Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan And Malware Infection


  • This topic is locked This topic is locked
7 replies to this topic

#1 sungura

sungura

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:35 PM

Posted 05 July 2007 - 11:22 AM

Every time Avast conducts a memory scan when I am connected to the internet it finds a trojan related to retadpu77.exe and aumbakkar... Even though I conduct the recommended action 'move to chest' the problem remains. Additionally, I have a growing pop up issue. Both issues emerged very suddenly after a friend used my computer.

Logfile of HijackThis v1.99.1
Scan saved at 10:57:19 AM, on 7/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\acs.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\aumbbkar.exe
C:\Program Files\M-Audio Fast Track\GBInst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVComS.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\svhost.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Belkin\Cardbus F5D7010\Wireless Utility\Belkinwcui.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\djrdaexu.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-xu\msntb.dll
O3 - Toolbar: eMusic Toolbar - {F8CC9B08-C14F-4A5C-B73B-518AFECC067A} - C:\Program Files\eMusic Toolbar\tbu50\emusicToolbar.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\system32\LVComS.exe
O4 - HKLM\..\Run: [PostCopy] C:\WINDOWS\system32\Belkin\F5U109\PostCopy.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\nfonjaay.dll",realset
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Registration-Studio 8.lnk = C:\Program Files\Pinnacle\Studio 8\Register\RegTool.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Belkin Wireless Utility.lnk = C:\Program Files\Belkin\Cardbus F5D7010\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\SYSTEM32\acs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\aumbbkar.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Fast Track Installer (FastTrackInstallerService) - Nemesis - C:\Program Files\M-Audio Fast Track\GBInst.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:35 PM

Posted 05 July 2007 - 12:46 PM

Hello,

* Download Combofix to your desktop.
Doubleclick combofix.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished and after reboot (in case it asks to reboot), combofix will open again to gather the necessary information for the log. This may take a bit. When done, Combofix will close and a log should open, combofix.txt.
Post the contents of this log in your next reply together with a new hijackthislog.
Do NOT post the ComboFix-quarantined-files.txt - unless I ask you to.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 sungura

sungura
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:35 PM

Posted 06 July 2007 - 12:11 AM

"King David" - 2007-07-05 22:55:19 - ComboFix 07-07-06 - Service Pack 2


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\craywmsc.dll
C:\WINDOWS\system32\nfonjaay.dll
C:\WINDOWS\system32\vdftalfk.dll
C:\WINDOWS\system32\ccqpnbuq.exe
C:\WINDOWS\system32\djrdaexu.exe
C:\WINDOWS\SYSTEM32\yaajnofn.ini
C:\WINDOWS\SYSTEM32\wvwxx.bak1
C:\WINDOWS\SYSTEM32\wvwxx.bak2
C:\WINDOWS\SYSTEM32\wvwxx.ini
C:\WINDOWS\SYSTEM32\wvwxx.bak1
C:\WINDOWS\SYSTEM32\wvwxx.bak2
C:\WINDOWS\SYSTEM32\wvwxx.ini
C:\WINDOWS\system32\ljjjjjh.dll
C:\WINDOWS\system32\xxwvw.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\KINGDA~1\ravmonlog
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\emusic toolbar
C:\Program Files\emusic toolbar\affid.dat
C:\Program Files\emusic toolbar\basis.xml
C:\Program Files\emusic toolbar\emusicToolbar.crc
C:\Program Files\emusic toolbar\icons.bmp
C:\Program Files\emusic toolbar\logo.bmp
C:\Program Files\emusic toolbar\msvcp60.dll
C:\Program Files\emusic toolbar\msvcrt.dll
C:\Program Files\emusic toolbar\newversion.txt
C:\Program Files\emusic toolbar\tbu50\affid.dat
C:\Program Files\emusic toolbar\tbu50\basis.xml
C:\Program Files\emusic toolbar\tbu50\cache\6e6697b743ee9a77a50e76315e839f68
C:\Program Files\emusic toolbar\tbu50\emusicToolbar.crc
C:\Program Files\emusic toolbar\tbu50\emusicToolbar.dll
C:\Program Files\emusic toolbar\tbu50\emusicToolbar.inf
C:\Program Files\emusic toolbar\tbu50\icons.bmp
C:\Program Files\emusic toolbar\tbu50\logo.bmp
C:\Program Files\emusic toolbar\tbu50\tbhelper.dll
C:\Program Files\emusic toolbar\tbu50\tbupdate.cab
C:\Program Files\emusic toolbar\tbu50\version.txt
C:\Program Files\emusic toolbar\tbu50affid.dat
C:\Program Files\emusic toolbar\version.txt
C:\Program Files\poolsv
C:\Program Files\poolsv\svhost.exe
C:\Program Files\poolsv\wr-1-0000077.exe
C:\Program Files\poolsv\YazzleBundle-1549.exe
C:\Program Files\svhost
C:\Program Files\svhost\wr-1-0000077.exe
C:\Program Files\winantispyware 2007
C:\Program Files\winantispyware 2007\AsAgents.xml
C:\Program Files\winantispyware 2007\atl71.dll
C:\Program Files\winantispyware 2007\AutoProcess.dat
C:\Program Files\winantispyware 2007\bnlink.dat
C:\Program Files\winantispyware 2007\database\enemies.dat
C:\Program Files\winantispyware 2007\database\knownfiles.dat
C:\Program Files\winantispyware 2007\database\TEBase.dat
C:\Program Files\winantispyware 2007\database\vbpv.dat
C:\Program Files\winantispyware 2007\dbupdate.dat
C:\Program Files\winantispyware 2007\fopnl.dll
C:\Program Files\winantispyware 2007\InstHelp.exe
C:\Program Files\winantispyware 2007\InstUp.exe
C:\Program Files\winantispyware 2007\lapv.dat
C:\Program Files\winantispyware 2007\license.rtf
C:\Program Files\winantispyware 2007\manual.pdf
C:\Program Files\winantispyware 2007\manual.url
C:\Program Files\winantispyware 2007\mfc71.dll
C:\Program Files\winantispyware 2007\monstate.dat
C:\Program Files\winantispyware 2007\msvcp71.dll
C:\Program Files\winantispyware 2007\msvcr71.dll
C:\Program Files\winantispyware 2007\ps.dat
C:\Program Files\winantispyware 2007\pv.dat
C:\Program Files\winantispyware 2007\quaratine.dat\#post_quarantine
C:\Program Files\winantispyware 2007\readme.rtf
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\01701e343b174591e85c2692\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\01701e343b174591e85c2692\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\096673fbfb414fd2349adbb9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\096673fbfb414fd2349adbb9\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\18ed2fbacb854a002e6413ac\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\18ed2fbacb854a002e6413ac\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1bd738a7693941fe6bdae2bf\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1bd738a7693941fe6bdae2bf\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1d23ebe4b95d457d50e287a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1d23ebe4b95d457d50e287a4\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1f794e9fdd85499296d37886\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1f794e9fdd85499296d37886\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1fdf248f97534fa3868097ae\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1fdf248f97534fa3868097ae\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\1fdf248f97534fa3868097ae\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\28cb29d4571f498b843690a5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\28cb29d4571f498b843690a5\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\29a83bd7bc09445cc910fa91\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\29a83bd7bc09445cc910fa91\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\2f4b65c0a48a4bafd09d5981\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\2f4b65c0a48a4bafd09d5981\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\396be3b1f70d4eb334cabb8b\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\396be3b1f70d4eb334cabb8b\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\39e5a295423c4ac13b43b882\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\39e5a295423c4ac13b43b882\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\3bd2f10306084c7891cebaa2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\3bd2f10306084c7891cebaa2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\3cb31f7105044c3c2c864180\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\3cb31f7105044c3c2c864180\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\3cd864681b634a2ece560e82\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\3cd864681b634a2ece560e82\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\46b12a7cb2fb47e3a9374dbb\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\46b12a7cb2fb47e3a9374dbb\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\4bcf6a9a3c864a94b02e8fad\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\4bcf6a9a3c864a94b02e8fad\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\4c8f5a4d0b6140526ae115b0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\4c8f5a4d0b6140526ae115b0\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\559dd20faa67400ddd6e41a3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\559dd20faa67400ddd6e41a3\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\56bbcdbc9b504d36af97eb8e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\56bbcdbc9b504d36af97eb8e\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\5779dc94f41d4953825e268e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\5779dc94f41d4953825e268e\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\57cc0869d89e49658bfae2a9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\57cc0869d89e49658bfae2a9\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\6190211aa0634437e1ba3287\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\6190211aa0634437e1ba3287\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\64a442e984864bedb067ec9f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\64a442e984864bedb067ec9f\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\6ad5c67fa8774f807d2c3eab\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\6ad5c67fa8774f807d2c3eab\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\6c753adc0b844f233ea531a5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\6c753adc0b844f233ea531a5\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\6d1a5126cb6a4b0e5461f4a5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\6d1a5126cb6a4b0e5461f4a5\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\71512837cf9f4e3e4ca176b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\71512837cf9f4e3e4ca176b5\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\7cd8fa6cb2054ccd31ffa995\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\7cd8fa6cb2054ccd31ffa995\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\7cd8fa6cb2054ccd31ffa995\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\8600576d51ce48fda3ded293\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\8600576d51ce48fda3ded293\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\874c68f87408457cabe1e0b2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\874c68f87408457cabe1e0b2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\8853a80171324821cd982695\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\8853a80171324821cd982695\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\94e2246aed7f4232e36ca395\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\94e2246aed7f4232e36ca395\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\97f9719d644746476a5382a2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\97f9719d644746476a5382a2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\9ea46decb23a42c40863db88\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\9ea46decb23a42c40863db88\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\a0385f0d769f4dec892c249b\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\a0385f0d769f4dec892c249b\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\ad7ce2e8065b4c7790c13d8e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\ad7ce2e8065b4c7790c13d8e\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\adf80f6f43a3466db1d0e286\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\adf80f6f43a3466db1d0e286\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b06d7d0815e344997e908081\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b06d7d0815e344997e908081\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b294bbe5b73640e8af2edc99\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b294bbe5b73640e8af2edc99\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b69a528bdde949fe3fcc0599\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b69a528bdde949fe3fcc0599\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b69fc4c8c10b4d6948df1f8e\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b69fc4c8c10b4d6948df1f8e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b69fc4c8c10b4d6948df1f8e\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b753ee7055c945d18b5440a0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\b753ee7055c945d18b5440a0\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\bc41965b37024c27eeba5290\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\bc41965b37024c27eeba5290\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\c16ac9b126b84edb02ad688d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\c16ac9b126b84edb02ad688d\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\e0100eefc3bb43504abe43b2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\e0100eefc3bb43504abe43b2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\e16a8db009e441c1d52efaa8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\e16a8db009e441c1d52efaa8\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\e53236228fb9480ad572dea0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\e53236228fb9480ad572dea0\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\f1c5b501e1e54812cbd320a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\f1c5b501e1e54812cbd320a4\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\f6d65f1487c04e42688833ab\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\0207d96014b1446391421da7\f6d65f1487c04e42688833ab\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\03efd090f020466af97d5e96\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\03efd090f020466af97d5e96\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\03efd090f020466af97d5e96\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\044933d5b8c54db4ea82379c\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\044933d5b8c54db4ea82379c\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\044933d5b8c54db4ea82379c\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\044933d5b8c54db4ea82379c\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\048057300975432e4ed630ab\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\048057300975432e4ed630ab\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\048057300975432e4ed630ab\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0607ca42365c499dd54fdf98\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0607ca42365c499dd54fdf98\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0607ca42365c499dd54fdf98\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0d791c4596d442cb105d2099\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0d791c4596d442cb105d2099\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0d791c4596d442cb105d2099\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0eca601d11044592b1478589\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0eca601d11044592b1478589\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0eca601d11044592b1478589\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0eca601d11044592b1478589\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0ed87adfd99047702b122f82\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0ed87adfd99047702b122f82\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0ed87adfd99047702b122f82\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\0ed87adfd99047702b122f82\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\10df11141ce0456eca0d3483\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\10df11141ce0456eca0d3483\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\10df11141ce0456eca0d3483\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\10df11141ce0456eca0d3483\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\125c52c8da3849ed24778983\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\125c52c8da3849ed24778983\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\125c52c8da3849ed24778983\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\125c52c8da3849ed24778983\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\1d873208e64e469ae584cead\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\1d873208e64e469ae584cead\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\1d873208e64e469ae584cead\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\201e092eba8a4ae1f3d5759d\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\201e092eba8a4ae1f3d5759d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\201e092eba8a4ae1f3d5759d\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\26393c8e0e154af8786a288e\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\26393c8e0e154af8786a288e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\26393c8e0e154af8786a288e\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\28158427166a45cb94fac297\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\28158427166a45cb94fac297\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\28158427166a45cb94fac297\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\29579b5f4a754e0613d01b89\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\29579b5f4a754e0613d01b89\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\29579b5f4a754e0613d01b89\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\2dfe1546507c406e14cf8eb9\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\2dfe1546507c406e14cf8eb9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\2dfe1546507c406e14cf8eb9\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\2dfe1546507c406e14cf8eb9\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3651cea7e9ee49d7fa85919b\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3651cea7e9ee49d7fa85919b\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3651cea7e9ee49d7fa85919b\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\36aec406997d4ee2db37e9a6\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\36aec406997d4ee2db37e9a6\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\36aec406997d4ee2db37e9a6\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3a852ad644bd48560b8e4988\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3a852ad644bd48560b8e4988\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3a852ad644bd48560b8e4988\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3c2bd3e83bca4477de4f598e\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3c2bd3e83bca4477de4f598e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3c2bd3e83bca4477de4f598e\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3d37f55ca70d4be6e83c00a8\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3d37f55ca70d4be6e83c00a8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3d37f55ca70d4be6e83c00a8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3d37f55ca70d4be6e83c00a8\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3ea614787b814ed0e08372a4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3ea614787b814ed0e08372a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3ea614787b814ed0e08372a4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3f39a969a5ef4d9bd7b11a85\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3f39a969a5ef4d9bd7b11a85\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3f39a969a5ef4d9bd7b11a85\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3fae8e890b9c47305811ce9d\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3fae8e890b9c47305811ce9d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\3fae8e890b9c47305811ce9d\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\461dfa3344454e109df4db92\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\461dfa3344454e109df4db92\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\461dfa3344454e109df4db92\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\4d6a9d1800344cd90518e7bb\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\4d6a9d1800344cd90518e7bb\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\4d6a9d1800344cd90518e7bb\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\4d6a9d1800344cd90518e7bb\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\50b344479fc14ceb5116b38a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\50b344479fc14ceb5116b38a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\50b344479fc14ceb5116b38a\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\56a06a154ba94031720d94a5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\56a06a154ba94031720d94a5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\56a06a154ba94031720d94a5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\5f8842e1d6f247d61f92d2a8\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\5f8842e1d6f247d61f92d2a8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\5f8842e1d6f247d61f92d2a8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\66cec9a298704954daf10dae\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\66cec9a298704954daf10dae\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\66cec9a298704954daf10dae\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\66cec9a298704954daf10dae\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\6d36af6c5672478ea5a8f883\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\6d36af6c5672478ea5a8f883\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\6d36af6c5672478ea5a8f883\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\6d36af6c5672478ea5a8f883\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\6d54f09c0df643f401dd05b1\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\6d54f09c0df643f401dd05b1\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\6d54f09c0df643f401dd05b1\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\6d54f09c0df643f401dd05b1\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\71440d4a0ca243be2e5250a4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\71440d4a0ca243be2e5250a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\71440d4a0ca243be2e5250a4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\71440d4a0ca243be2e5250a4\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\823c694869304712f74fdc86\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\823c694869304712f74fdc86\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\823c694869304712f74fdc86\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\823c694869304712f74fdc86\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\82f1ac68b29c49f14a4b2e81\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\82f1ac68b29c49f14a4b2e81\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\82f1ac68b29c49f14a4b2e81\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\8524ecff0d044c635cc753b7\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\8524ecff0d044c635cc753b7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\8524ecff0d044c635cc753b7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\86a789c48e4d4270aa5670a4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\86a789c48e4d4270aa5670a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\86a789c48e4d4270aa5670a4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\8d912be2e087431ca44e3c89\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\8d912be2e087431ca44e3c89\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\8d912be2e087431ca44e3c89\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\a72777788c80402fadb91dbd\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\a72777788c80402fadb91dbd\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\a72777788c80402fadb91dbd\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\a72777788c80402fadb91dbd\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b0c0fc1439da4a54f801f5ae\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b0c0fc1439da4a54f801f5ae\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b0c0fc1439da4a54f801f5ae\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b699c458d8e94b1ea2fd41b2\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b699c458d8e94b1ea2fd41b2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b699c458d8e94b1ea2fd41b2\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b6ff1c10bc9a495f894227a2\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b6ff1c10bc9a495f894227a2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b6ff1c10bc9a495f894227a2\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b80df76b226f4ba04520f3ae\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b80df76b226f4ba04520f3ae\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b80df76b226f4ba04520f3ae\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b87e307fe2404267437464bf\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b87e307fe2404267437464bf\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\b87e307fe2404267437464bf\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\bdb553d255234b1fb90906a5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\bdb553d255234b1fb90906a5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\bdb553d255234b1fb90906a5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\bfb5cb60d41842e5a92ec1bb\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\bfb5cb60d41842e5a92ec1bb\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\bfb5cb60d41842e5a92ec1bb\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\bfb5cb60d41842e5a92ec1bb\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\c0e07810a0d24aab2b4b959f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\c0e07810a0d24aab2b4b959f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\c0e07810a0d24aab2b4b959f\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\c1a6c4eb515c4832e1d29895\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\c1a6c4eb515c4832e1d29895\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\c1a6c4eb515c4832e1d29895\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\c1a6c4eb515c4832e1d29895\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\cb079455c4774fe7198ddd96\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\cb079455c4774fe7198ddd96\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\cb079455c4774fe7198ddd96\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\cf1e2ae83e334ac221a68e84\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\cf1e2ae83e334ac221a68e84\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\cf1e2ae83e334ac221a68e84\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\d1b3d104db3b46ed0d284bb4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\d1b3d104db3b46ed0d284bb4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\d1b3d104db3b46ed0d284bb4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dc32c6260548421fd6016491\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dc32c6260548421fd6016491\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dc32c6260548421fd6016491\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dc32c6260548421fd6016491\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dc87cb79e3c846dbba4665b8\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dc87cb79e3c846dbba4665b8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dc87cb79e3c846dbba4665b8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dc87cb79e3c846dbba4665b8\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dead4f1dce2c43dc2548edad\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dead4f1dce2c43dc2548edad\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dead4f1dce2c43dc2548edad\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\dead4f1dce2c43dc2548edad\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e118e567d94d4cafb6d1789e\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e118e567d94d4cafb6d1789e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e118e567d94d4cafb6d1789e\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e18732d286294caeec178187\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e18732d286294caeec178187\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e18732d286294caeec178187\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e3751642da6b461a97ced0b0\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e3751642da6b461a97ced0b0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e3751642da6b461a97ced0b0\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e7eabe9331734c2f3a9edda2\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e7eabe9331734c2f3a9edda2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e7eabe9331734c2f3a9edda2\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e7eabe9331734c2f3a9edda2\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e9d387f30f0749c655b682a9\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e9d387f30f0749c655b682a9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\e9d387f30f0749c655b682a9\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\ed8cb42239634fa25a98f585\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\ed8cb42239634fa25a98f585\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\ed8cb42239634fa25a98f585\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f57c6581bc0748d9e83e92a9\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f57c6581bc0748d9e83e92a9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f57c6581bc0748d9e83e92a9\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f75d98270a2d4e757e90dfbb\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f75d98270a2d4e757e90dfbb\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f75d98270a2d4e757e90dfbb\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f75d98270a2d4e757e90dfbb\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f82a24697f144881b2d817bf\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f82a24697f144881b2d817bf\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f82a24697f144881b2d817bf\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f82a24697f144881b2d817bf\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f8d4520615b4486ae0f2a8b5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f8d4520615b4486ae0f2a8b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f8d4520615b4486ae0f2a8b5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\f8d4520615b4486ae0f2a8b5\King David
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\fbabd5f8a2f446486917aab7\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\fbabd5f8a2f446486917aab7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\fbabd5f8a2f446486917aab7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\fec14ee1e3a748ff3834ad8a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\fec14ee1e3a748ff3834ad8a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\2d0e4b7c630c4ce10e8692b5\fec14ee1e3a748ff3834ad8a\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\2b3a4aeaf58e414e9da15196\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\2b3a4aeaf58e414e9da15196\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\2b3a4aeaf58e414e9da15196\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\5d74d581d9c84833c8590abc\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\5d74d581d9c84833c8590abc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\5d74d581d9c84833c8590abc\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\9ab09ac9466f4bcbd19b8c98\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\9ab09ac9466f4bcbd19b8c98\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\9ab09ac9466f4bcbd19b8c98\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\cf33fe69b8a642a7582e0f90\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\cf33fe69b8a642a7582e0f90\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\4cbf2aac45e44ece78dfc999\cf33fe69b8a642a7582e0f90\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\36f6748afe8447023b8769bc\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\36f6748afe8447023b8769bc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\36f6748afe8447023b8769bc\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\b7fbb1e057e44acaf98bcea8\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\b7fbb1e057e44acaf98bcea8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\b7fbb1e057e44acaf98bcea8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\dd6cde00c3ba4ef57f9e6491\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\dd6cde00c3ba4ef57f9e6491\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\15888746615048c3d90677bf\aea80e6fa916492c492241b3\dd6cde00c3ba4ef57f9e6491\#name
C:\Program Files\winantispyware 2007\scanlog.xml
C:\Program Files\winantispyware 2007\settings.ini
C:\Program Files\winantispyware 2007\shellext.dll
C:\Program Files\winantispyware 2007\shellext.xml
C:\Program Files\winantispyware 2007\sr.log
C:\Program Files\winantispyware 2007\Summary.dat
C:\Program Files\winantispyware 2007\support.url
C:\Program Files\winantispyware 2007\tasks.dat
C:\Program Files\winantispyware 2007\threatnet.dat
C:\Program Files\winantispyware 2007\threatnet.ini
C:\Program Files\winantispyware 2007\unins000.dat
C:\Program Files\winantispyware 2007\unins000.exe
C:\Program Files\winantispyware 2007\uninstall.ico
C:\Program Files\winantispyware 2007\UnWizard.exe
C:\Program Files\winantispyware 2007\unwizard.xml
C:\Program Files\winantispyware 2007\up.dat
C:\Program Files\winantispyware 2007\updater.dat
C:\Program Files\winantispyware 2007\was7.exe
C:\Program Files\winantispyware 2007\WAS7.url
C:\Program Files\winantispyware 2007\WAS7.xml
C:\WINDOWS\poolsv.exe
C:\WINDOWS\svhost.exe
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\stera.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2007-06-06 to 2007-07-06 )))))))))))))))))))))))))))))))


2007-07-05 22:52 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-01 17:48 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2007-07-01 14:20 <DIR> d-------- C:\Program Files\Lavasoft
2007-07-01 14:09 18,432 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ApiMon.sys
2007-06-17 10:41 <DIR> d-------- C:\DOCUME~1\KINGDA~1\APPLIC~1\Hewlett-Packard
2007-06-17 10:18 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-06-17 10:16 19,558 --------- C:\WINDOWS\hpoins01.dat
2007-06-17 10:16 16,606 --------- C:\WINDOWS\hpomdl01.dat


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-06 04:21:03 -------- d-----w C:\DOCUME~1\KINGDA~1\APPLIC~1\Skype
2007-05-28 06:04:38 -------- d-----w C:\Program Files\Microsoft IntelliPoint
2007-05-25 20:28:13 -------- d-----w C:\Program Files\Soulseek
2007-05-24 23:21:55 -------- d-----w C:\Program Files\Jeskola Buzz
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
2003-08-06 02:04 106548 --a------ C:\WINDOWS\system32\dla\tfswshx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
2004-08-13 18:42 155648 --a------ C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A50B6E91-4081-4B37-BEA1-AD98A3CD51BA}]
C:\PROGRA~1\EMUSIC~2\tbu50\EMUSIC~1.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
2006-01-17 17:04 282624 --a------ C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-xu\msntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 04:59 C:\WINDOWS\BCMSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-13 19:23]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 09:35]
"DadApp"="C:\Program Files\Dell\AccessDirect\dadapp.exe" [2002-11-01 17:47]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2003-06-20 15:18]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-09-23 12:23]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-02-12 14:33]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 10:42]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 18:15]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 13:00]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-02-22 23:31]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{78a87d63-8045-11d8-9b4d-000d56ac3a0e}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e


Contents of the 'Scheduled Tasks' folder
2007-05-01 01:15:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-17 15:41:52 C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1182094854.job
2007-06-02 01:00:00 C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (DG3QM241-King David).job

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-05 23:20:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-05 23:23:04 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-05 23:22

--- E O F ---




Logfile of HijackThis v1.99.1
Scan saved at 12:07:54 AM, on 7/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\acs.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\M-Audio Fast Track\GBInst.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Belkin\Cardbus F5D7010\Wireless Utility\Belkinwcui.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\King David\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: XBTBPos00 - {A50B6E91-4081-4B37-BEA1-AD98A3CD51BA} - C:\PROGRA~1\EMUSIC~2\tbu50\EMUSIC~1.DLL (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-xu\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-xu\msntb.dll
O3 - Toolbar: eMusic Toolbar - {F8CC9B08-C14F-4A5C-B73B-518AFECC067A} - C:\Program Files\eMusic Toolbar\tbu50\emusicToolbar.dll (file missing)
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Registration-Studio 8.lnk = C:\Program Files\Pinnacle\Studio 8\Register\RegTool.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Belkin Wireless Utility.lnk = C:\Program Files\Belkin\Cardbus F5D7010\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\SYSTEM32\acs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Fast Track Installer (FastTrackInstallerService) - Nemesis - C:\Program Files\M-Audio Fast Track\GBInst.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:35 PM

Posted 06 July 2007 - 01:40 AM

Hi,

I see you were dealing with a flashdrive infection as well..

* Download next removal tool to your desktop:
http://www.techsupportforum.com/sectools/s...Disinfector.exe
If you have any flashdrives being used previously, since this is a flashdrive infection, insert your flashdrive as well, because above tool will disinfect it as well.
Then doubleclick the Flash_Disinfector.exe to run the tool.
Your desktop and icons will disappear afterwards. This is normal.
When the tool has finished, reboot your computer.

Then, go to start > run and copy and paste next commands in the field:

sc stop Apimon Hit enter

sc delete Apimon Hit enter

Then delete the following file and folder:

C:\WINDOWS\SYSTEM32\DRIVERS\ApiMon.sys
C:\Qoobox <== folder

Open notepad and copy and paste next present in the quotebox below in it:
(don't forget to copy and paste REGEDIT4)

REGEDIT4

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{78a87d63-8045-11d8-9b4d-000d56ac3a0e}]

Save this as fix.reg Choose to save as *all files and place it on your desktop.
It should look like this: Posted Image
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
(In case you are unsure how to create a reg file, take a look here with screenshots.)

* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
O2 - BHO: XBTBPos00 - {A50B6E91-4081-4B37-BEA1-AD98A3CD51BA} - C:\PROGRA~1\EMUSIC~2\tbu50\EMUSIC~1.DLL (file missing)
O3 - Toolbar: eMusic Toolbar - {F8CC9B08-C14F-4A5C-B73B-518AFECC067A} - C:\Program Files\eMusic Toolbar\tbu50\emusicToolbar.dll (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)


* Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Let me know in your next reply how things are now.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 sungura

sungura
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:35 PM

Posted 14 July 2007 - 11:40 PM

Thanks much,
everything seems to be back to normal.

#6 sungura

sungura
  • Topic Starter

  • Members
  • 18 posts
  • OFFLINE
  •  
  • Local time:12:35 PM

Posted 15 July 2007 - 12:32 AM

Should I run a registry cleaner (Ccleaner)?

#7 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:35 PM

Posted 15 July 2007 - 02:01 AM

hi,

Should I run a registry cleaner


Ccleaner is not really a Registry Cleaner although it has the Registry Cleaning option as well. So I don't recommend using the Registry Cleaning option in Ccleaner. Actually I do not recommend Registry Cleaners. This because some may rather damage than cleaning/fixing your registry.
Only use it if you have basic knowledge about the registry and know if a certain key/value is safe to be removed or not. Cleaning the registry won't really improve system performance anyway even though there are a lot of orphaned keys. If registry cleaning was really required, then Microsoft would have added this option already imho.
So use at your own risk. After all, a corrupted registry is a corrupted Windows.

Good to hear everything is running OK again.

Glad I could help. :thumbsup:

Please read my Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.

Happy Surfing again!
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:35 PM

Posted 18 July 2007 - 01:42 AM

Since this issue appears resolved ... this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users