Please God Help...
I have recently been infected by a virus. I've purchased Bitdefender, ran it several times, cleaned up what I could, read several threads here about my 530+ archives, etc. BD now shows no other infections, but I still have lots of popups and, what I assume are, fake security alerts, desk top icons, homepage hijacking, etc. I am running another full system scan now.
Please god help as this is sooooooooo very annoying.
My webpage is now ucleaner.com.
One security pop up says I am infected by worm.win32.netsky and asks if I want to remove it. I always say no.
I have a flashing orange octagon with a white X flashing in my tray. It does nothing.
I have a pop up just now for malwarecrush. BD moved a trojan to quarantine.
Here is my hijackthis! log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:27:39 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\GameSpot\DownloadManager_Win32.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\clclean.0001
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Electronic Arts\EA Link\Core.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\GameSpot\GDM_TrayApp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BitDefender\BitDefender 2008\uiscan.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = actsvr.comcastonline.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (file missing)
O3 - Toolbar: The ensfolr - {7D1AD5EB-9902-4FF0-986F-CA498179A53B} - C:\WINDOWS\ensfolr.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Link\Core.exe" -silent
O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - S-1-5-18 Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GDM_TrayApp.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GDM_TrayApp.exe (User 'Default user')
O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GDM_TrayApp.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZJxdm186YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab
O16 - DPF: {28E2EDF1-2383-4BA9-9A8C-980D1414B3B0} (ctrlNev1.ctrlNev) - http://www.neveron.com/ctrlNev1.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O21 - SSODL: ampkfst - {3B80113B-9FDB-4C20-AD44-EC046A096BB7} - C:\WINDOWS\ampkfst.dll
O21 - SSODL: bklgvsf - {B7862974-FE0B-4B03-BECB-6606094C89A6} - C:\WINDOWS\bklgvsf.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DNADownloader - CNET Networks - C:\Program Files\GameSpot\DownloadManager_Win32.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 12521 bytes
will post BD log as soon as it's done...
Comments
-
Hello Paulie771,
Fix these with HijackThis!R0 - HKCU\Software\Microsoft\Internet Explorer\Ma in,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961 -B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL ( file missing)
O3 - Toolbar: The ensfolr - {7D1AD5EB-9902-4FF0-9 86F-CA498179A53B} - C:\WINDOWS\ensfolr.dll
O8 - Extra context menu item: &Search - http://ed its.mywebsearch.com/toolbaredits/...?p=ZJxdm186YY US
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p 1.0.0.15-3.cab
O21 - SSODL: ampkfst - {3B80113B-9FDB-4C20-AD44-E C046A096BB7} - C:\WINDOWS\ampkfst.dll
O21 - SSODL: bklgvsf - {B7862974-FE0B-4B03-BECB-6 606094C89A6} - C:\WINDOWS\bklgvsf.dll
Cris.0 -
Hello Paulie771,
I am getting the EXACT same problem as you are Someone please provide assistance for us so we can get this issue resolved.0 -
Please post a HijackThis log.
Best regards!0 -
Hello Paulie771,
Please search the following files on your computer and send them to me in a PM (private message). Don't forget to put them in a password-protected archive, with the password= "infected" (without quotes):
C:\WINDOWS\ampkfst.dll
C:\WINDOWS\bklgvsf.dll
C:\WINDOWS\dxpvqlmqng.dll
C:\WINDOWS\ensfolr.dll
C:\WINDOWS\foxflpd.exe
C:\WINDOWS\ensfolr.dll
I will add the necessary detections.
Thank you.0 -
Lirima, PM sent requesting guidance.
Here is my latest BD log. I still have one trojan that is poping up as blocked but not deletable. Also my homepage is still hijacked.
I have run Superantispyware and Rogueremover, on top of removing the files suggested above with Hijackthis!
Log:
BitDefender Log File !!!!!
Product : BitDefender Internet Security 2008
Version : BitDefender UIScanner v.11
Log date : 11:41:43 10/01/2008
Log path : C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\deep_scan\1199986903_1_02.xml
Scan Paths:Path0000: C:\
Scan Options:Scan for viruses : Yes
Scan for adware : Yes
Scan for spyware : Yes
Scan for applications : Yes
Scan for dialers : Yes
Scan for rootkits : Yes
Target selection options:Scan registry keys : Yes
Scan cookies : Yes
Scan boot sectors : Yes
Scan memory processes : Yes
Scan archives : Yes
Scan runtime packers : Yes
Scan emails : Yes
Scan all files : Yes
Heuristic Scan : Yes
Scanned extensions :
Excluded extensions :
Target ProcessingDefault action for infected objects : Disinfect
Default action for suspicious objects : None
Default action for hidden objects : None
Scan engines summaryNumber of virus signatures : 967039
Archive plugins : 41
Email plugins : 6
Scan plugins : 12
Archive plugins : 41
System plugins : 4
Unpack plugins : 7
Overall scan summaryScanned items : 299024
Infected items : 3
Suspicious items : 0
Resolved items : 2
Individual viruses found : 3
Scanned directories : 9246
Scanned boot sectors : 3
Scanned archives : 3477
Input-output errors : 27
Scan time : 00:00:54:13
Files per second : 91
Scanned processes summaryScanned : 70
Infected : 0
Scanned registry keys summaryScanned : 376
Infected : 0
Scanned cookies summaryScanned : 0
Infected : 0
Remaining issues:Object Name Threat Name Final Status
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{0C76E95F-32D9-4401-9840-B03700DB5DBE} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{14804A52-1507-43C3-BDDD-161E0E440C6B} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{1AA6807E-EFA5-4F98-8ABA-BACF1B0F242B} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{1CDE53E4-D47B-4947-A288-F159F0DBF1ED} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{1DC3055A-AB4B-4C22-BFC3-874E836BBA2B} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{2D1A5CBC-2B89-4B76-B854-76F9DF18C8D7} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{2E3B2CF0-0390-449D-8713-41FCD05F8A53} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{2FB4A74E-D854-44E2-8C81-32FF6506825C} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{3BA04D58-855E-49CF-B6A0-7342B53B83B6} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{3C04084F-1474-46FE-AB39-8FF3B3F5228B} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{3D3C54BE-859C-4639-B1F7-081EDB582FCC} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{3E0A514F-8EDF-4224-B8BA-16E668C6A86D} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{3FEC001B-E505-43EF-8753-F3E289144649} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{4448B414-B0F7-4FEB-B905-AE19FDD7C1A2} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{5F471916-9031-4D55-8378-28D444E97CE7} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{5FB52FFC-2C73-475E-AB13-4D9F2E72424F} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{605899B9-C269-469C-81A1-84C1992A0652} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{6F93E906-2D91-4290-AD55-BAAA60EF840A} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{7B4C7D5D-0DAA-49E1-A434-422CC835FB4E} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{7BE3DCFD-A8E8-4D2A-8AE8-C4E453D69A3C} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{7D7948D1-87C0-4DB3-AF0B-74AA2102B4C3} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{8444C72E-5CBA-4AE3-9C7C-BD68A3086C0B} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{874872D2-555F-41CD-858C-6F78801C756C} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{928A219E-64A2-4A61-AEA0-258B82E9CCC8} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{97D91253-3073-4D71-9E90-8F9EDD2EB74A} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{A296A4A7-060C-4D3B-9548-971C22930BE0} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{A366E941-4F67-4AC6-A4E4-931CC0137A1D} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{AA76BC18-2287-4375-A3AD-3C16E389BC4F} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{AEE1C110-AF5A-4661-A802-2022C9AC03EF} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{BACFCCE8-95FE-49EE-BBBF-4C187B5FBE59} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{CAF937CD-2857-42B3-8AAC-63A05135784B} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{CB09EE45-C8D5-4F6C-97A2-2841107AB4D1} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{CBF39784-CD44-4433-A870-AB32BB78CC1E} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{CDB1843E-7185-494F-84F7-616FA870B72E} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{D7DD8A9F-9EAE-4F8F-878D-0E812FB5A891} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{D92AABD0-8DE8-416B-ABF2-A8A3FFB62825} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{DB5B0451-65F2-4E8A-8BF1-5B28F82D2E62} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{E83B6BB8-3136-4DB7-AB11-257081355022} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{EE3F6CA9-7614-4968-810B-B4CE0D91C2A3} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]{FE29EBBA-19CD-4CFE-BBB7-9C0552891E44} Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]backup.db Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]default.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]appconst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]comctl.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]config.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]lang_mps.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninstall.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninstall.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]appcons.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]appinst.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]appinst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]applang.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]default.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]header.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]InstUtil.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]instwiz.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]instxp.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]mcccom.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]setcss.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]shrins.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]comctl.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]shredcons.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]shredrem.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]UnInsStr.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]uninst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]uninstall.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]comctl.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]config.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]uninstall.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]appcons.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]appinst.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]appinst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]applang.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]config.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]default.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]header.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/bg_left_165x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]instwiz.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]instxp.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]mpsins.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]utils.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.cab=]agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]appinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]apputil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]install.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]lang_app.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]mskins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]images/bg_left_MSK_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.cab=]mskins.ui=]appcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]appinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]apputil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]install.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]lang_app.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]mskins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]images/bg_left_MSK_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu146.tmp\mskins.ui=]appcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.cab=]agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]appconst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]comctl.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]config.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]lang_mps.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninstall.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninstall.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]appcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]appinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]appinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]applang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0017=]shrins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]comctl.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]shredcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]shredrem.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]UnInsStr.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]uninst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]uninstall.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]comctl.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]config.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]uninstall.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]appcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]appinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]appinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]applang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]config.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]images/bg_left_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]mpsins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.cab=]mpsins.ui=]utils.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]appcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]appinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]appinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]applang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]config.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]images/bg_left_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]mpsins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18.tmp\mpsins.ui=]utils.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.cab=]agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]common_utils.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]countries.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]default.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]install.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]install.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]lang_common.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]strids_brandables.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]strids_common.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]strids_vsinstaller.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]vmap_reporting.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]VsoConst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]vsoins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.cab=]vsoins.ui=]VSOPropConst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]common_utils.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]countries.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]default.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]install.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]install.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]lang_common.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]strids_brandables.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]strids_common.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]strids_vsinstaller.js Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]vmap_reporting.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]VsoConst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]vsoins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu18A.tmp\vsoins.ui=]VSOPropConst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.cab=]agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]default.htm Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]appconst.vbs Password-Protected Items No action was possible
C:\WINDOWS\Temp\mcu3A.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]comctl.lpk Password-Protected Items No action was p0 -
Hello Paulie771,
I sent you a PM with the requested instructions. Please follow them and send me the archive.
The file detected as Trojan.Downloader.Zlob.ABGL could not be deleted because it is contained in an archive. In order to remove it, deactivate BitDefender and simply delete the entire archive, the file
C:\Documents and Settings\Mike\Local Settings\Temp\BIT1D4.tmp. Don't forget to re-activate BitDefender.
Have a nice day!C:\Documents and Settings\Mike\Local Settings\Temp\BIT1D4.tmp=](NSIS o)=]lzma_solid_nsis0002 Trojan.Downloader.Zlob.ABGL Delete Failed (file was in an archive)0 -
Hi Paulie771,
- I notice you need some cleaning/maintenance to get rid of a lot of (infected or otherwise unneeded) left overs.
You may try this (this is a very smal application, it does all cleaning you need):Please downloadby Atribune.Double-clickATF-Cleaner.exeto run the program.
UnderMainchoose:Select All
Click theEmpty Selectedbutton - Then you may run a new Bitdefender scan. If you want you may post the scan log with a fresh HJT log to see if you still have the infection and if necessary go on to the next step.
0 - I notice you need some cleaning/maintenance to get rid of a lot of (infected or otherwise unneeded) left overs.
-
I couldn't edit my post, so please after applying ATFcleaner empty your SuperAntispyware Quarantine also. Then you may run scanning by Bitdefender and HJT.
0 -
Hello Paulie771,
I signed the file you sent, but I think the dll's are hidding on your computer.
Please be sure that when you search for those files you see the hidden files, too.
Go to My Computer -> Tools ->Folder Options -> View -> click Show hidden files and folders.
Afterwards, search for those files from My Computer.
A new HijackThis log may be usefull.
Have a nice day!0 -
Ok, after cleaning up with the above posted program, here is the latest BD log and HJT! log...
BitDefender Log File !!!!!
Product : BitDefender Internet Security 2008
Version : BitDefender UIScanner v.11
Log date : 12:59:46 11/01/2008
Log path : C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\deep_scan\1200077986_1_02.xml
Scan Paths:Path0000: C:\
Scan Options:Scan for viruses : Yes
Scan for adware : Yes
Scan for spyware : Yes
Scan for applications : Yes
Scan for dialers : Yes
Scan for rootkits : Yes
Target selection options:Scan registry keys : Yes
Scan cookies : Yes
Scan boot sectors : Yes
Scan memory processes : Yes
Scan archives : Yes
Scan runtime packers : Yes
Scan emails : Yes
Scan all files : Yes
Heuristic Scan : Yes
Scanned extensions :
Excluded extensions :
Target ProcessingDefault action for infected objects : Disinfect
Default action for suspicious objects : None
Default action for hidden objects : None
Scan engines summaryNumber of virus signatures : 967084
Archive plugins : 41
Email plugins : 6
Scan plugins : 12
Archive plugins : 41
System plugins : 4
Unpack plugins : 7
Overall scan summaryScanned items : 292064
Infected items : 0
Suspicious items : 0
Resolved items : 0
Individual viruses found : 0
Scanned directories : 9078
Scanned boot sectors : 3
Scanned archives : 3269
Input-output errors : 27
Scan time : 00:00:45:21
Files per second : 107
Scanned processes summaryScanned : 70
Infected : 0
Scanned registry keys summaryScanned : 376
Infected : 0
Scanned cookies summaryScanned : 0
Infected : 0
Remaining issues:Object Name Threat Name Final Status
C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 01-06-2008 - 00-51-07.SBU=]backup.db Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agentins.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agntcons.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agntinst.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agntinst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]agntlang.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]default.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]header.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]InstUtil.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]instwiz.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]instxp.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\agentins.ui=]SubInfoData.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]appconst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]comctl.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]config.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]lang_mps.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninstall.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\mpscfg.cab=]mpsrem.ui=]uninstall.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]appcons.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]appinst.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]appinst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]applang.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]default.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]header.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]HtmlUtil.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/bg_left_1x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/bg_left_MSC_165x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]InstUtil.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]instwiz.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]instxp.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]mcccom.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]setcss.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0017=]shrins.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]comctl.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]shredcons.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]shredrem.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]UnInsStr.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]uninst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\en-us\us\shredder.exe=]wise0022=]shredrem.ui=]uninstall.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]comctl.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]config.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mps\mpsmain.cab=]RemoveMPS.exe=]wise0006=]uninstall.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]appcons.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]appinst.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]appinst.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]applang.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]config.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]default.htm Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]header.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/bg_left_165x314.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_info_16x16.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_mcafee_61x61.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_progress_checked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_progress_hot_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]images/icon_progress_unchecked_13x13.gif Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]instwiz.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]instxp.css Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]mcccom.lpk Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]mpsins.ini Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]pbar.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]setcss.vbs Password-Protected Items No action was possible
C:\Documents and Settings\Mike\Local Settings\Temp\MCA22.tmp\mpsins.ui=]utils.vbs Password-Protected Items No action was possible
Resolved issues:Object Name Threat Name Final Status
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:59:03 PM, on 1/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\GameSpot\DownloadManager_Win32.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\clclean.0001
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Electronic Arts\EA Link\Core.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\GameSpot\GDM_TrayApp.exe
C:\Program Files\BitDefender\BitDefender 2008\uiscan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = actsvr.comcastonline.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iSUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EA Link\Core.exe" -silent
O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GDM_TrayApp.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {28E2EDF1-2383-4BA9-9A8C-980D1414B3B0} (ctrlNev1.ctrlNev) - http://www.neveron.com/ctrlNev1.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: bklgvsf - {20D3059D-D740-4A8E-BE0B-296D37FE242D} - C:\WINDOWS\bklgvsf.dll (file missing)
O21 - SSODL: ampkfst - {92F74E4D-8E6C-4CAE-823D-5CE00A95A6AB} - C:\WINDOWS\ampkfst.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: DNADownloader - CNET Networks - C:\Program Files\GameSpot\DownloadManager_Win32.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 11721 bytes
I'm really glad you all understand this stuff. I thought I did, but now realize I am well outside understanding...0 -
Hello Paulie771,
It seems the the dll's I requested have been deleted from the computer, and now I cannot see any suspicious things in your logs. I hope that your computer is clean and you won't have anymore the troubles you mentioned in the first post on this topic.
Anyway, let us know if you still see something bad happening with your computer.0 -
Hello Paulie771,
It seems the the dll's I requested have been deleted from the computer, and now I cannot see any suspicious things in your logs. I hope that your computer is clean and you won't have anymore the troubles you mentioned in the first post on this topic.
Anyway, let us know if you still see something bad happening with your computer.
all seems to be running quite well. after all the advice you all have given me, plus a defrag, this ole laptop is running smoother than ever. I'm now going to install BD, HJT, SASW, and RR on my wife's and see what we can find there.
Thanks again for all your help. I suspect this will be the first anti-virus software I will continue to renew if the service is always this good.0 -
Hi paulie771,
Your HJT log is indeed clean as it is said. I advise you to do all the following:- To make sure the above mentioned files are gone for ever: Go to start-search-click all files and folders-type the name of one of the files without extension in the upper box - click more advanced options and check: search system folders, search hidden files and folders and search sub-folders- click on search. Repeat the procedure for all the files. If you find any of those files (make sure you have got exactly the same file) remove it from there in right panel. If you cannot delete these file(s)then:
Start HijackThis and click the Open the misc tools section now click Delete a file on reboot
Select the following file to be deleted on reboot:
C:\WINDOWS\ file name
[indent]
O21 - SSODL: bklgvsf - {20D3059D-D740-4A8E-BE0B-296D37FE242D} - C:\WINDOWS\bklgvsf.dll (file missing)O21 - SSODL: ampkfst - {92F74E4D-8E6C-4CAE-823D-5CE00A95A6AB} - C:\WINDOWS\ampkfst.dll (file missing)</B>you have a long list of startup items, some of them are not necessary to run at startup as they prolong the startup time and run processes which you use time to time. It is optional but better to set this application not to start with windows, or simply remove the startup item by fixing it with HJT.
[/indent]- Empty your user temp folder by going to start-control panel- folder options- click view tab: check show hidden files and folders. Then reboot, right after reboot open the explorer (not Internet explorer) by right clicking on start and selecting explorer from the context menu. In the left panel go to C:\Documents and Settings\Mike\Local Settings\Temp (select temp) select one of the files/folders in the right panel, click Ctrl+A to select all of the then delete - confirm deleting. Make sure you empty the folder.
- Go to start-control panel- Internet options- General- click delete- delete all- check 'Also delete files and settings stored by add-ons'. Click YES and then OK, when this is done click privacy tab the privacy setting should be Medium.
- Reboot and check if your computer is running fine. Then empty your restore volume to get rid of recreation of infection by windows recovery. To do that: go to start-control panel- system- system restore- check turn off system restore on all drives. Click apply. By doing this you loose all your (often infected) restore points. Reboot and uncheck "turn off system restore on all drives' to create a clean restore point.
0 - To make sure the above mentioned files are gone for ever: Go to start-search-click all files and folders-type the name of one of the files without extension in the upper box - click more advanced options and check: search system folders, search hidden files and folders and search sub-folders- click on search. Repeat the procedure for all the files. If you find any of those files (make sure you have got exactly the same file) remove it from there in right panel. If you cannot delete these file(s)then: