1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Winfixer Virus! Please help!

Discussion in 'Virus & Other Malware Removal' started by Sabrina Glyndale, Aug 7, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. Sabrina Glyndale

    Sabrina Glyndale Thread Starter

    Joined:
    Apr 29, 2006
    Messages:
    40
    Dear Tech Support Guy,

    Hello. I am repeatedly getting a message from Norton as follows:

    Virus Alert High Risk
    Norton has detected a virus on your computer
    Virus name: WinFixer
    Action taken: "The file was detected"
    C:\Program Files\Co...\WapCHK.dll

    First, I don't know why Norton doesn't just fix the damn thing or quarantine it. How does it help me at all to keep telling me merely that the virus has been "detected?"

    Second, when I run a full-system anti-virus and anti-spyware scan (latest Norton 2006 edition), nothing comes up at all: "there are no viruses on your computer."

    And yet, periodically, as I am working on MS Word files, this red-colored "high alert" window from Norton keeps popping up. What is going on??

    A couple of months ago I purchased the WinAnti-Virus program. Then I learned through this website that it is a very dubious program that actually installs spyware on one's computer. So on you advice, I uninstalled it and never got my money back. That was more than $50 down the drain. (I am unemployed, desperately trying to finish my book).

    So I then bought this 2-year subscription for Norton Anti-Virus 2006: more than $60. I tried to find an e-mail address on the Norton site for an answer to this problem. Well, they give nothing but physical mailing addresses or telephone numbers or a "chat" option that the customer has to pay for. (I am in the Urals, Russia, so it's too expensive to call, and I only have a cell phone that doesn't do long-distance anyway). Funny how these anti-virus companies love to take your money, but offer no free help for their cruddy products.

    Basically, I need to know: do I have the Winfixer virus or not? Please tell me what I should do to find out why this Norton virus alert keeps popping up and how to get rid of WinFixer if I AM infected.

    By the way, I also notice that my Toshiba laptop (bought just last year) has been running extremely slowly since this problem started. It takes forever just to open up a MS Word file or a folder.

    Please help me. Thank you very much, in advance, for your help!

    Sabrina
     
  2. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,299
    Please do this:

    Click here to download HJTsetup.exe
    • Save HJTsetup.exe to your desktop.
    • Double click on the HJTsetup.exe icon on your desktop.
    • By default it will install to C:\Program Files\Hijack This.
    • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
    • Put a check by Create a desktop icon then click Next again.
    • Continue to follow the rest of the prompts from there.
    • At the final dialogue box click Finish and it will launch Hijack This.
    • Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
    • Click Save to save the log file and then the log will open in notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    • Come back here to this thread and Paste the log in your next reply.
    • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
     
  3. Sabrina Glyndale

    Sabrina Glyndale Thread Starter

    Joined:
    Apr 29, 2006
    Messages:
    40
    Hi, Cookiegal:

    Thanks for your reply. Okay, here is my HiJack This Log. See below. Just so you know: my computer is running e-x-t-r-e-m-e-l-y slowly. It takes forever to call up a Microsoft Word document. I am constantly seeing the hourglass sign. Then the system hangs periodically while I am editing the document. Could this be the Winfixer virus slowing everything down? Norton keeps telling me I have a "high threat" Winfixer virus on my computer, but doesn't do anything to eliminate the virus!!!

    Please study this log and advise me what to do next (in very clear, simple language for a computer illiterate like me, please). Thanks again for all your help!

    HJT Log:

    Logfile of HijackThis v1.99.1
    Scan saved at 5:38:21 PM, on 8/8/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    C:\Documents and Settings\Sabrina\My Documents\My Data Sources\Anti-Virus\Evido\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\EzButton\EzButton.EXE
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    C:\WINDOWS\System32\ZoomingHook.exe
    C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    C:\WINDOWS\system32\svchost.exe
    c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\toshiba\ivp\ism\ivpsvmgr.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Common Files\Companion Wizard\compwiz.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Documents and Settings\Sabrina\My Documents\My Data Sources\Anti-Virus\Evido\ewido anti-spyware 4.0\ewido.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Messenger\msmsgs.exe
    C:\DOCUME~1\JOHANN~1\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.doteasy.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    O4 - HKLM\..\Run: [ZoomingHook] c:\WINDOWS\System32\ZoomingHook.exe
    O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
    O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
    O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKLM\..\Run: [IVPServiceMgr] C:\toshiba\ivp\ism\ivpsvmgr.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [CompanionWizard] "C:\Program Files\Common Files\Companion Wizard\compwiz.exe" /silent
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [!ewido] "C:\Documents and Settings\Sabrina\My Documents\My Data Sources\Anti-Virus\Evido\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TeleAuth] C:\Documents and Settings\Sabrina\Desktop\teleauth.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{F558CA23-D3A9-4ED9-91EF-B5067602FD9F}: NameServer = 87.224.197.1,87.224.213.1
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Sabrina\My Documents\My Data Sources\Anti-Virus\Evido\ewido anti-spyware 4.0\guard.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
     
  4. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,299
    Download WinPFind
    • Right Click the Zip Folder and Select "Extract All"
    • Extract it somewhere you will remember like the Desktop
    • Don’t do anything with it yet!


    Click here for info on how to boot to safe mode if you don't already know how.


    Reboot into Safe Mode.


    Double click WinPFind.exe
    • Click "Start Scan"
    • It will scan the entire System, so please be patient and let it complete.


    Reboot back to Normal Mode!


    • Go to the WinPFind folder
    • Locate WinPFind.txt
    • Copy and paste WinPFind.txt in your next post here please.
     
  5. Sabrina Glyndale

    Sabrina Glyndale Thread Starter

    Joined:
    Apr 29, 2006
    Messages:
    40
    Thanks for your clear instructions, CookieGal. Below is the new log:

    WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

    If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

    »»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
    Internet Explorer Version: 6.0.2900.2180

    »»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

    Checking %SystemDrive% folder...

    Checking %ProgramFilesDir% folder...

    Checking %WinDir% folder...

    Checking %System% folder...
    PEC2 8/4/2004 6:00:00 PM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
    PTech 6/19/2006 4:19:42 PM 571184 C:\WINDOWS\SYSTEM32\LegitCheckControl.dll
    aspack 7/7/2006 7:21:46 AM 6757792 C:\WINDOWS\SYSTEM32\MRT.exe
    aspack 8/4/2004 6:00:00 PM 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
    Umonitor 8/4/2004 6:00:00 PM 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
    winsync 8/4/2004 6:00:00 PM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
    PTech 6/19/2006 4:19:26 PM 304944 C:\WINDOWS\SYSTEM32\WgaTray.exe

    Checking %System%\Drivers folder and sub-folders...

    Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts


    Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
    8/8/2006 9:15:22 PM S 2048 C:\WINDOWS\bootstat.dat
    6/19/2006 4:20:58 PM S 7160 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WgaNotify.cat
    8/8/2006 9:15:12 PM H 8192 C:\WINDOWS\system32\config\default.LOG
    8/8/2006 9:15:40 PM H 1024 C:\WINDOWS\system32\config\SAM.LOG
    8/8/2006 9:15:24 PM H 16384 C:\WINDOWS\system32\config\SECURITY.LOG
    8/8/2006 9:15:42 PM H 65536 C:\WINDOWS\system32\config\software.LOG
    8/8/2006 9:15:32 PM H 1077248 C:\WINDOWS\system32\config\system.LOG
    7/13/2006 3:01:12 PM H 1024 C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
    7/28/2006 9:18:42 PM HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\1b57fd01-98ef-4dc6-9353-df2f827756fa
    7/28/2006 9:18:42 PM HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred
    8/8/2006 9:14:28 PM H 6 C:\WINDOWS\Tasks\SA.DAT

    Checking for CPL files...
    Microsoft Corporation 8/4/2004 6:00:00 PM 68608 C:\WINDOWS\SYSTEM32\access.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
    COMPAL ELECTRONIC INC. 8/20/2004 7:46:34 AM 917504 C:\WINDOWS\SYSTEM32\CoPM.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 135168 C:\WINDOWS\SYSTEM32\desk.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
    Intel Corporation 11/18/2003 2:19:24 PM 98304 C:\WINDOWS\SYSTEM32\igfxcpl.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 129536 C:\WINDOWS\SYSTEM32\intl.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 68608 C:\WINDOWS\SYSTEM32\joy.cpl
    Sun Microsystems 8/20/2004 4:59:30 AM 61555 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 187904 C:\WINDOWS\SYSTEM32\main.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
    RealNetworks, Inc. 8/20/2004 6:43:34 AM 24576 C:\WINDOWS\SYSTEM32\prefscpl.cpl
    Apple Computer, Inc. 7/27/2003 11:05:54 PM 295936 C:\WINDOWS\SYSTEM32\QuickTime.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
    9/6/2003 2:36:40 AM 495616 C:\WINDOWS\SYSTEM32\TOSCDSPD.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
    Microsoft Corporation 5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 68608 C:\WINDOWS\SYSTEM32\dllcache\access.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 155136 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 358400 C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 129536 C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 380416 C:\WINDOWS\SYSTEM32\dllcache\irprops.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 68608 C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 618496 C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 257024 C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 32768 C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 114688 C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 155648 C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 298496 C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
    Microsoft Corporation 8/4/2004 6:00:00 PM 148480 C:\WINDOWS\SYSTEM32\dllcache\wscui.cpl
    Microsoft Corporation 5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl

    »»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

    Checking files in %ALLUSERSPROFILE%\Startup folder...
    8/20/2004 4:31:26 AM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
    3/10/2005 12:44:22 PM 1730 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk

    Checking files in %ALLUSERSPROFILE%\Application Data folder...
    8/19/2004 9:22:12 PM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini

    Checking files in %USERPROFILE%\Startup folder...
    8/20/2004 4:31:26 AM HS 84 C:\Documents and Settings\Sabrina\Start Menu\Programs\Startup\desktop.ini

    Checking files in %USERPROFILE%\Application Data folder...
    8/19/2004 9:22:12 PM HS 62 C:\Documents and Settings\Sabrina\Application Data\desktop.ini
    3/18/2005 10:58:58 AM 30440 C:\Documents and Settings\Sabrina\Application Data\GDIPFONTCACHEV1.DAT

    »»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    SV1 =

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

    [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AJC
    {5071CDA5-D3E1-11D5-BFC0-005004A71005} = C:\Program Files\Advanced JPEG Compressor\ContextMenuExt.dll
    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido anti-spyware
    {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Documents and Settings\Sabrina\My Documents\My Data Sources\Anti-Virus\Evido\ewido anti-spyware 4.0\context.dll
    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
    {750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
    {09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
    {A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
    {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} = C:\Program Files\Norton AntiVirus\NavShExt.dll
    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{8C504614-A455-4CBA-81B4-D279644B8A7D}
    = tfaxext.dll
    HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
    Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
    {FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} = C:\Program Files\Norton AntiVirus\NavShExt.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
    {A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ewido anti-spyware
    {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Documents and Settings\Sabrina\My Documents\My Data Sources\Anti-Virus\Evido\ewido anti-spyware 4.0\context.dll
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
    {750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
    {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
    = %SystemRoot%\system32\SHELL32.dll
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
    = %SystemRoot%\system32\SHELL32.dll

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
    = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}
    DriveLetterAccess = C:\WINDOWS\system32\dla\tfswshx.dll
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}
    CNavExtBho Class = C:\Program Files\Norton AntiVirus\NavShExt.dll
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
    Google Toolbar Helper = c:\program files\google\googletoolbar2.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
    &Tip of the Day = %SystemRoot%\system32\shdocvw.dll
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
    Real.com = C:\WINDOWS\system32\Shdocvw.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
    {327C2873-E90D-4c37-AA9D-10AC9BABA46C} = Easy-WebPrint : C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} = &Google : c:\program files\google\googletoolbar2.dll
    {C4069E3A-68F1-403E-B40E-20066696354B} = Norton AntiVirus : C:\Program Files\Norton AntiVirus\NavShExt.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
    MenuText = Sun Java Console :
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
    ButtonText = Research :
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
    ButtonText = Real.com :
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
    ButtonText = Messenger : C:\Program Files\Messenger\msmsgs.exe

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{21569614-B795-46B1-85F4-E737A8DC09AD}
    Shell Search Band = %SystemRoot%\system32\browseui.dll
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}
    Search Band = %SystemRoot%\system32\browseui.dll
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
    Favorites Band = %SystemRoot%\system32\shdocvw.dll

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
    {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :
    {2318C2B1-4965-11D4-9B18-009027A5CD4F} = &Google : c:\program files\google\googletoolbar2.dll
    {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\system32\browseui.dll
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
    {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\system32\browseui.dll
    {0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
    {2318C2B1-4965-11D4-9B18-009027A5CD4F} = &Google : c:\program files\google\googletoolbar2.dll
    {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = :

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    CeEPOWER C:\Program Files\TOSHIBA\Power Management\CePMTray.exe

    dla C:\WINDOWS\system32\dla\tfswctrl.exe
    LtMoh C:\Program Files\ltmoh\Ltmoh.exe
    AGRSMMSG AGRSMMSG.exe
    Apoint C:\Program Files\Apoint2K\Apoint.exe
    EzButton C:\Program Files\EzButton\EzButton.EXE
    NDSTray.exe NDSTray.exe
    CeEKEY C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    PadTouch C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    SmoothView C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    ZoomingHook c:\WINDOWS\System32\ZoomingHook.exe
    TPNF C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    IgfxTray C:\WINDOWS\system32\igfxtray.exe
    HotKeysCmds C:\WINDOWS\system32\hkcmd.exe
    ATIPTA C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    Pinger c:\toshiba\ivp\ism\pinger.exe /run
    IndexSearch C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
    OneTouch Monitor C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
    CFSServ.exe CFSServ.exe -NoClient
    IVPServiceMgr C:\toshiba\ivp\ism\ivpsvmgr.exe
    RealTray C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    CompanionWizard "C:\Program Files\Common Files\Companion Wizard\compwiz.exe" /silent
    ccApp "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    !ewido "C:\Documents and Settings\Sabrina\My Documents\My Data Sources\Anti-Virus\Evido\ewido anti-spyware 4.0\ewido.exe" /minimized

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
    IMAIL Installed = 1
    MAPI Installed = 1
    MSFS Installed = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    TOSCDSPD C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
    TeleAuth C:\Documents and Settings\Sabrina\Desktop\teleauth.exe

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID
    {17492023-C23A-453E-A040-C7C580BBF700} 1

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
    {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
    {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
    {0DF44EAA-FF21-4412-828E-260A8728E7F1} =


    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
    dontdisplaylastusername 0
    legalnoticecaption
    legalnoticetext
    shutdownwithoutlogon 1
    undockwithoutlogon 1


    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
    NoDriveTypeAutoRun 255

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
    DisableRegistryTools 0


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
    CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
    WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll
    SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINDOWS\system32\userinit.exe,
    Shell = Explorer.exe
    System =

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
    = crypt32.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
    = cryptnet.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
    = cscdll.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
    = igfxsrvc.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
    = wlnotify.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
    = wlnotify.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
    = sclgntfy.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
    = WlNotify.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    = wlnotify.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon
    = WgaLogon.dll

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
    = wlnotify.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
    Debugger = ntsd -d

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    AppInit_DLLs


    »»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
    Scan completed on 8/8/2006 9:23:20 PM
     
  6. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,299
    Please go HERE to run Panda's ActiveScan
    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
     
  7. Sabrina Glyndale

    Sabrina Glyndale Thread Starter

    Joined:
    Apr 29, 2006
    Messages:
    40
    Hi, Cookiegal,

    Okay, I followed your instructions. Here is the most recent log from Panda Active scan. The text is too long, so here is the first part. See my next message for the rest of the log:

    Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
    Adware:adware/swimsuitnetwork Not disinfected c:\windows\system32\MYDLL.dll
    Potentially unwanted tool:application/mediapipe Not disinfected hkey_classes_root\clsid\{B3E19860-0CD5-4991-A066-4FCA2704DE59}
    Potentially unwanted tool:application/winantivirus2006 Not disinfected hkey_classes_root\WAP6.PCheck
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Sabrina\Cookies\[email protected][2].txt
    Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{78B62AAA-CE27-458E-BB07-1B2FC2C33724}.dll
    Spyware:Cookie/2o7 Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtoxdvgtqs
    Spyware:Cookie/2o7 Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtjftjzfkx
    Spyware:Cookie/2o7 Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtnjabyqyt
    Spyware:Cookie/2o7 Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtogopovza
    Spyware:Cookie/2o7 Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txttiynevwn
    Spyware:Cookie/2o7 Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtvoiabdah
    Spyware:Cookie/Apmebf Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txttesquoya
    Spyware:Cookie/Falkag Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txteqxgmxfs
    Spyware:Cookie/Falkag Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtwzihmzzw
    Spyware:Cookie/Atwola Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txthijngqqq
    Spyware:Cookie/Atwola Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtltlfmsxu
    Spyware:Cookie/Atwola Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtqymyzjzn
     
  8. Sabrina Glyndale

    Sabrina Glyndale Thread Starter

    Joined:
    Apr 29, 2006
    Messages:
    40
    Here is Part Two of the Panda Log:

    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtdrghtgdr
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txthfgadlro
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txttfdhkskw
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txttwdhjipa
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtjxhmrcdl
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtlgyjxkbj
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtltlfmsxu
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtnvkfyecl
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtrsvnjiuo
    Spyware:Cookie/Bluestreak Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtzstekvdg
    Spyware:Cookie/bravenetA Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtzstekvdg
    Spyware:Cookie/Serving-sys Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtlepggsrp
    Spyware:Cookie/BurstNet Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txteraiqgsj
    Spyware:Cookie/BurstNet Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtldueuguh
    Spyware:Cookie/BurstNet Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtltcmumrp
    Spyware:Cookie/BurstNet Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtnvkfyecl
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txteraiqgsj
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txteuiwnphb
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txthrzrppba
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtiqjnlnak
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtjmezogwj
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtltcmumrp
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtnvkfyecl
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtwbcytufr
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtbaqkdwfk
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtpetqziln
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtqfnbkzrs
    Spyware:Cookie/Casalemedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtxsyyfohg
    Spyware:Cookie/cs.sexcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtptidwlek
    Spyware:Cookie/Go Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtptidwlek
    Spyware:Cookie/Internetfuel Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtdlamiiqg
    Spyware:Cookie/Maxserving Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtltcmumrp
    Spyware:Cookie/Maxserving Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtrqqbfymv
    Spyware:Cookie/PayCounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtafvunlqt
    Spyware:Cookie/Paypopup Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txttyiosgip
    Spyware:Cookie/QuestionMarket Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtbaqkdwfk
    Spyware:Cookie/QuestionMarket Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtgcnldxvi
    Spyware:Cookie/QuestionMarket Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmjzixvww
    Spyware:Cookie/QuestionMarket Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtovwrekhm
    Spyware:Cookie/QuestionMarket Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtgztqmdcu
    Spyware:Cookie/QuestionMarket Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtlqrzrqsv
    Spyware:Cookie/RealMedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtdohshred
    Spyware:Cookie/RealMedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtlqrzrqsv
    Spyware:Cookie/RealMedia Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtovwrekhm
    Spyware:Cookie/WUpd Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtdezytyxs
    Spyware:Cookie/Serving-sys Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtepcggpsv
    Spyware:Cookie/Serving-sys Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtlqrzrqsv
    Spyware:Cookie/Serving-sys Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txttyiosgip
    Spyware:Cookie/SpyLog Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmauzlxkc
    Spyware:Cookie/SpyLog Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmjzixvww
    Spyware:Cookie/SpyLog Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtyizfevhc
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtatnigeht
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txticlhwlti
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmauzlxkc
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmfckbgnf
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmjzixvww
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtqaamkhic
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtzwmltngi
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtbbxnskai
    Spyware:Cookie/Statcounter Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtqkdwxbjc
    Spyware:Cookie/Tickle Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtmpjuasdh
    Spyware:Cookie/Traffic Marketplace Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmpjuasdh
    Spyware:Cookie/Traffic Marketplace Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtbbxnskai
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtatnigeht
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtbbxnskai
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtiqautgun
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtjbdcnvmu
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmhlwjflc
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtztbgqrzf
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtmgovurxc
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtqkdwxbjc
    Spyware:Cookie/Tribalfusion Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtyfoscqaa
    Spyware:Cookie/Adserver Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtiqautgun
    Spyware:Cookie/Adserver Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtjbdcnvmu
    Spyware:Cookie/Adserver Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtmgovurxc
    Spyware:Cookie/Adserver Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtrdgwrtef
    Spyware:Cookie/Adserver Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtvzvtppfb
    Spyware:Cookie/Adserver Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtykgiubcb
    Spyware:Cookie/Zedo Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtinxpqcnl
    Spyware:Cookie/Zedo Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtopbewwms
    Spyware:Cookie/Zedo Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][1].txtsetaobir
    Spyware:Cookie/Zedo Not disinfected C:\WinAntiVirus Pro 2006\Quarantine\[email protected][2].txtjbdcnvmu
     
  9. Sabrina Glyndale

    Sabrina Glyndale Thread Starter

    Joined:
    Apr 29, 2006
    Messages:
    40
    Hi, Cookiegal.

    Are you still there? I sent you my latest Panda logs. Did you get them?? Please help me ASAP. My computer is running excruciatingly slowly. Recently I noticed that when I cut and paste blocks of text, the text is all garbled. I ran SpyBot, and it told me I have all kinds of serious hacker tools from Winfixer in my registry.

    I didn't wna to delete anything until I hear from you. I was expecting an answer by now. Sorry to rush you, but I am an Ameican writer doing research in the Urals region of Russia. This is my ONLY computer, and I am unemployed.

    I think this virus is spreading, so if you would please get back to me ASAP, I would really, really appreciate it. Thank you!

    Sabrina
     
  10. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,299
    I'm sorry but I didn't receive any notification of your reply. I have to go out shortly and will post back with further instructions when I return.
     
  11. ~Candy~

    ~Candy~ Retired Administrator

    Joined:
    Jan 27, 2001
    Messages:
    103,706
  12. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Joined:
    Aug 27, 2003
    Messages:
    112,299
    I'm attaching a FixSabrina.zip file to this post. Save it to your desktop but don't do anything with it yet. We will use it later in safe mode.


    Click Here and download Killbox and save it to your desktop but don’t run it yet.


    Rescan with HijackThis, close all browser windows except HijackThis, put a check mark beside these entries and click fix checked.


    O4 - HKLM\..\Run: [CompanionWizard] "C:\Program Files\Common Files\Companion Wizard\compwiz.exe" /silent


    Then boot to safe mode:


    How to restart to safe mode


    Double-click on Killbox.exe to run it.
    • Put a tick by Standard File Kill.
    • In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time:

      C:\Program Files\common files\winantivirus pro 2006\wapchk.dll

      C:\Program Files\common files\winantivirus pro 2006

      C:\Program Files\Common Files\Companion Wizard\compwiz.exe

      C:\Program Files\Common Files\Companion Wizard\WapCHK.dll

      C:\Program Files\Common Files\Companion Wizard\WapCHK{78B62AAA-CE27-458E-BB07-1B2FC2C33724}.dll

      C:\Program Files\Common Files\Companion Wizard

      c:\windows\system32\MYDLL.dll


    • Click on the button that has the red circle with the X in the middle after you enter each file.
    • It will ask for confirmation to delete the file.
    • Click Yes.
    • Continue with that procedure until you have pasted all of these in the "Paste Full Path of File to Delete" box.
    • Killbox may tell you that one or more files do not exist.
    • If that happens, just continue on with all the files. Be sure you don't miss any.
    • Next in Killbox go to Tools > Delete Temp Files
    • In the window that pops up, put a check by ALL the options there except these three:
      • XP Prefetch
      • Recent
      • History
    • Now click the Delete Selected Temp Files button.
    • Exit the Killbox.


    Unzip the FixSabrina.zip file that you saved to your desktop earlier and double click on the FixSabrina.reg file and allow it to enter into the registry.


    You also need to replace your Sun java with newest version. There are more vulnerabilities in the older versions that can be exploited.

    Go to Add/Remove programs and uninstall this:

    Java 2 Runtime Environment, SE v1.4.2


    Now go here and install the latest version of Java.



    Boot back to Windows normally and post another HijackThis log please.
     
  13. Sabrina Glyndale

    Sabrina Glyndale Thread Starter

    Joined:
    Apr 29, 2006
    Messages:
    40
    Hellllllllllllllloooooooooooooo?? Could someone please help me? I posted the results of my Panda log.

    WHAT NEXT?

    Please stop delaying on this, or least refer me to someone who can reply more promptly. Thank you.
     
  14. Nigel55

    Nigel55

    Joined:
    Aug 10, 2006
    Messages:
    3
    Thanks, Cookiegal! I only saw this message just now! For some reason, I received no notification of your reply in my email inbox.

    Okay, I will do all this right now and get back to you soon. So do you think this is serious? How serious?

    Back soon,

    Sabrina
     
  15. Sabrina Glyndale

    Sabrina Glyndale Thread Starter

    Joined:
    Apr 29, 2006
    Messages:
    40
    Hi again. Sorry about the other post. I just needed help quickly.

    I do not see any FixSabrina.zip file attached to your post. Can you please try it again?

    Thank you!

    Sabrina
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/490133

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice