 10760 bytes




NER REPORT
Saturday, March 15, 2008 10:19:53 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/03/2008
Kaspersky Anti-Virus database records: 570876
Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
Scan Statistics
Total number of scanned objects 60311
Number of viruses found 4
Number of infected objects 9
Number of suspicious objects 0
Duration of the scan process 01:09:11

Infected Object Name Virus Name Last Action
C:\4e24f9f04ee4e200d80fe6ca4d815d\update\eula.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5dfffea2f8866b35639d5c3b6f3d3931_e6505d7a-89ca-4719-b6f0-2fe4a3b60ba2 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\Crystal\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Crystal\Desktop\netsight_setup_5.1.2.15_MP_Production_mid60819774972_p.exe/nswatchdog.exe Infected: Trojan-Downloader.Win32.Agent.jlp skipped
C:\Documents and Settings\Crystal\Desktop\netsight_setup_5.1.2.15_MP_Production_mid60819774972_p.exe CAB: infected - 1 skipped
C:\Documents and Settings\Crystal\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Crystal\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Crystal\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Crystal\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Crystal\Local Settings\History\History.IE5\MSHist012008031520080316\index.dat Object is locked skipped
C:\Documents and Settings\Crystal\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Crystal\Local Settings\Temp\Wireless Manager_Log.txt Object is locked skipped
C:\Documents and Settings\Crystal\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Crystal\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Crystal\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\desktop.ini Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\FaxCtr\FAXLOG32.CDX Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\FaxCtr\FAXLOG32.DBF Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\FaxCtr\FAXLOG32.FPT Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\funkitron\Poker Superstars II\Poker2.cfg Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\GoogleEarth\myplaces.backup.kml Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\GoogleEarth\myplaces.kml Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\GoogleEarth\myplaces.kml.tmp Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\GoogleEarth\myplaces.old Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\Local Search History\google%2Efroogle.w Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\Local Search History\google%2Eimages.w Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\Local Search History\google%2Emaps.w Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\Local Search History\google%2Enews.w Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Google\Local Search History\google%2Eweb.w Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\InterVideo\WinDVD\5.0\Bookmark\BANNED_IN_THE_ORIENT-237585784_Auto.bmk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\InterVideo\WinDVD\5.0\Bookmark\CHRIS_ROCK21839631110_Auto.bmk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\InterVideo\WinDVD\5.0\Bookmark\HIDALGO-404334382_Auto.bmk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\InterVideo\WinDVD\5.0\Bookmark\RIPLEY1308751852_Auto.bmk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\InterVideo\WinDVD\5.0\Bookmark\StorageLabs TinyUDF Volume1419890642_Auto.bmk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\InterVideo\WinDVD\5.0\Bookmark\StorageLabs TinyUDF Volume1437731713_Auto.bmk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\InterVideo\WinDVD\5.0\Bookmark\THE_MATRIX_16X9LB_N_AMERICA-434913808_Auto.bmk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#Security\FlashPlayerTrust\AOL.cfg Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\admin.brightcove.com\markers.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\aolcdn.com\_media\aolvideo30\rootmovie351.swf\videoSO.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\bankofamerica.com\sas\sas-docs\html\pmfso.swf\PassMark.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\bin.clearspring.com\clearspring.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\cosmos.bcst.yahoo.com\LCOMMENGINEMGR.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\cosmos.bcst.yahoo.com\up\player\popup\swf\POP_tray.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\cosmos.bcst.yahoo.com\up\vyc_e\embed\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\earth.google.com\datastore.swf\googleEarthSettings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\entimg.msn.com\i\rs2\build3\main.swf\msn.rockstar.site.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\entimg.msn.com\userPreferencesmyLSORockstar.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\finetune.com\finetune.user.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\flash.quantserve.com\com.quantserve.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\flash.revver.com\player\1.0\core.swf\revverplayer.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\flash.revver.com\player\1.0\player.swf\revverplayer.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\games.armorgames.com\games0015\gladiatorcastlewars.swf\unlockable.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\groveparkinn.com\filmstrip6.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\groveparkinn.com\marketingfilmstrip.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\groveparkinn.com\splashfilmstrip.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\hiltonjourneys.com\userPreferencesBlitzDemo.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\ibsys.com\sh\idi\templates\videoplayer_180x135.swf\flashcookie.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\ibsys.com\sh\idi\templates\videoplayer_200x150.swf\flashcookie.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\images.metacafe.com\MetacafeFlashVideoPlayer.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\ivillage.com\rightcol\rightcol.swf\ivillage.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\l.yimg.com\cosmos.bcst.yahoo.com\ver\226\popup-2007-04-18-0959\swf\POP_tray.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\l.yimg.com\cosmos.bcst.yahoo.com\ver\230b\popup-2007-05-07-1251\swf\POP_tray.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\l.yimg.com\cosmos.bcst.yahoo.com\ver\234\embed-2007-06-19-1259\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\l.yimg.com\cosmos.bcst.yahoo.com\ver\234\popup-2007-06-19-1259\swf\POP_tray.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\l.yimg.com\cosmos.bcst.yahoo.com\ver\237\embed-2007-07-31-1718\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\l.yimg.com\LCOMMENGINEMGR.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\login.yahoo.com\loginCache.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\mochibot.com\com.mochibot.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\msn.foxsports.com\userPreferencesundefined.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\pagead2.googlesyndication.com\pagead\googleadplayer.swf\mediaPlayerUserSettings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\resources.imeem.com\com.quantserve.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\seal.buysafe.com\buySAFE.com.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\sparkart.net\crissangel\index39.swf\BBSO.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\sparkart.net\crissangel\index39.swf\BBSO_351.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\static.espn.go.com\motion\fsp\FSPRoot\espnmotion1_cv.swf\fspSettings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\static.userplane.com\presence\presence.swf\presence_1.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\suitesmart.com\FTGCREXP_6637.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\suitesmart.com\_f5e.swf\5thElement.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\traffic.com\userSO.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\uncutvideo.aol.com\soundcookie.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\us.i1.yimg.com\cosmos.bcst.yahoo.com\player\embed-2-0-2006-12-08-1317\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\us.i1.yimg.com\cosmos.bcst.yahoo.com\player\embed-2-0-2007-01-30-1601\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\us.i1.yimg.com\COSMOSPrefs.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\us.i1.yimg.com\LCOMMENGINEMGR.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\us.i1.yimg.com\us.yimg.com\a\1-\java\promotions\gm\071107\container.swf\swfCounter.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\us.i1.yimg.com\vidPlayer.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\video.google.com\googleplayer.swf\mediaPlayerUserSettings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\video.nbc.com\embed\player_2-1\embedded.swf\nbcuvp.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\video.nbc.com\lastConnectionSettings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\video.yahoo.com\js\ccp.swf\yvp.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\video1.redorbit.com\player_v2\bht_large.swf\Lightningcast.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.aetv.com\flash\multiplayer.swf\Lightningcast.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.americanidol.com\userPreferencesundefined.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.bubblebox.com\swf\103\stickarena.swf\xgsalite6.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.cingular.com\cell-phone-service\swf\home_marquee.swf\cingularCookie.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.cmt.com\loaded\Loaded.1.5.swf\UserPrefs.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.comedycentral.com\UserPrefs.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.ge.com\userPreferencesGEITSO.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.grindtv.com\player.swf\user_profile.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.heavy.com\browserling\browserling3.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.heavy.com\channels_swfs\asc_current.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.heavy.com\HeavyVideoPlayer.swf\json_data.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.ifilm.com\flash\container2.swf\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.jibjab.com\randomjoke.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.metacafe.com\MetacafeFlashVideoPlayer.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.playersonly.com\index.swf\playersonly.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.sho.com\site\video\stream\movies\screen_3.swf\sessionID.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.skechers.com\images\landing\skechers_landing_590x770.swf\FPMData.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.stupidvideos.com\player.swf\user_profile.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.wesh.com\download\sh\images\flash\mediawindow_320x340_v1.swf\mediaWindowSO4.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.youtube.com\soundData.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.youtube.com\soundData_level0.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\www.youtube.com\timeDisplayConfig.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\#SharedObjects\FJQV8G96\youtube.com\soundData.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\aolcdn.com\_media\aolvideo30\rootmovie351.swf\videoSO.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\doubleclick.net\runforyourflight.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\espn.go.com\mPreferences.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\localhost\core.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#admin.brightcove.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#aolcdn.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bankofamerica.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cdn.channel.aol.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cosmos.bcst.yahoo.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#doubleclick.net\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#entimg.msn.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#espn.go.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#finetune.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#flash.quantserve.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#flash.revver.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#games.armorgames.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#godlikeproductions.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#groveparkinn.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#hiltonjourneys.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#ibsys.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#images.metacafe.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#ivillage.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#l.yimg.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#local\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#login.yahoo.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mochibot.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#msn.foxsports.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#pagead2.googlesyndication.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#resources.imeem.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#rr.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#seal.buysafe.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#sparkart.net\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.espn.go.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.userplane.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#suitesmart.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#traffic.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#uncutvideo.aol.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#us.i1.yimg.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video.google.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video.nbc.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video.yahoo.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video1.redorbit.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#wjrr.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.aetv.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.americanidol.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.bubblebox.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.cingular.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.cmt.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.comedycentral.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.ge.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.grindtv.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.heavy.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.ifilm.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.jibjab.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.metacafe.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.playersonly.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.sho.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.skechers.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.stupidvideos.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.wesh.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.youtube.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#youtube.com\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\rr.com\flash\browser-1.0.swf\QL.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\rr.com\flash\browser-1.0.swf\QLdivision.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\rr.com\flash\browser-1.0.swf\QLloggedIn.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\rr.com\QLpolling.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\rr.com\QLsag.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Macromedia\Flash Player\wjrr.com\WJRR-FM.sol Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\.NET Framework Config\v1.0.5000.0\settings.xml Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Address Book\GREGORY.wab Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Address Book\GREGORY.wab~ Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CLR Security Config\v1.1.4322\security.config Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CLR Security Config\v1.1.4322\security.config.cch Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Credentials\S-1-5-21-405975939-62259662-1152745810-1006\Credentials Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\303572DF538EDD8B1D606185F1D559B8 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\33ECCD4EC2899E5F6A7E306662596E0F Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\3C83474D61E624A4F9844DF935AFE217 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\486CC6AFD08942336C61FCD401C4A1D1 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\561F989D166B9195191D8592AEB81CDD Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\5C8DDA36D60247082B142836039F4636 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\71644221AC231DBD2359C18EBB2118DC Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\74BFD122C0875EC75DBE5C6DB4C59019 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\7735880A01E3F94F763761958A7A8191 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\79841F8EF00FBA86D33CC5A47696F165 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\7B2238AACCEDC3F1FFE8E7EB5F575EC9 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\7C8A03C4580C6B04FDF34357F3474EDC Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\904590238400AD963F77FAAAADC9BAB5 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\AE50E4037196A443C2E8F56DAD9E165B Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\B2F4B1D39F0694C6CDB433BC3CCF1418 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\B69D763EB21649DA26F20618312DEE70 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\B82262A5D5DA4DDACE9EDA7F787D0DEB Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\C571B417AAF1F617555A0486AB3F5361 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\CFC456E7E410D69E2C6F3E2DB75C7DB3 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\DC2135CED98D8A4D7C0CEE202BB0B810 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\EE7DFEE2CA8CFB0F905ED5FA70B3CD71 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\F482C95F83F1B59228F1B1E720F2EDF1 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\Content\F5A17C00E427F919C4A49EEF5AD0EE53 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\303572DF538EDD8B1D606185F1D559B8 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\33ECCD4EC2899E5F6A7E306662596E0F Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\3C83474D61E624A4F9844DF935AFE217 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\486CC6AFD08942336C61FCD401C4A1D1 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\561F989D166B9195191D8592AEB81CDD Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\5C8DDA36D60247082B142836039F4636 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\71644221AC231DBD2359C18EBB2118DC Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\74BFD122C0875EC75DBE5C6DB4C59019 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\7735880A01E3F94F763761958A7A8191 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\79841F8EF00FBA86D33CC5A47696F165 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\7B2238AACCEDC3F1FFE8E7EB5F575EC9 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\7C8A03C4580C6B04FDF34357F3474EDC Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\904590238400AD963F77FAAAADC9BAB5 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\AE50E4037196A443C2E8F56DAD9E165B Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\B2F4B1D39F0694C6CDB433BC3CCF1418 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\B69D763EB21649DA26F20618312DEE70 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\B82262A5D5DA4DDACE9EDA7F787D0DEB Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\C571B417AAF1F617555A0486AB3F5361 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\CFC456E7E410D69E2C6F3E2DB75C7DB3 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\DC2135CED98D8A4D7C0CEE202BB0B810 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\EE7DFEE2CA8CFB0F905ED5FA70B3CD71 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\F482C95F83F1B59228F1B1E720F2EDF1 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\CryptnetUrlCache\MetaData\F5A17C00E427F919C4A49EEF5AD0EE53 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Crypto\RSA\S-1-5-21-405975939-62259662-1152745810-1006\360e9316558dc5fc61c74119e7e1abb7_e6505d7a-89ca-4719-b6f0-2fe4a3b60ba2 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Crypto\RSA\S-1-5-21-405975939-62259662-1152745810-1006\6151549f1b830bc28d3ae3bd878e1f30_e6505d7a-89ca-4719-b6f0-2fe4a3b60ba2 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Crypto\RSA\S-1-5-21-405975939-62259662-1152745810-1006\83aa4cc77f591dfc2374580bbd95f6ba_e6505d7a-89ca-4719-b6f0-2fe4a3b60ba2 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\HTML Help\hh.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Installer\{6815FCDD-401D-481E-BA88-31B4754C2B46}\ARPPRODUCTICON.exe Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Installer\{9860A9CF-7E71-43AC-888F-0B4D3EA212D1}\KK.exe Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\brndlog.bak Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL 9.0.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\AOL Explorer.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC for Errors.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Outlook.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\Play iWin Games.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\Warez Shared Folder.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Media Player\011FDFCD.wpl Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Backgrounds\map.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Backgrounds\TFR6D.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Backgrounds\TFRA9.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Backgrounds\TFRAA.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Backgrounds\TFRAB.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Backgrounds\TFRAC.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Backgrounds\TFRAD.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\DynamicBackgrounds\map.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\DynamicBackgrounds\TFRB1.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\DynamicBackgrounds\TFRBC.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\DynamicBackgrounds\TFRC7.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\DynamicBackgrounds\TFRD2.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\ListCache.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\MapFile\TFR6E.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\MapFile\TFR6F.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\MapFile\TFR90.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\MapFile\TFRFA.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata01.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata02.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata03.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata04.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata05.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata06.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata07.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata08.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata09.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata10.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata11.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata12.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata13.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata14.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata15.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata16.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata17.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata18.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmdata19.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt01.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt02.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt03.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt04.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt05.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt06.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt07.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt08.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt09.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt10.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt11.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt12.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt13.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt14.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt15.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt16.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt17.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt18.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\sqmnoopt19.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\map.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFR8F.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFR9D.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFR9E.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFR9F.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFRA0.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFRA1.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFRA2.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFRA3.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFRA4.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFRA5.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFRA6.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\UserTile\TFRA7.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\map.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRDD.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRDF.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRE1.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRE3.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRE5.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRE7.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRE9.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFREB.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRED.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFREF.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRF1.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRF3.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRF5.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRF7.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\1404762323\Winks3\TFRF9.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3309069632\sqmdata00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3309069632\sqmnoopt00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Backgrounds\map.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Backgrounds\TFR2AC.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Backgrounds\TFR2AD.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Backgrounds\TFR2AE.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Backgrounds\TFR2AF.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Backgrounds\TFR2B0.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Backgrounds\TFR89.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\DynamicBackgrounds\map.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\DynamicBackgrounds\TFR2B4.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\DynamicBackgrounds\TFR2BF.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\DynamicBackgrounds\TFR2CA.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\DynamicBackgrounds\TFR2D5.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\ListCache.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\MapFile\TFR2FD.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\MapFile\TFR8A.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\MapFile\TFR8B.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\MapFile\TFRA6.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmdata00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmdata01.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmdata02.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmdata03.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmdata04.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmnoopt00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmnoopt01.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmnoopt02.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmnoopt03.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\sqmnoopt04.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\map.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A0.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A1.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A2.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A3.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A4.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A5.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A6.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A7.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A8.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2A9.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFR2AA.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\UserTile\TFRA5.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\map.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2E0.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2E2.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2E4.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2E6.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2E8.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2EA.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2EC.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2EE.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2F0.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2F2.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2F4.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2F6.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2F8.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2FA.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3346948707\Winks3\TFR2FC.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3382543017\sqmdata00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\3382543017\sqmnoopt00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\373983967\sqmdata00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\MSN Messenger\373983967\sqmnoopt00.sqm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Excel10.pip Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\FP10.pip Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\MSO1033.acl Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\MSOut10.pip Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\MSOut11.pip Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\PowerP10.pip Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\020107 on images.ibsys.com.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\056N4PGF.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\2006-Murders.xls.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\6efdbda6-ca9e-4122-9787-3fd7ca7d7f33 on download.microsoft.com.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\blakemccorkle.tripod.com.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\BRU556GX.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\criminal on www.seminolesheriff.org.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\Desktop.ini Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\Desktop.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\Gmail - Inmate Release Information Detail - Sent Using Google...LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\Gmail - Inmate Release Information Detail - Sent Using Google..0001.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\GTI7KLMZ.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\hawaii2005 on www.pria.us.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\index.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\mccorklehazmat.doc.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\mccorklehazmat.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\mccorklekey.doc.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\MSFaxWizardTempPreview-#000004e01C7DC6075D1BF.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\MSFaxWizardTempPreview-#00000d841C8734CFAE6FD.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\My Documents.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\My Webs.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\online_reg_form.doc.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\PRIA_MembershipReport_Hawaii2005.ppt.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\SLMFWVO3.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\Temp.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\Templates.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\WE7YYDIJ.LNK Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Recent\WFINF_Guide.doc.url Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Word10.pip Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Office\Word11.pip Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Outlook\Outlook.FAV Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Outlook\Outlook.NK2 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Proof\CUSTOM.DIC Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-2000478354-602609370-725345543-1003\f1596fa2-d961-4cdb-bb1e-749252d2a0da Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-2000478354-602609370-725345543-1003\Preferred Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\289f4c90-611a-4680-aa6a-7c830824f67c Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\55d54ad9-0b65-41b9-9683-e2a5e292ef52 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\78ad27c0-b67b-47e1-a9e3-6fe830576c0d Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\862d5265-9e92-42a3-954d-da1e8521c94d Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\b9d99a5b-fd77-4a90-af38-39b60ede65f7 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\c4f06021-e7a3-433b-b9ef-7e00a1103a88 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\ea54aa83-8ed4-403c-b772-bfdad688d66a Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\f3ae9cf9-0443-4c4f-97fe-0dca1d7d95f2 Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Protect\S-1-5-21-405975939-62259662-1152745810-1006\Preferred Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Speech\Files\UserLexicons\SP_72C596BB2D4841899358B8C9E098B339.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Templates\~$Normal.dot Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Windows\Themes\Custom.theme Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Windows Messenger\3346948707\ListCache.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Microsoft\Word\AutoRecovery save of Document.asd Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\MSNInstaller\cProductInfo.xml Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\MSNInstaller\msnauins.exe Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\MSNInstaller\msninstallerlog.xml Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Netscape\registry.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\Msg\104_1204251146\ipm_movies022808.html Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\Msg\3115_1204667723\bom_030408.htm Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\Msg\4155_1204324247\IPM 030108.html Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\Msg\Category.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\Msg\Messages.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\Msg\SCategory.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\cookies.txt Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\db\23.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\db\26.dat Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\db\Backup\000\000001.tmd Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\db\Backup\000\000002.tmd Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\db\Backup\000\000003.tmd Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\db\Backup\000\000004.tmd Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\db\Backup\000\000005.tmd Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Real\RealPlayer\db\Backup\000\000006.tmd Object is locked skipped
C:\Documents and Settings\GREGORY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-6d49a2a9-6338562c.zip/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\GREGORY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-6d49a2a9-6338562c.zip ZIP: infected - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1281OinAdmin.exe.vir Infected: Trojan.Win32.Scapur.k skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\windows.vir Infected: Trojan.Win32.Zapchast.dt skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{0C1D1238-A1EF-43EA-9ACF-9240DDBA7386}\RP1\A0000093.exe/nswatchdog.exe Infected: Trojan-Downloader.Win32.Agent.jlp skipped
C:\System Volume Information\_restore{0C1D1238-A1EF-43EA-9ACF-9240DDBA7386}\RP1\A0000093.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C1D1238-A1EF-43EA-9ACF-9240DDBA7386}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\GREG.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\nswatchdog.exe Infected: Trojan-Downloader.Win32.Agent.jlp skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\Perflib_Perfdata_6e8.dat Object is locked skipped
C:\WINDOWS\TEMP\ZLT01fd1.TMP Object is locked skipped
C:\WINDOWS\TEMP\ZLT04c57.TMP Object is locked skipped
C:\WINDOWS\TEMP\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Crystal

#10 ken545

ken545

    Malware Response Team


  • Malware Response Team
  • 1,685 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Space Coast of Florida
  • Local time:01:04 PM

Posted 16 March 2008 - 05:36 AM

Good Morning,

Those entries I asked about may be related to Lop Malware, lets run this tool.

Please Download No Lop to your desktop
  • First close any other programs you have running as this will require a reboot
  • Double click NoLop.exe to run it
  • Now click the button labeled "Search and Destroy"
    <<your computer will now be scanned for infected files>>
  • When scanning is finished you will be prompted to reboot only if infected, Click OK
  • Now click the "REBOOT" Button.
  • A Message should pop-up from NoLop. If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log after completing the next steps.
--If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.




REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boobcopyfraghold]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CastInter]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]


Copy the entire contents inside the Quote box and Paste it into Notepad ( this will only work with Notepad ) name the file Regfix.reg and in the drop down box, save it as All Files. Save it to your desktop. Then Rightclick on the Regfix.reg file and click on Merge, when it asks you to merge with the Registry, say yes.

If you saved the file correctly it should look like this Posted Image



You need to enable windows to show all files and folders, instructions Here

Delete these please
C:\Program Files\NetRatingsNetSight
C:\WINDOWS\nswatchdog.exe


Post the LOP report and a New HJT log and let me know how your system is running now????

mvp_host.pngConsumer Security 2007-2008-2009-2010-2011-2012-2013-2014



donate.gif Please consider a donation to help me keep up my fight against malware.

 

Just a reminder that threads will be closed if no response in 3 days


#11 crystal13

crystal13
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 16 March 2008 - 12:22 PM

NoLop link will not work, does not give me the option to save file.
Crystal

#12 crystal13

crystal13
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 16 March 2008 - 12:24 PM

Sorry never mind, I got it to work.
Crystal

#13 crystal13

crystal13
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 16 March 2008 - 01:02 PM

C:\Program Files\NetRatingsNetSight
cannot delete nscore.dll access is denied
There is no No Lop log, I guess this is because it did not find any infections. The system seams to be running fine.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:05 PM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
C:\Program Files\Support.com\BellSouth\hcenter.exe
C:\WINDOWS\System32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - > - (no file)
O2 - BHO: (no name) - 8 - (no file)
O2 - BHO: (no name) - C31B-401F-89BC-4CBB25E853D7} - (no file)
O2 - BHO: (no name) - h@ - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: (no name) - {2BCE3224-D277-413E-A16D-DCE4B8AA32DB} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - = - (no file)
O2 - BHO: (no name) - @ - (no file)
O2 - BHO: (no name) - $ - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [GC75-Manager-Class] "C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AirCardEnabler] C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [PINGER] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [ZoomingHook] c:\WINDOWS\System32\ZoomingHook.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: jhexftep - C:\WINDOWS\
O21 - SSODL: WinMain - {C231CF11-134F-3552-44AC-E685D962C63C} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsubleepa Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)

--
End of file - 11431 bytes
Crystal

#14 ken545

ken545

    Malware Response Team


  • Malware Response Team
  • 1,685 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Space Coast of Florida
  • Local time:01:04 PM

Posted 16 March 2008 - 05:30 PM

Hello,

We have some bad entries return, you need to disable the TeaTimer in Spybot and leave it disabled until we are entirely done.

Download Reset Tea Timer to your desktop, you need to use Internet Explorer, double click it to run, just takes a sec.

REBOOT YOUR COMPUTER


Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - > - (no file)
O2 - BHO: (no name) - 8 - (no file)
O2 - BHO: (no name) - C31B-401F-89BC-4CBB25E853D7} - (no file)
O2 - BHO: (no name) - h@ - (no file)
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: (no name) - {2BCE3224-D277-413E-A16D-DCE4B8AA32DB} - (no file)
O2 - BHO: (no name) -  - (no file)
O2 - BHO: (no name) - = - (no file)
O2 - BHO: (no name) - @ - (no file)
O2 - BHO: (no name) - $ - (no file)

O20 - Winlogon Notify: jhexftep - C:\WINDOWS\

O21 - SSODL: WinMain - {C231CF11-134F-3552-44AC-E685D962C63C} - (no file)





Please download SuperAntiSpyware Free
Install the program
  • Run SuperAntiSpyware and click: Check for updates
  • Once the update is finished, on the main screen, click: Scan your computer
  • Check: Perform Complete Scan
  • Click Next to start the scan.
Superantispyware scans the computer, and when finished, lists all the infections found.
Make sure everything found has a check next to it, and press: Next <-- Important
Then, click Finish

It is possible that the program asks to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
  • Click: Preferences
  • Click the Statistics/Logs tab
  • Under Scanner Logs, double-click SuperAntiSpyware Scan Log
It opens in your default text editor (such as Notepad)

Please provide the SuperAntiSpyware log in your reply, as well as a new HijackThis log.




Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::

File::
C:\WINDOWS\nswatchdog.exe
C:\WINDOWS\system32\drivers\nnrnstdi.sys 

Folder::
C:\Program Files\NetRatingsNetSight

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.


Post the SAS log , the Combofix log and a new HJT log please

mvp_host.pngConsumer Security 2007-2008-2009-2010-2011-2012-2013-2014



donate.gif Please consider a donation to help me keep up my fight against malware.

 

Just a reminder that threads will be closed if no response in 3 days


#15 crystal13

crystal13
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:12:04 PM

Posted 17 March 2008 - 01:47 PM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/17/2008 at 02:23 AM

Application Version : 4.0.1154

Core Rules Database Version : 3420
Trace Rules Database Version: 1412

Scan type : Complete Scan
Total Scan Time : 00:39:21

Memory items scanned : 557
Memory threats detected : 0
Registry items scanned : 5450
Registry threats detected : 0
File items scanned : 15374
File threats detected : 16

Adware.Tracking Cookie
C:\Documents and Settings\Crystal\Cookies\crystal@ads.bleepingcomputer[1].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@adserver[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@247realmedia[1].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@apmebf[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@zedo[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@realmedia[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@adrevolver[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@fastclick[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@advertising[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@mediaplex[1].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@ad.m5prod[1].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@casalemedia[1].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@adopt.specificclick[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@ad.yieldmanager[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@burstnet[2].txt
C:\Documents and Settings\GREGORY\Cookies\gregory@media.adrevolver[2].txt


ComboFix 08-03-14.4 - Crystal 2008-03-17 13:33:32.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.123 [GMT -5:00]
Running from: C:\Documents and Settings\Crystal\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Crystal\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\nswatchdog.exe
C:\WINDOWS\system32\drivers\nnrnstdi.sys
.

((((((((((((((((((((((((( Files Created from 2008-02-17 to 2008-03-17 )))))))))))))))))))))))))))))))
.

2008-03-17 01:30 . 2008-03-17 01:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-17 01:25 . 2008-03-17 01:25 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-17 01:25 . 2008-03-17 01:25 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\SUPERAntiSpyware.com
2008-03-16 18:05 . 2008-03-16 18:05 <DIR> d-------- C:\Program Files\CCleaner
2008-03-16 12:25 . 2008-03-16 12:25 106 --a------ C:\delete.bat
2008-03-15 20:44 . 2008-03-15 20:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-15 20:43 . 2008-03-15 20:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-15 14:36 . 2008-03-15 14:36 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-15 14:36 . 2008-03-15 14:36 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-03-15 14:36 . 2008-03-15 14:36 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Malwarebytes
2008-03-15 14:36 . 2008-03-15 14:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-15 13:17 . 2008-03-15 13:17 <DIR> d-------- C:\Program Files\Common Files\HP
2008-03-15 13:17 . 2008-03-15 13:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-03-15 13:15 . 2008-03-15 13:15 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-03-15 13:13 . 2008-03-15 13:13 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-03-15 13:12 . 2005-03-07 23:43 51,120 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-03-15 13:12 . 2005-03-07 23:43 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-03-15 13:11 . 2005-03-07 23:43 21,744 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-03-15 13:10 . 2004-09-29 12:12 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2008-03-15 13:10 . 2004-09-29 12:15 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2008-03-15 13:10 . 2004-09-29 12:09 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2008-03-15 13:10 . 2004-09-29 12:14 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2008-03-15 13:10 . 2004-09-29 12:08 61,440 --a------ C:\WINDOWS\system32\HPZinw12.exe
2008-03-15 13:10 . 2004-09-29 12:09 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2008-03-15 13:08 . 2008-03-15 13:17 <DIR> d-------- C:\Program Files\HP
2008-03-15 13:03 . 2008-03-15 13:03 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\HP
2008-03-15 13:03 . 2008-03-15 13:21 112,924 --a------ C:\WINDOWS\hpoins07.dat
2008-03-15 13:03 . 2005-05-24 01:52 21,124 --------- C:\WINDOWS\hpomdl07.dat
2008-03-07 20:02 . 2008-03-17 13:38 5,169,184 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-07 20:02 . 2008-03-17 13:21 61,412 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-07 20:00 . 2008-03-07 20:00 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2008-03-07 19:57 . 2008-03-07 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-07 19:57 . 2007-11-14 17:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-03-07 19:57 . 2008-03-07 20:00 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-07 19:56 . 2008-03-07 19:56 <DIR> d-------- C:\Program Files\Zone Labs
2008-03-07 19:29 . 2008-03-17 13:34 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-03-07 00:39 . 2008-03-07 21:03 <DIR> d-------- C:\Program Files\Gutterball 2
2008-03-06 22:20 . 2008-03-07 00:34 <DIR> d-------- C:\Program Files\Saints & Sinners Bowling
2008-03-06 22:19 . 2008-03-06 22:19 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-03-06 17:43 . 2008-03-06 17:43 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-06 13:35 . 2008-03-06 13:36 <DIR> d-------- C:\Documents and Settings\Crystal\.housecall6.6
2008-03-06 01:01 . 2008-03-06 01:02 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-06 01:01 . 2008-03-06 01:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-05 22:30 . 2008-03-05 22:30 <DIR> d-------- C:\Program Files\Lavasoft
2008-03-05 22:30 . 2008-03-05 22:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-05 22:09 . 2007-12-04 08:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-05 22:09 . 2004-01-09 04:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-05 22:09 . 2007-12-04 07:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-05 22:09 . 2007-12-04 09:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-05 22:09 . 2007-12-04 09:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-05 22:09 . 2007-12-04 09:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-05 22:09 . 2007-12-04 09:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-05 22:09 . 2007-12-04 09:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-05 15:50 . 2008-03-17 13:23 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-05 15:50 . 2008-03-15 17:26 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-05 15:49 . 2008-03-05 15:49 0 --a------ C:\WINDOWS\CePMTray.INI
2008-03-05 15:48 . 2008-03-05 15:48 0 --a------ C:\WINDOWS\TPTray.INI
2008-03-04 21:59 . 2008-03-17 00:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-03-04 19:47 . 2007-12-06 21:21 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-04 19:47 . 2007-06-30 22:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-04 19:47 . 2007-06-30 22:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-04 19:47 . 2007-12-06 21:21 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-04 19:47 . 2007-12-06 21:21 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-04 19:47 . 2007-12-06 21:21 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-04 19:47 . 2007-12-06 21:21 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-04 19:47 . 2007-12-06 21:21 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-04 19:47 . 2007-12-06 06:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-04 19:39 . 2007-08-13 19:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-03-04 19:27 . 2008-03-04 19:27 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\MySpace
2008-03-04 16:19 . 2008-03-04 16:19 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-03-04 16:17 . 2005-02-23 15:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2008-03-04 11:14 . 2008-01-12 19:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-04 11:14 . 2008-01-15 10:54 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-04 11:14 . 2008-01-15 06:28 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-03 18:54 . 2008-03-05 15:33 <DIR> d-------- C:\Program Files\MySpace
2008-03-03 18:54 . 2008-03-03 18:54 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\MySpace
2008-03-03 13:07 . 2008-03-03 13:07 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-03-03 12:56 . 2008-03-03 12:56 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-03-02 21:59 . 2007-07-09 08:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-03-02 21:43 . 2008-03-02 21:43 <DIR> d--h----- C:\WINDOWS\PIF
2008-03-02 21:33 . 2007-07-30 20:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-03-02 21:33 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-03-02 21:33 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-02 21:33 . 2007-07-30 20:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-03-02 20:47 . 2008-03-15 13:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-02 20:45 . 2008-03-15 13:48 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-02 20:43 . 2005-05-03 13:58 78,848 --a------ C:\WINDOWS\system32\msiexec.exe
2008-03-02 20:43 . 2005-05-03 13:58 78,848 --a--c--- C:\WINDOWS\system32\dllcache\msiexec.exe
2008-03-02 20:40 . 2008-03-02 20:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-02 20:22 . 2008-03-17 12:59 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-02-26 17:14 . 2008-02-26 17:14 <DIR> d-------- C:\Documents and Settings\GREGORY\Application Data\Flock
2008-02-25 19:21 . 2008-03-17 01:24 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-25 11:44 . 2008-03-16 18:11 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Flock
2008-02-25 11:42 . 2008-03-16 18:11 <DIR> d-------- C:\Program Files\Flock
2008-02-23 23:09 . 2008-02-23 23:09 <DIR> d-------- C:\_OTMoveIt
2008-02-23 01:16 . 2008-02-23 01:16 <DIR> d-------- C:\Program Files\ACW
2008-02-23 00:21 . 2008-02-23 00:23 <DIR> d-------- C:\DVD RAM.temp
2008-02-23 00:11 . 2008-02-23 00:11 <DIR> d-------- C:\Documents and Settings\Crystal\Application Data\Sonic
2008-02-22 20:54 . 2008-02-22 20:54 65,536 --a------ C:\WINDOWS\system32\drivers\Audio3D.dll
2008-02-22 20:54 . 2008-02-22 20:54 65,536 --a------ C:\WINDOWS\system32\Audio3D.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-15 19:09 --------- d-----w C:\Program Files\Viewpoint
2008-03-14 06:03 1,168,384 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-03-12 03:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-09 22:16 981,504 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-03-05 19:14 --------- d-----w C:\Program Files\Google
2008-03-04 21:32 --------- d-----w C:\Documents and Settings\Crystal\Application Data\ArcSoft
2008-03-04 21:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-04 21:19 --------- d-----w C:\Program Files\ArcSoft
2008-02-17 17:53 --------- d-----w C:\Documents and Settings\GREGORY\Application Data\Smart PC Solutions
2008-02-16 07:53 --------- d-----w C:\Documents and Settings\Crystal\Application Data\Morpheus
2008-02-14 23:04 4,676,096 ----a-r C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-02-14 17:33 --------- d-----w C:\Program Files\Error Repair Professional
2008-02-14 17:00 --------- d-----r C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-14 15:57 --------- d-----w C:\Program Files\Support.com
2008-02-14 15:57 --------- d-----w C:\Program Files\Common Files\SupportSoft
2008-02-14 15:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Support.com
2008-02-14 13:44 --------- d-----w C:\Program Files\FastAccessDSL
2008-02-14 05:56 --------- d-----w C:\Program Files\BellSouth
2008-02-13 20:31 16,857,600 ----a-r C:\WINDOWS\RTHDCPL.exe
2008-02-12 23:10 --------- d-----w C:\Program Files\Yahoo!
2008-02-12 18:04 --------- d-----w C:\Documents and Settings\GREGORY\Application Data\Talkback
2008-02-12 17:41 --------- d-----w C:\Documents and Settings\GREGORY\Application Data\GameHouse
2008-02-12 17:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-02-11 05:18 67,042 ----a-w C:\Program Files\INSTALL.LOG
2008-02-11 05:17 --------- d-----w C:\Program Files\BellSouth Application Management
2008-02-11 04:50 --------- d-----w C:\Program Files\Common Files\Motive
2008-02-10 23:46 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-02-10 18:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-02-10 03:34 --------- d-----w C:\Documents and Settings\Administrator\Application Data\toshiba
2008-02-10 03:34 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-10 03:34 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InterVideo
2008-02-10 03:34 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-02-10 03:33 --------- d-----w C:\Program Files\UBNet
2008-02-10 03:33 --------- d-----w C:\Documents and Settings\GREGORY\Application Data\Netscape
2008-02-10 03:33 --------- d-----w C:\Documents and Settings\Crystal\Application Data\Yahoo!
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\aolshare
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\aolback
2008-02-10 03:32 --------- d-----w C:\Program Files\Common Files\AOL
2008-02-10 03:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-10 03:31 --------- d-----w C:\Program Files\Webshots
2008-02-10 03:31 --------- d-----w C:\Program Files\Photo Viewer
2008-02-10 03:31 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-10 03:31 --------- d-----w C:\Documents and Settings\Crystal\Application Data\toshiba
2008-02-10 03:31 --------- d-----w C:\Documents and Settings\Crystal\Application Data\Symantec
2008-02-10 03:31 --------- d-----w C:\Documents and Settings\Crystal\Application Data\InterVideo
2008-02-10 03:31 --------- d-----w C:\Documents and Settings\Crystal\Application Data\InterTrust
2008-02-10 03:28 --------- d-----w C:\Program Files\Sony Ericsson
2007-12-22 00:01 139,264 ----a-w C:\WINDOWS\system32\RTLCPAPI.dll
2006-01-26 21:49 6,572 ----a-w C:\Program Files\Warez P2P ClientIPGUARD.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 05:24 65536]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 17:10 68856]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GC75-Manager-Class"="C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe" [2004-04-08 05:36 766045]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-08-19 19:44 77824]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-11 14:07 185896]
"AirCardEnabler"="C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe" [2003-04-16 09:21 151552]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [2005-08-31 15:14 1277952]
"PINGER"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 17:37 151552]
"ZoomingHook"="c:\WINDOWS\System32\ZoomingHook.exe" [2004-07-14 18:07 24576]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-07-28 18:23 53248]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-03-02 15:45 135168]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-02-03 16:47 1089589]
"NDSTray.exe"="NDSTray.exe" []
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-09-26 17:43 184320]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-11-18 03:24 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-11-18 03:11 118784]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-07-14 04:04 122939]
"CeEPOWER"="C:\Program Files\TOSHIBA\Power Management\CePMTray.exe" [2004-08-19 20:14 135168]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2004-08-06 17:14 643072]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 23:10 339968]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-30 18:46 192512]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 17:00 88363 C:\WINDOWS\agrsmmsg.exe]
"HostManager"="C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 17:05 919016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Notebook Maximizer"="C:\Program Files\Notebook Maximizer\maximizer_startup.exe" [2004-05-25 16:35 28672]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]

C:\Documents and Settings\GREGORY\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-11 18:40:29 45056]

C:\Documents and Settings\Crystal\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-11 18:40:29 45056]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-03-04 21:59:19 125624]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2004-08-19 18:18:56 155648]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
backup=C:\WINDOWS\pss\RAMASST.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzButton]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=

R2 VProt2k;BroadJump PPPoE Helper Protocol;C:\WINDOWS\system32\DRIVERS\VProt2k.SYS [2003-05-10 16:18]
R3 VWan2k;BroadJump PPPoE Adapter;C:\WINDOWS\system32\DRIVERS\VWan2k.SYS [2003-05-10 16:19]
S3 ACGPRS;Sierra Wireless GPRS Adapter;C:\WINDOWS\system32\DRIVERS\acgprs.sys [2004-05-19 16:26]
S3 SEWModem;Sony Ericsson Wireless Modem;C:\WINDOWS\system32\DRIVERS\GC75.sys [2004-04-26 00:42]
S3 SEWWNIC;Sony Ericsson Wireless WAN Adapter;C:\WINDOWS\system32\DRIVERS\GC75Net.sys [2004-04-26 00:42]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-17 13:38:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-17 13:40:18
ComboFix-quarantined-files.txt 2008-03-17 18:40:13
ComboFix2.txt 2008-03-15 22:36:30
ComboFix3.txt 2008-03-06 02:47:18
ComboFix4.txt 2008-02-27 07:05:54
ComboFix5.txt 2008-02-27 06:56:56
.
2008-03-13 04:05:43 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:42:25 PM, on 3/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
C:\Program Files\Support.com\BellSouth\hcenter.exe
C:\WINDOWS\System32\ZoomingHook.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Webshots\Webshots.scr
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) - $ - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [GC75-Manager-Class] "C:\Program Files\Sony Ericsson\Wireless Manager\GC75Manager.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AirCardEnabler] C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [PINGER] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [ZoomingHook] c:\WINDOWS\System32\ZoomingHook.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1197151429\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsubleepa Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)

--
End of file - 10947 bytes
Crystal




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users