| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
13-Sep-2008, 10:48 PM
#1 |
| for a few months now my control panel has been missing ive tried everything and i have just recently found this sit and have seen that it is helpful. also when i try to do certain things like add/remove programs in my computer it sais this operation has been cancelled due to restrictions in effect on this computer. please contact your system administrator. i have already tryd doing regedit and changing nocontrolpanel to 0 from 1 and i have no idea what else to do. thank you for reading about my problems and thanks in advance for helping me solve them. |
| |
|
13-Sep-2008, 11:26 PM
#3 |
| |
|
14-Sep-2008, 11:35 AM
#4 |
| so i read that forum and here is my log -------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:32:51 AM, on 9/14/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Yahoo!\Antivirus\ISafe.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Yahoo!\Antivirus\VetMsg.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe C:\Program Files\Microsoft Windows OneCare Live\winss.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe C:\Program Files\Yahoo!\Antivirus\CAVTray.exe C:\Program Files\Yahoo!\Antivirus\CAVRID.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\PixArt\PAC207\Monitor.exe C:\Program Files\Seekmo\bin\10.0.424.0\OEAddOn.exe C:\Program Files\QuickTime\QTTask.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Electronic Arts\EADM\Core.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\OpenOffice.org 2.4\program\soffice.exe C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe C:\WINDOWS\System32\dllhost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll R3 - URLSearchHook: (no name) - {0E39B8F0-7E31-2ABB-4D1E-58C7EE70B39E} - C:\WINDOWS\system32\rnorld.dll R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: (no name) - rsion - (no file) O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll O2 - BHO: Seekmo /fleok=1D8A83A5C2ED127E9DAB6C2A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - C:\Program Files\Seekmo\bin\10.0.424.0\HostIE.dll O2 - BHO: (no name) - {0E39B8F0-7E31-2ABB-4D1E-58C7EE70B39E} - C:\WINDOWS\system32\rnorld.dll O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll O2 - BHO: (no name) - {47B83D78-F986-4E96-9769-2C55EF14DA0B} - C:\WINDOWS\system32\__c00E3A88.dat (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: (no name) - {D27987B8-7244-4DE0-AE10-39B826B492F1} - C:\WINDOWS\system32\bronto.dll O2 - BHO: (no name) - {DABCE839-3831-3818-AF3A-3837BCD324D2} - C:\WINDOWS\system32\mskvtns.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Seekmo - {07AA283A-43D7-4CBE-A064-32A21112D94D} - C:\Program Files\Seekmo\bin\10.0.424.0\HostIE.dll O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe O4 - HKLM\..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.424.0\OEAddOn.exe O4 - HKLM\..\Run: [SeekmoSA] "C:\Program Files\Seekmo\bin\10.0.424.0\SeekmoSA.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [Tlom] "C:\WINDOWS\system32\FNTS~1\nopdb.exe" -vt yazb O4 - HKCU\..\Run: [Qinj] C:\Program Files\W?nSxS\?xplorer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing) O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.topsoftwarefeed.com/redirect.php (file missing) O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sd...SL/tgctlcm.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/noc...up1.0.0.15.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {5DBF08EF-4BDE-11D3-B8E4-0080C84E9C66} (Medi@Show Control) - file:///C:/Fraps/MediaShow.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://disteng.nefficient.com/disten...fyLauncher.cab O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/.../Installer.exe O20 - AppInit_DLLs: C:\WINDOWS\system32\sol323.txt O22 - SharedTaskScheduler: heterotroph - {de5ede53-9db0-422d-b32d-5c41c96d6f52} - C:\WINDOWS\system32\iklqcx.dll (file missing) O22 - SharedTaskScheduler: bemocked - {b0883848-1466-4470-a418-3fe7d36694b9} - C:\WINDOWS\system32\rldyt.dll (file missing) O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: getPlus(R) Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE -- End of file - 13119 bytes |
|
14-Sep-2008, 11:37 AM
#5 |
| thanks for moving it Last edited by problemnanswer; 14-Sep-2008 at 12:01 PM.. |
14-Sep-2008, 12:52 PM
#6 | |||||
| Please download SmitfraudFix (by S!Ri) to your Desktop. Double-click SmitfraudFix.exe Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. **If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. http://www.beyondlogic.org/consulting/proc...processutil.htm Warning: Do not run Option #2 until you are instructed to do so. Running option #2 on a non infected computer will remove your Desktop background.
__________________ Microsoft MVP - Consumer Security |
|
14-Sep-2008, 04:37 PM
#7 |
| ok did all that here is what came up SmitFraudFix v2.350 Scan done at 15:30:14.01, Sun 09/14/2008 Run from C:\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Yahoo!\Antivirus\ISafe.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Yahoo!\Antivirus\VetMsg.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe C:\Program Files\Microsoft Windows OneCare Live\winss.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE C:\Program Files\Yahoo!\Antivirus\CAVTray.exe C:\Program Files\Yahoo!\Antivirus\CAVRID.exe C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\PixArt\PAC207\Monitor.exe C:\Program Files\Seekmo\bin\10.0.424.0\OEAddOn.exe C:\Program Files\QuickTime\QTTask.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\OpenOffice.org 2.4\program\soffice.exe C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe C:\WINDOWS\System32\dllhost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\bronto.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ROBERT »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ROBERT\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ROBERT\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\VirusProtectPro 3.7\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, following keys are not inevitably infected!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» VACFix !!!Attention, following keys are not inevitably infected!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix !!!Attention, following keys are not inevitably infected!!! 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix !!!Attention, following keys are not inevitably infected!!! AntiXPVSTFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Share dTaskScheduler] "{de5ede53-9db0-422d-b32d-5c41c96d6f52}"="heterotroph" [HKEY_CLASSES_ROOT\CLSID\{de5ede53-9db0-422d-b32d-5c41c96d6f52}\InProcServer32] @="C:\WINDOWS\system32\iklqcx.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{de5ede53-9db0-422d-b32d-5c41c96d6f52}\InProcServer32] @="C:\WINDOWS\system32\iklqcx.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Share dTaskScheduler] "{b0883848-1466-4470-a418-3fe7d36694b9}"="bemocked" [HKEY_CLASSES_ROOT\CLSID\{b0883848-1466-4470-a418-3fe7d36694b9}\InProcServer32] @="C:\WINDOWS\system32\rldyt.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b0883848-1466-4470-a418-3fe7d36694b9}\InProcServer32] @="C:\WINDOWS\system32\rldyt.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\WINDOWS\\system32\\sol323.txt" "LoadAppInit_DLLs"=dword:00000001 »»»»»»»»»»»»»»»»»»»»»»»» Winlogon !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," "System"="" »»»»»»»»»»»»»»»»»»»»»»»» RK »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: VIA Compatable Fast Ethernet Adapter - Packet Scheduler Miniport DNS Server Search Order: 192.168.1.1 DNS Server Search Order: 192.168.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\..\{F3C7D3AC-C6C0-41BF-96B9-D495FB74CFCF}: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{F3C7D3AC-C6C0-41BF-96B9-D495FB74CFCF}: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{F3C7D3AC-C6C0-41BF-96B9-D495FB74CFCF}: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End thank you for the help and advance thank you for more help |
14-Sep-2008, 04:45 PM
#8 | |||||
| You should print out these instructions or copy them to a Notepad file for reading while in Safe Mode because you will not be able to connect to the Internet to read from this site. Next, please reboot your computer in Safe Mode by doing the following:
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files. You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection. The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter". The tool may need to restart your computer to finish the cleaning process. If it doesn't, please restart it into Normal Windows. A text file will appear onscreen, with results from the cleaning process. Please copy/paste the content of that report into your next reply along with a new HijackThis log. The report can also be found at the root of the system drive, usually at C:\rapport.txt
__________________ Microsoft MVP - Consumer Security |
|
14-Sep-2008, 05:43 PM
#9 |
| thank you cookiegal for your help this is the raport ------------------------------------------- SmitFraudFix v2.350 Scan done at 15:56:30.59, Sun 09/14/2008 Run from C:\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Share dTaskScheduler] "{de5ede53-9db0-422d-b32d-5c41c96d6f52}"="heterotroph" [HKEY_CLASSES_ROOT\CLSID\{de5ede53-9db0-422d-b32d-5c41c96d6f52}\InProcServer32] @="C:\WINDOWS\system32\iklqcx.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{de5ede53-9db0-422d-b32d-5c41c96d6f52}\InProcServer32] @="C:\WINDOWS\system32\iklqcx.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Share dTaskScheduler] "{b0883848-1466-4470-a418-3fe7d36694b9}"="bemocked" [HKEY_CLASSES_ROOT\CLSID\{b0883848-1466-4470-a418-3fe7d36694b9}\InProcServer32] @="C:\WINDOWS\system32\rldyt.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b0883848-1466-4470-a418-3fe7d36694b9}\InProcServer32] @="C:\WINDOWS\system32\rldyt.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» VACFix VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix S!Ri's WS2Fix: LSP not Found. »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\bronto.dll Deleted C:\Program Files\VirusProtectPro 3.7\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» IEDFix IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix AntiXPVSTFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» RK »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{F3C7D3AC-C6C0-41BF-96B9-D495FB74CFCF}: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{F3C7D3AC-C6C0-41BF-96B9-D495FB74CFCF}: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{F3C7D3AC-C6C0-41BF-96B9-D495FB74CFCF}: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End --------------------------------------------------------- and this is the hijackthis --------------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:30:30, on 9/14/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Yahoo!\Antivirus\ISafe.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Yahoo!\Antivirus\VetMsg.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe C:\Program Files\Microsoft Windows OneCare Live\winss.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe C:\Program Files\Yahoo!\Antivirus\CAVTray.exe C:\Program Files\Yahoo!\Antivirus\CAVRID.exe C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe C:\WINDOWS\PixArt\PAC207\Monitor.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\OpenOffice.org 2.4\program\soffice.exe C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\Defrag.exe C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe C:\WINDOWS\system32\NOTEPAD.EXE R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll R3 - URLSearchHook: (no name) - {0E39B8F0-7E31-2ABB-4D1E-58C7EE70B39E} - C:\WINDOWS\system32\rnorld.dll R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: (no name) - rsion - (no file) O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll O2 - BHO: Seekmo /fleok=1D8A83A5C2ED127E9DAB6C2A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - C:\Program Files\Seekmo\bin\10.0.424.0\HostIE.dll O2 - BHO: (no name) - {0E39B8F0-7E31-2ABB-4D1E-58C7EE70B39E} - C:\WINDOWS\system32\rnorld.dll O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll O2 - BHO: (no name) - {47B83D78-F986-4E96-9769-2C55EF14DA0B} - C:\WINDOWS\system32\__c00E3A88.dat (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: (no name) - {DABCE839-3831-3818-AF3A-3837BCD324D2} - C:\WINDOWS\system32\mskvtns.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Seekmo - {07AA283A-43D7-4CBE-A064-32A21112D94D} - C:\Program Files\Seekmo\bin\10.0.424.0\HostIE.dll O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe O4 - HKLM\..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.424.0\OEAddOn.exe O4 - HKLM\..\Run: [SeekmoSA] "C:\Program Files\Seekmo\bin\10.0.424.0\SeekmoSA.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [Tlom] "C:\WINDOWS\system32\FNTS~1\nopdb.exe" -vt yazb O4 - HKCU\..\Run: [Qinj] C:\Program Files\W?nSxS\?xplorer.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sd...SL/tgctlcm.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/...x/qtplugin.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/noc...up1.0.0.15.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {5DBF08EF-4BDE-11D3-B8E4-0080C84E9C66} (Medi@Show Control) - file:///C:/Fraps/MediaShow.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://disteng.nefficient.com/disten...fyLauncher.cab O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/.../Installer.exe O20 - AppInit_DLLs: C:\WINDOWS\system32\sol323.txt O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: getPlus(R) Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE -- End of file - 12039 bytes ------------------------------------------------------------- thank you for the help and by the way dont know if this was suppost to happen but it took away my background |
|
14-Sep-2008, 05:46 PM
#10 |
| and i cant get it back lol because i cant go into properties stupid operation has been restricted message pops up |
14-Sep-2008, 08:13 PM
#11 | |||||
| Please visit Combofix Guide & Instructions for instructions for installing the recovery console and downloading and running ComboFix. The only thing different from the instructions there is that when downloading and saving the ComboFix.exe I would like you to rename it to ComboFox.exe please. Post the log from ComboFix when you've accomplished that along with a new HijackThis log. Important notes regarding ComboFix: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser. This can easily be changed once we're finished. ComboFix also prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you, please let me know. This can be undone manually when we're finished.
__________________ Microsoft MVP - Consumer Security |
|
14-Sep-2008, 08:49 PM
#12 |
| thanks for the help cookie i am going to finish this tommaro thank you |
|
16-Sep-2008, 01:37 AM
#14 |
| ok so i finished everything and everything looks to be in order my control panel is back i dont have that stupid message poppin up everywhere but if you would could check my logs that would be awsome ![]() this is the combofix (fyi i couldnt rename it to combofox and it did alot more steps than the instuctions lol) ------------------------------------------------------------- ComboFix 08-09-15.02 - ROBERT 2008-09-15 23:24:08.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.32 [GMT -4:00]Running from: C:\Documents and Settings\ROBERT\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\ROBERT\Desktop\WinXP_EN_HOM_BF.EXE * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 C:\Documents and Settings\All Users\Application Data\SeekmoSA C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSA.dat C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSA_kyf.dat C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAAbout.mht C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAau.dat C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAEULA.mht C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Reset Cursor.lnk C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Seekmo Customer Support Center.lnk C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Seekmo Uninstall Instructions.lnk C:\Documents and Settings\Every1\Application Data\Seekmo C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\819382.sdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\domains.txt C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\25471 C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\427148 C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\455563 C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\455743 C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\747635 C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93110 C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\3737.dat C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans.idx C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans1.dat C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\buttondir.txt C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\components.cdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\cursors.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_1000.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_2000.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_3000.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bar.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bbar1.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_logos.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_other.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_weather.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\default.cdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_511745-514279.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_categorize.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_comparison.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-Mails.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-people.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_favorites.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Games.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hide.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hotbarcom.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hotmail.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hsskin.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Mails.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_new.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_premium.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchfor.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchgo.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_weather.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_yellowpages.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-548964.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-9595.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\email-t1-bg.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\icons2.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_games_icon.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_video.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords.idx C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords1.dat C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\layout.cdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\linkpathlegal.txt C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\progress.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\s_icons_buttons.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\sales_buttons.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo_ie_menu.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\t2_bg.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\theweb.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\top7.cdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\Top7_theweb.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\1\tsd_bg.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans.idx C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans1.dat C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\buttondir.txt C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\components.cdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\cursors.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_1000.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_2000.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_3000.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_bar.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_bbar1.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_logos.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_other.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_weather.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\default.cdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_511745-514279.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_categorize.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_comparison.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-Mails.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-people.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_favorites.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Games.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hide.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hotbarcom.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hotmail.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hsskin.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Mails.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_new.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_premium.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchfor.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchgo.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_weather.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_yellowpages.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-548964.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-9595.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\email-t1-bg.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\icons2.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_games_icon.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_video.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords.idx C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords1.dat C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\layout.cdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\linkpathlegal.txt C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\progress.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\s_icons_buttons.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\sales_buttons.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo_ie_menu.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\t2_bg.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\theweb.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\top7.cdf C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\Top7_theweb.mnu C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\2\tsd_bg.res C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans1.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\cursors.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_1000.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_2000.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_3000.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bar.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bbar1.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_logos.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_other.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_weather.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\default.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\email-t1-bg.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\icons2.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_games_icon.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_video.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords1.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\layout.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\linkpathlegal.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\progress.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\s_icons_buttons.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\sales_buttons.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.txt C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo_ie_menu.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\t2_bg.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\top7.xip C:\Documents and Settings\Every1\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\tsd_bg.xip C:\Documents and Settings\Every1\Cookies\every1@2o7[1].txt C:\Documents and Settings\Every1\Cookies\every1@ad.yieldmanager[2].txt C:\Documents and Settings\Every1\Cookies\every1@advertising[1].txt C:\Documents and Settings\Every1\Cookies\every1@edge.ru4[2].txt C:\Documents and Settings\Every1\Cookies\every1@ehg-idgentertainment.hitbox[2].txt C:\Documents and Settings\Every1\Cookies\every1@insightexpressai[2].txt C:\Documents and Settings\Every1\Cookies\every1@revsci[1].txt C:\Documents and Settings\Every1\Cookies\every1@trafficmp[2].txt C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[1].txt C:\Documents and Settings\Guest\Cookies\guest@advertising[2].txt C:\Documents and Settings\Michael\Cookies\michael@insightexpressai[1].txt C:\Documents and Settings\ROBERT\Application Data\Seekmo C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\1.sdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\3240891.sdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\3893642.sdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\648665.sdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\domains.txt C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\114249 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\14271 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\15162 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\168167 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\17040 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\19052 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\202699 |
|
16-Sep-2008, 01:38 AM
#15 |
| (continued) C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\20517 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\21669 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\218712 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\22254 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\233027 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\253785 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\28812 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\297534 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\300441 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\30604 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\32290 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\36079 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\36735 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\367353 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\39897 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\40256 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\43719 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\45058 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\45837 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\512635 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\516057 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\520179 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\53481 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\54765 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\547723 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\59234 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\61779 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\625325 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\6292 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\65770 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\65809 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\66456 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\67220 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\67466 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\68094 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\68257 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\69263 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\72873 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\744617 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\744881 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\745137 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\745175 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\74777 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\747936 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\748176 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\753335 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\753377 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\79721 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\80670 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\81022 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\81566 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\81830 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\82120 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\8443 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\85083 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93899 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\93934 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\94125 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\95200 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\97734 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\9966 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML\998 C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\372b.dat C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans.idx C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans1.dat C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\buttondir.txt C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\components.cdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\cursors.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_1000.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_2000.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_3000.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bar.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_bbar1.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_logos.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_other.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_weather.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\default.cdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_511745-514279.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_categorize.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_comparison.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-Mails.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-people.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_favorites.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Games.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hide.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hotbarcom.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hotmail.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hsskin.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Mails.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_new.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_premium.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchfor.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchgo.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_weather.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_yellowpages.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-548964.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-9595.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\email-t1-bg.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\icons2.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_games_icon.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_video.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords.idx C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords1.dat C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\layout.cdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\linkpathlegal.txt C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\progress.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\s_icons_buttons.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\sales_buttons.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo_ie_menu.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\t2_bg.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\theweb.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\top7.cdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\Top7_theweb.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\1\tsd_bg.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans.idx C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans1.dat C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\buttondir.txt C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\components.cdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\cursors.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_1000.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_2000.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_3000.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_bar.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_bbar1.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_logos.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_other.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_weather.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\default.cdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_511745-514279.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_categorize.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_comparison.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-Mails.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-people.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_favorites.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Games.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hide.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hotbarcom.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hotmail.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hsskin.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Mails.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_new.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_premium.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchfor.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchgo.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_weather.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_yellowpages.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-548964.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-9595.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\email-t1-bg.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\icons2.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_games_icon.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_video.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords.idx C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords1.dat C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\layout.cdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\linkpathlegal.txt C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\progress.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\s_icons_buttons.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\sales_buttons.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo_ie_menu.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\t2_bg.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\theweb.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\top7.cdf C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\Top7_theweb.mnu C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\2\tsd_bg.res C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans1.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\buttondir.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\cursors.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_1000.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_2000.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_3000.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bar.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bbar1.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_logos.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_other.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_weather.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\default.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\email-t1-bg.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\icons2.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_games_icon.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_video.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords1.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\layout.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\linkpathlegal.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\progress.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\s_icons_buttons.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\sales_buttons.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.txt C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo_ie_menu.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\t2_bg.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\top7.xip C:\Documents and Settings\ROBERT\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\tsd_bg.xip C:\Documents and Settings\ROBERT\Cookies\robert@2o7[2].txt C:\Documents and Settings\ROBERT\Cookies\robert@a.hasbro[2].txt C:\Documents and Settings\ROBERT\Cookies\robert@advertising[2].txt C:\Documents and Settings\ROBERT\Cookies\robert@cts.metricsdirect[2].txt C:\Documents and Settings\ROBERT\Cookies\robert@insightexpressai[2].txt C:\Documents and Settings\ROBERT\Cookies\robert@spamblockerutility[2].txt C:\Documents and Settings\ROBERT\Cookies\robert@track.bestbuy[1].txt C:\Documents and Settings\ROBERT\Cookies\robert@wat.contextweb[2].txt C:\Documents and Settings\ROBERT\Cookies\robert@www-t.cars[1].txt C:\Program Files\Common Files\curity~1 C:\Program Files\Common Files\pppatc~1 C:\Program Files\Common Files\Yazzle1409OinUninstaller.exe C:\Program Files\seekmo C:\Program Files\seekmo\bin\10.0.424.0\arrow.ico C:\Program Files\seekmo\bin\10.0.424.0\copyright.txt C:\Program Files\seekmo\bin\10.0.424.0\firefox\extensions\chrome.manifest C:\Program Files\seekmo\bin\10.0.424.0\firefox\extensions\components\npclntax.xpt C:\Program Files\seekmo\bin\10.0.424.0\firefox\extensions\install.rdf C:\Program Files\seekmo\bin\10.0.424.0\firefox\extensions\plugins\npclntax_SeekmoSA.dl l C:\Program Files\seekmo\bin\10.0.424.0\HostOE.dll C:\Program Files\seekmo\bin\10.0.424.0\link.ico C:\Program Files\seekmo\bin\10.0.424.0\SeekmoSAAX.dll C:\Program Files\seekmo\bin\10.0.424.0\SeekmoSADF.exe C:\Program Files\seekmo\bin\10.0.424.0\SeekmoSAHook.dll C:\Program Files\ShoppingReport C:\Program Files\winupdates C:\Program Files\wnsxs~1 C:\WINDOWS\sks~1 C:\WINDOWS\system32\bszip.dll C:\WINDOWS\system32\cmd.com C:\WINDOWS\system32\fnts~1 C:\WINDOWS\system32\fnts~1\F?nts\ C:\WINDOWS\system32\msdtexch.dll C:\WINDOWS\system32\msftedswc.dll C:\WINDOWS\system32\netstat.com C:\WINDOWS\system32\ping.com C:\WINDOWS\system32\taskkill.com C:\WINDOWS\system32\tasklist.com C:\WINDOWS\system32\tracert.com |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 05:20 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

