I followed all of the instructions from the previous posting. In addition, I ran the Symantec "Trojan.Abwiz.F" removal tool. When I ran the scans in safe mode, Norton and MS Antispyware did not find anything. However, ewido found 28 items and Spy Sweeper found one more. I follwed your instructions and cleaned those files. There was nothing to empty from my recycle bin in safe mode. However, when I rebooted in regular mode there were items in my recycle bin which needed to be deleted. Maybe this was due to my being logged in as the administrator in safe mode and myself in regular mode. The logs from the scan are listed below, please let me know what you think and if there is anything to worry about from here on out. Thanks again=) Brian
Hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 3:04:23 PM, on 3/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java141\jre\bin\NPJPI141.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) -
https://www.ibm.com/pc/support/acces...tent/AcpIR.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -
http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {D772BBC7-1F7A-40BD-BD0A-889F43341CA4} (CmdInsReg Class) -
https://www.send2fax.com/microsoft-o...RegControl.cab
O18 - Protocol: bw+0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {86BCA0A7-F916-4B38-9D5B-79D40EA0597D} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TSS Core Service (TSSCoreService) - IBM - C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
O23 - Service: TVT Backup Service - Unknown owner - C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Unknown owner - C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
ewido log:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 11:23:50 AM, 3/27/2006
+ Report-Checksum: F800FB97
+ Scan result:
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP148\A0084198.exe -> Trojan.Small : Cleaned with backup
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP148\A0084199.exe -> Trojan.Small : Cleaned with backup
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP148\A0084200.exe -> Downloader.Small.ciw : Cleaned with backup
C:\WINDOWS\system32\akfloing.huv -> Trojan.Agent.qe : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@cbs.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@com[2].txt -> TrackingCookie.Com : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@coxhsi.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@data1.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@e-2dj6wjk4kgajkdo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@ehg-uniontrib.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@greatschools.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@image.masterstats[2].txt -> TrackingCookie.Masterstats : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@microsofteup.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@sec1.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@sonycorporate.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@thunderbolt.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@www.web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
E:\Backup of C Drive\Documents and Settings\Brian Stebbins\Cookies\brian stebbins@yadro[2].txt -> TrackingCookie.Yadro : Cleaned with backup
::Report End
Spy Sweeper log:
********
1:15 PM: | Start of Session, Monday, March 27, 2006 |
1:15 PM: Spy Sweeper started
1:15 PM: Sweep initiated using definitions version 641
1:15 PM: Starting Memory Sweep
1:17 PM: Memory Sweep Complete, Elapsed Time: 00:01:44
1:17 PM: Starting Registry Sweep
1:17 PM: Registry Sweep Complete, Elapsed Time:00:00:17
1:17 PM: Starting Cookie Sweep
1:17 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
1:18 PM: Starting File Sweep
1:18 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:18 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:18 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:18 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:18 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:18 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:18 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\program files\\{1007f41f-7d69-468e-8017-3849a5a973c2}\data1.hdr". The system cannot find the path specified
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\program files\\{3868a8ee-5051-4db0-8df6-4f4b8a98d083}\setup.ilg". The system cannot find the path specified
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:19 PM: Warning: Failed to open file "c:\program files\\{78f4dfce-1336-4027-bcb2-1a00c24a8653}\setup.ilg". The system cannot find the path specified
1:19 PM: Warning: Failed to open file "c:\program files\\{2e088491-2681-46bf-b8e8-e835b121cda3}\data1.hdr". The system cannot find the path specified
1:19 PM: Warning: Failed to open file "c:\program files\\{900b1197-53f5-4f46-a882-2cfffe2eedcb}\data1.hdr". The system cannot find the path specified
1:19 PM: Warning: Failed to open file "c:\program files\\{872653c6-5ddc-488b-b7c2-cf9e4d9335e5}\setup.ilg". The system cannot find the path specified
1:20 PM: Warning: Failed to open file "c:\program files\\{fe7a3fe1-af76-44fd-bc70-09868a51887a}\setup.ilg". The system cannot find the path specified
1:20 PM: Warning: Failed to open file "c:\program files\\{72806716-7088-41b2-8fa6-717a2a164dab}\data1.hdr". The system cannot find the path specified
1:20 PM: Warning: Failed to open file "c:\program files\\{82512bc9-bd5d-4c50-be4d-b98e7df78687}\data1.hdr". The system cannot find the path specified
1:20 PM: Warning: Failed to open file "c:\program files\\{ea664480-3844-11d5-8c25-444553540000}\data1.hdr". The system cannot find the path specified
1:21 PM: Warning: Failed to open file "c:\program files\\{2111b23f-7fda-4a41-8309-e5a1663ca296}\data1.hdr". The system cannot find the path specified
1:22 PM: Warning: Failed to open file "c:\program files\\pc-doctor\diagnostics\setup.bmp". The system cannot find the path specified
1:25 PM: Warning: Failed to open file "c:\program files\\{1f7ccfa3-d926-4882-b2a5-a0217ed25597}\setup.ilg". The system cannot find the path specified
1:25 PM: Warning: Failed to open file "c:\program files\\{9b94be6f-7ca3-4c40-a266-62667ff746cc}\data1.hdr". The system cannot find the path specified
1:25 PM: Warning: Failed to open file "c:\program files\\{bad59025-5b73-4e12-b789-0028c5a573c2}\setup.ilg". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\{91810afc-a4f8-4eba-a5aa-b198bbc81144}\icon.bmp". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\{43801800-cfee-11d2-a41b-006097b55ad3}\data1.hdr". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\pc-doctor\services\setup.bmp". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\pc-doctor\cui\setup.bmp". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\pc-doctor\setup.bmp". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\{e646dcf0-5a68-11d5-b229-002078017fbf}\data1.hdr". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\pc-doctor\diagnostics\setup.iss". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\{47808f78-f178-49dc-b708-15fe538b16ff}\setup.ilg". The system cannot find the path specified
1:26 PM: Warning: Failed to open file "c:\program files\\{1f7ccfa3-d926-4882-b2a5-a0217ed25597}\setup.inx". The system cannot find the path specified
1:27 PM: Warning: Failed to open file "c:\program files\\pc-doctor\diagnostics\setup.inx". The system cannot find the path specified
1:27 PM: Warning: Failed to open file "c:\program files\\pc-doctor\services\setup.inx". The system cannot find the path specified
1:27 PM: Warning: Failed to open file "c:\program files\\{5809e7cf-4dcf-11d4-9875-00105ace7734}\layout.bin". The system cannot find the path specified
1:27 PM: Warning: Failed to open file "c:\program files\\{22b71a00-4ded-11d4-a5e5-0004ac564f43}\setup.ilg". The system cannot find the path specified
1:27 PM: Warning: Failed to open file "c:\program files\\{54de0b75-6cd9-44c4-b10a-1f25da9899d8}\setup.ilg". The system cannot find the path specified
1:27 PM: Warning: Failed to open file "c:\program files\\pc-doctor\cui\setup.inx". The system cannot find the path specified
1:27 PM: Warning: Failed to open file "c:\program files\\{2e088491-2681-46bf-b8e8-e835b121cda3}\setup.inx". The system cannot find the path specified
1:27 PM: Warning: Failed to open file "c:\program files\\{0bedbd4e-2d34-47b5-9973-57e62b29307c}\setup.ilg". The system cannot find the path specified
1:28 PM: Warning: Failed to open file "c:\program files\\{2fce4fc5-6930-40e7-a4f1-f862207424ef}\data1.hdr". The system cannot find the path specified
1:28 PM: Warning: Failed to open file "c:\program files\\{2fce4fc5-6930-40e7-a4f1-f862207424ef}\layout.bin". The system cannot find the path specified
1:28 PM: Warning: Failed to open file "c:\program files\\{6c72e14a-c1f3-45e5-8810-83ce3c19ed63}\setup.inx". The system cannot find the path specified
1:28 PM: Warning: Failed to open file "c:\program files\\pc-doctor\cui\data1.hdr". The system cannot find the path specified
1:28 PM: Warning: Failed to open file "c:\program files\\{44a537a5-859c-43a6-8285-c0668142a090}\setup.ilg". The system cannot find the path specified
1:28 PM: Warning: Failed to open file "c:\program files\\{0552a36d-0d7e-4ff5-8fdb-6629aba7c779}\setup.ilg". The system cannot find the path specified
1:29 PM: Warning: Failed to open file "c:\program files\\{91810afc-a4f8-4eba-a5aa-b198bbc81144}\layout.bin". The system cannot find the path specified
1:29 PM: Warning: Failed to open file "c:\program files\\{5809e7cf-4dcf-11d4-9875-00105ace7734}\setup.inx". The system cannot find the path specified
1:29 PM: Warning: Failed to open file "c:\program files\\{5809e7cf-4dcf-11d4-9875-00105ace7734}\setup.ilg". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{22b71a00-4ded-11d4-a5e5-0004ac564f43}\data1.cab". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{91810afc-a4f8-4eba-a5aa-b198bbc81144}\setup.ilg". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{2fce4fc5-6930-40e7-a4f1-f862207424ef}\setup.inx". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\pc-doctor\setup.inx". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{9f765bd0-b900-4ede-a90b-61c8a9e95c42}\setup.inx". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{9f765bd0-b900-4ede-a90b-61c8a9e95c42}\data1.hdr". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\pc-doctor\cui\data2.cab". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{13413c6c-c640-40b8-917e-ca3062826b18}\data1.hdr". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{3f92abbb-6bbf-11d5-b229-002078017fbf}\data1.cab". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{39da87a1-0b26-4562-a70c-2a6147366e47}\setup.ilg". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{39da87a1-0b26-4562-a70c-2a6147366e47}\setup.inx". The system cannot find the path specified
1:30 PM: Warning: Failed to open file "c:\program files\\{bad59025-5b73-4e12-b789-0028c5a573c2}\setup.inx". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{9fac9e5c-0d20-4dbf-afe5-2e09c52a95a2}\setup.ilg". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{13413c6c-c640-40b8-917e-ca3062826b18}\data1.cab". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{22b71a00-4ded-11d4-a5e5-0004ac564f43}\setup.inx". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{91810afc-a4f8-4eba-a5aa-b198bbc81144}\data1.hdr". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{2e088491-2681-46bf-b8e8-e835b121cda3}\data1.cab". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{44a537a5-859c-43a6-8285-c0668142a090}\setup.inx". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{fe7a3fe1-af76-44fd-bc70-09868a51887a}\setup.inx". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{1007f41f-7d69-468e-8017-3849a5a973c2}\setup.ilg". The system cannot find the path specified
1:31 PM: Warning: Failed to open file "c:\program files\\{4e5e22c2-1386-47ae-8ede-32ddcdcd6653}\setup.ilg". The system cannot find the path specified
1:32 PM: Warning: Failed to open file "c:\program files\\{9fac9e5c-0d20-4dbf-afe5-2e09c52a95a2}\setup.inx". The system cannot find the path specified
1:32 PM: Warning: Failed to open file "c:\program files\\{2111b23f-7fda-4a41-8309-e5a1663ca296}\setup.inx". The system cannot find the path specified
1:32 PM: Warning: Failed to open file "c:\program files\\{91810afc-a4f8-4eba-a5aa-b198bbc81144}\data1.cab". The system cannot find the path specified
1:32 PM: Warning: Failed to open file "c:\program files\\{2fce4fc5-6930-40e7-a4f1-f862207424ef}\data1.cab". The system cannot find the path specified
1:32 PM: Warning: Failed to open file "c:\program files\\{5809e7cf-4dcf-11d4-9875-00105ace7734}\data1.cab". The system cannot find the path specified
1:32 PM: Warning: Failed to open file "c:\program files\\{9b94be6f-7ca3-4c40-a266-62667ff746cc}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{900b1197-53f5-4f46-a882-2cfffe2eedcb}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{9fac9e5c-0d20-4dbf-afe5-2e09c52a95a2}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{1007f41f-7d69-468e-8017-3849a5a973c2}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{0bedbd4e-2d34-47b5-9973-57e62b29307c}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{2111b23f-7fda-4a41-8309-e5a1663ca296}\setup.ilg". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{e646dcf0-5a68-11d5-b229-002078017fbf}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{72806716-7088-41b2-8fa6-717a2a164dab}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{2111b23f-7fda-4a41-8309-e5a1663ca296}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{54de0b75-6cd9-44c4-b10a-1f25da9899d8}\setup.inx". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{82512bc9-bd5d-4c50-be4d-b98e7df78687}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{9f765bd0-b900-4ede-a90b-61c8a9e95c42}\setup.ilg". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\pc-doctor\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{1f7ccfa3-d926-4882-b2a5-a0217ed25597}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{ea664480-3844-11d5-8c25-444553540000}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{bad59025-5b73-4e12-b789-0028c5a573c2}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{39da87a1-0b26-4562-a70c-2a6147366e47}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{9f765bd0-b900-4ede-a90b-61c8a9e95c42}\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\pc-doctor\cui\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\pc-doctor\services\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\pc-doctor\diagnostics\data1.cab". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{72806716-7088-41b2-8fa6-717a2a164dab}\setup.inx". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{1f7ccfa3-d926-4882-b2a5-a0217ed25597}\data1.hdr". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\pc-doctor\services\data1.hdr". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\pc-doctor\data1.hdr". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{39da87a1-0b26-4562-a70c-2a6147366e47}\data1.hdr". The system cannot find the path specified
1:33 PM: Warning: Failed to open file "c:\program files\\{3f92abbb-6bbf-11d5-b229-002078017fbf}\data1.hdr". The system cannot find the path specified
1:34 PM: Warning: Failed to open file "c:\program files\\{22b71a00-4ded-11d4-a5e5-0004ac564f43}\data1.hdr". The system cannot find the path specified
1:35 PM: Warning: Failed to open file "c:\program files\\{1efba4b2-5000-49a5-a107-0816e10605a1}\setup.ilg". The system cannot find the path specified
1:35 PM: Warning: Failed to open file "c:\program files\\{6c72e14a-c1f3-45e5-8810-83ce3c19ed63}\setup.ilg". The system cannot find the path specified
1:35 PM: Warning: Failed to open file "c:\program files\\{be20e2f5-1903-4aae-b1af-2046e586c925}\setup.ilg". The system cannot find the path specified
1:36 PM: Warning: Failed to open file "c:\program files\\pc-doctor\services\setup.iss". The system cannot find the path specified
1:36 PM: Warning: Failed to open file "c:\program files\\pc-doctor\setup.iss". The system cannot find the path specified
1:36 PM: Warning: Failed to open file "c:\program files\\{5809e7cf-4dcf-11d4-9875-00105ace7734}\data1.hdr". The system cannot find the path specified
1:36 PM: Warning: Failed to open file "c:\program files\\pc-doctor\diagnostics\data1.hdr". The system cannot find the path specified
1:36 PM: Warning: Failed to open file "c:\program files\\{bad59025-5b73-4e12-b789-0028c5a573c2}\data1.hdr". The system cannot find the path specified
1:37 PM: Warning: Failed to open file "c:\program files\\{3ea9d975-bfdc-4e8e-b88b-0446fbc8ca66}\data1.hdr". The system cannot find the path specified
1:38 PM: Warning: Failed to open file "c:\program files\\{13413c6c-c640-40b8-917e-ca3062826b18}\setup.inx". The system cannot find the path specified
1:38 PM: Warning: Failed to open file "c:\program files\\{900b1197-53f5-4f46-a882-2cfffe2eedcb}\setup.ilg". The system cannot find the path specified
1:39 PM: Warning: Failed to open file "c:\program files\\{900b1197-53f5-4f46-a882-2cfffe2eedcb}\setup.inx". The system cannot find the path specified
1:39 PM: Warning: Failed to open file "c:\program files\\{72806716-7088-41b2-8fa6-717a2a164dab}\setup.ilg". The system cannot find the path specified
1:39 PM: Warning: Failed to open file "c:\program files\\{82512bc9-bd5d-4c50-be4d-b98e7df78687}\setup.inx". The system cannot find the path specified
1:41 PM: Warning: Failed to open file "c:\program files\\{9fac9e5c-0d20-4dbf-afe5-2e09c52a95a2}\data1.hdr". The system cannot find the path specified
1:41 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:41 PM: Warning: Failed to open file "c:\program files\\pc-doctor\diagnostics\ikernel.ex_". The system cannot find the path specified
1:41 PM: Warning: Failed to open file "c:\program files\\pc-doctor\services\ikernel.ex_". The system cannot find the path specified
1:41 PM: Warning: Failed to open file "c:\program files\\pc-doctor\cui\ikernel.ex_". The system cannot find the path specified
1:41 PM: Warning: Failed to open file "c:\program files\\pc-doctor\ikernel.ex_". The system cannot find the path specified
1:41 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:41 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:41 PM: Warning: Failed to open file "c:\program files\\{1efba4b2-5000-49a5-a107-0816e10605a1}\setup.inx". The system cannot find the path specified
1:42 PM: Warning: Failed to open file "c:\program files\\pc-doctor\services\data2.cab". The system cannot find the path specified
1:42 PM: Warning: Failed to open file "c:\program files\\{82512bc9-bd5d-4c50-be4d-b98e7df78687}\setup.ilg". The system cannot find the path specified
1:42 PM: Warning: Failed to open file "c:\program files\\{2fce4fc5-6930-40e7-a4f1-f862207424ef}\setup.ilg". The system cannot find the path specified
1:42 PM: Warning: Failed to open file "c:\program files\\{3ea9d975-bfdc-4e8e-b88b-0446fbc8ca66}\data1.cab". The system cannot find the path specified
1:43 PM: Warning: Failed to open file "c:\program files\\{ea664480-3844-11d5-8c25-444553540000}\setup.ilg". The system cannot find the path specified
1:43 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:43 PM: Warning: Failed to open file "c:\program files\\{ea664480-3844-11d5-8c25-444553540000}\setup.inx". The system cannot find the path specified
1:43 PM: Warning: Failed to open file "c:\program files\\{0bedbd4e-2d34-47b5-9973-57e62b29307c}\data1.hdr". The system cannot find the path specified
1:43 PM: Warning: Failed to open file "c:\program files\\{3f92abbb-6bbf-11d5-b229-002078017fbf}\setup.inx". The system cannot find the path specified
1:43 PM: Warning: Failed to open file "c:\program files\\{3f92abbb-6bbf-11d5-b229-002078017fbf}\setup.ilg". The system cannot find the path specified
1:43 PM: Warning: Failed to open file "c:\program files\\{43801800-cfee-11d2-a41b-006097b55ad3}\data1.cab". The system cannot find the path specified
1:43 PM: Warning: Failed to open file "c:\program files\\{91810afc-a4f8-4eba-a5aa-b198bbc81144}\setup.inx". The system cannot find the path specified
1:43 PM: Warning: Failed to open file "c:\program files\\{e646dcf0-5a68-11d5-b229-002078017fbf}\setup.inx". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\{e646dcf0-5a68-11d5-b229-002078017fbf}\setup.ilg". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\{43801800-cfee-11d2-a41b-006097b55ad3}\setup.inx". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\{9b94be6f-7ca3-4c40-a266-62667ff746cc}\setup.inx". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\{0bedbd4e-2d34-47b5-9973-57e62b29307c}\setup.inx". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\{13413c6c-c640-40b8-917e-ca3062826b18}\setup.ilg". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\{3ea9d975-bfdc-4e8e-b88b-0446fbc8ca66}\setup.inx". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\{3ea9d975-bfdc-4e8e-b88b-0446fbc8ca66}\setup.ilg". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\{1007f41f-7d69-468e-8017-3849a5a973c2}\setup.inx". The system cannot find the path specified
1:44 PM: Warning: Failed to open file "c:\program files\\pc-doctor\diagnostics\data2.cab". The system cannot find the path specified
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
1:46 PM: Warning: Failed to open file "c:\windows\system32\catroot\a
2:02 PM: Found System Monitor: potentially rootkit-masked files
2:02 PM: 04-violin concerto ('l'estate', the four seasons) for violin, strings & continuo in g minor, op. 8-2, rv 315- allegro-various artists-25 romantic classics.wma (ID = 0)
2:02 PM: Warning: Unhandled Archive Type
2:02 PM: Warning: Unhandled Archive Type
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Invalid file - not a PKZip file
2:02 PM: Warning: Unhandled Archive Type
2:02 PM: Warning: Unhandled Archive Type
2:04 PM: Warning: Invalid file - not a PKZip file
2:04 PM: Warning: Invalid file - not a PKZip file
2:04 PM: Warning: Invalid file - not a PKZip file
2:04 PM: Warning: Invalid file - not a PKZip file
2:04 PM: Warning: Invalid file - not a PKZip file
2:04 PM: Warning: Invalid file - not a PKZip file
2:04 PM: Warning: Invalid file - not a PKZip file
2:04 PM: Warning: Invalid file - not a PKZip file
2:04 PM: File Sweep Complete, Elapsed Time: 00:46:50
2:04 PM: Full Sweep has completed. Elapsed time 00:49:05
2:04 PM: Traces Found: 1
2:45 PM: Removal process initiated
2:45 PM: Quarantining All Traces: potentially rootkit-masked files
2:45 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
2:45 PM: 04-violin concerto ('l'estate', the four seasons) for violin, strings & continuo in g minor, op. 8-2, rv 315- allegro-various artists-25 romantic classics.wma is in use. It will be removed on reboot.
2:46 PM: Preparing to restart your computer. Please wait...
2:46 PM: Removal process completed. Elapsed time 00:00:52
********
1:13 PM: | Start of Session, Monday, March 27, 2006 |
1:13 PM: Spy Sweeper started
1:15 PM: | End of Session, Monday, March 27, 2006 |