Hi,
I have got this thing where if i go on google and search, the text is bigger than usual. Also if i click on a search it loads up a new window and some random site comes up.
Id really appreciate a step by step guide on what to do as im not really into computers.
Incidentally ive seen some other posts on here and tried to follow then with no joy.
I have used ccleaner, superantispyware, vundofix, hostxpert and I also used Malwarebytes' Anti-Malware. I saved the log but have used ccleaner again since and loaded up the net to post this message. I also used Eset but in fairness it was all done randomly. I think i need a proceedure as I could be removing the problem but then restarting it somehow??
Any help would be greatly appreciated.

here is the log
from Malwarebytes' Anti Malware

Malwarebytes' Anti-Malware 1.28
Database version: 1218
Windows 5.1.2600 Service Pack 3

28/09/2008 14:55:06
mbam-log-2008-09-28 (14-55-00).txt

Scan type: Full Scan (C:\|)
Objects scanned: 143792
Time elapsed: 35 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 2
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ugac (Rogue.PCSecureSystem) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Security Tools (Trojan.Zlob) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.PCVirusless) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> No action taken.

Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> No action taken.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> No action taken.

Files Infected:
C:\WINDOWS\system32\ (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\ (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\drivers\svchost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.

and here is the log from hijack this

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:18:28, on 28/09/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/webhp?sourceid=navclient&ie=UTF-8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 8314 bytes

Recommended Answers

All 70 Replies

ps i downloaded spybot to try and use but my access would not allow me to give it the required updates it needs to proceed.

thanks

Hi skiesaregrey, welcome to daniweb. For now don't worry about the Spybot program.

Obviously MBA-M has found some infections but you need to run it again in order for them to be cleaned out.
Run it again and this time First of course check to see if there are any updates to it since your last run. If there are then update.
Then run it again and when the scan is complete
Be sure that everything is checked, and click Remove Selected.

Reboot the computer.

Please Run the ESET Online Scanner and attach the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is Un-checked at this time (we may have it clean what it finds at a later time), and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.
Reboot the computer

Then run HiJackThis again, save the log. Post back here with the new MBA-M log and ESET Scan log and the new HiJackThis log.
Judy

Hi Judy thankyou so much for your reply.
I have completed what you asked although CNET website would not let me on. I got a neighbour to download it for me and I did it that way, although the options (* Be sure the option to Remove found threats is Un-checked at this time (we may have it clean what it finds at a later time), and the option to Scan unwanted applications is Checked.) could not be found.

MALWAREBYTES LOG

Malwarebytes' Anti-Malware 1.28
Database version: 1221
Windows 5.1.2600 Service Pack 3

28/09/2008 20:41:55
mbam-log-2008-09-28 (20-41-55).txt

Scan type: Full Scan (C:\|)
Objects scanned: 145166
Time elapsed: 40 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ugac (Rogue.PCSecureSystem) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Security Tools (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.PCVirusless) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\ (Trojan.Agent) -> Quarantined and deleted successfully.


CNET SCAN LOG

Scan Log
Version of virus signature database: 3312 (20080731)
Date: 28/09/2008 Time: 22:28:05
Scanned disks, folders and files: C:\
C:\hiberfil.sys - error opening [4]
C:\pagefile.sys - error opening [4]
C:\Documents and Settings\Guest\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Inbox.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\LocalService\NTUSER.DAT - error opening [4]
C:\Documents and Settings\LocalService\ntuser.dat.LOG - error opening [4]
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening [4]
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening [4]
C:\Documents and Settings\NetworkService\NTUSER.DAT - error opening [4]
C:\Documents and Settings\NetworkService\ntuser.dat.LOG - error opening [4]
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening [4]
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening [4]
C:\Documents and Settings\Peresh Gela\NTUSER.DAT - error opening [4]
C:\Documents and Settings\Peresh Gela\ntuser.dat.LOG - error opening [4]
C:\Documents and Settings\Peresh Gela\Desktop\Browser Redirects to go_google_com (or nowhere at all) - Viruses, Spyware and other Nasties.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\Desktop\FREE SMS.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\Desktop\HijackThis Logfileauswertung.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\Desktop\Inventor Services Pre-submission Registration Form.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\Desktop\kid stuff! - Easy craft activities and projects for kids.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\Desktop\vdmsound.exe » NSIS - bad archive
C:\Documents and Settings\Peresh Gela\Desktop\wrestling boots.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\Desktop\101MSDCF\The Green Head - Finds Cool New Stuff!.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\Desktop\ComboFix\ComboFix.exe » UPX v12_m2 - is OK
C:\Documents and Settings\Peresh Gela\Desktop\ComboFix\ComboFix.exe » RAR » ComboFixT\ntp.exe » AUTOIT » file.bin - archive damaged
C:\Documents and Settings\Peresh Gela\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Inbox.dbx » DBX - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening [4]
C:\Documents and Settings\Peresh Gela\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening [4]
C:\Documents and Settings\Peresh Gela\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D96DC0CC-B036-4F0F-B3D5-31B0031122C7} - error opening [4]
C:\Documents and Settings\Peresh Gela\My Documents\Business\BusinessNews\For Innovative Engineering Design suppliers, design news.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Business\domains\Transfer.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Business\domains\nameservers\1&1 Webhosting FAQ How do I create my own name servers for a Windows Server.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Business\domains\nameservers\ASOwiki Setting up Custom Nameservers at your Registrar.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Business\domains\nameservers\How To Park a Domain with Sedo www_businesstwins_com.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Business\MotionTouch\Design - MotionTouch.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Charity\How it works Child Sponsorship What You Can Do World Vision UK.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Charity\India Charity Organisations Education System Residential Childrens Schools Orissa UK.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Desktop\IWC Media Television Drama.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Desktop\TQ example\View More Pictures.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Installers\PC Hell How to Remove SmitFraud variants like WinAntivirus Pro 2007, PestCapture, and more.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Installers\winamp5531_full_emusic-7plus_en-us.exe » NSIS » file.bin - error - unknown compression method
C:\Documents and Settings\Peresh Gela\My Documents\Installers\Vundo\BleepingComputer_com Sstts_exe Missing.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Music\More music\Donald Byrd\03 - Love's So Far Away.mp3 - error opening [4]
C:\Documents and Settings\Peresh Gela\My Documents\Music\More music\Donald Byrd\04 - Mr. Thomas.mp3 - error opening [4]
C:\Documents and Settings\Peresh Gela\My Documents\Music\More music\Donald Byrd\05 - Sky High.mp3 - error opening [4]
C:\Documents and Settings\Peresh Gela\My Documents\Music\More music\Donald Byrd\06 - Slop Jar Blues.mp3 - error opening [4]
C:\Documents and Settings\Peresh Gela\My Documents\Music\Net Music\Can anyone give me names of best hiphop songs to dance to - Yahoo! Answers UK.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Music\Net Music\disco1and2dance_chart4u.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Music\Net Music\DJSanFran.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Music\Net Music\Maurice 'n' Morris.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Music\Net Music\The Power of Funky ___ the originals !!!.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Music\Podcast downloads\Google Image Result for http--farm2_static_flickr_com-1076-797202797_309504b66a_jpg.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Music\Podcast downloads\Hed Kandi A Taste Of Kandi Summer ??????? mp3 - ??????? ?????? mp3 ?????????, ??? ???????????, ????? ??????? ? mp3.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Short Film Writing\Because of Mama Drafting the Short Screenplay.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Short Film Writing\DVD 4 FREE - Online DVD Rental Guide.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Todotosee\music to get.txt » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\tracks to get\Amazon_co_uk Compilation Explosion!.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\tracks to get\Amazon_co_uk Discoteca.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\tracks to get\Amazon_co_uk Ten Soul Jazz Belters.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\tracks to get\BackRoomSounds Podcast.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Trainning\From Geek to Freak How I Gained 34 lbs_ of Muscle in 4 Weeks - The Blog of Author Tim Ferriss.mht » MIME - is OK (internal scanning not performed)
C:\Documents and Settings\Peresh Gela\My Documents\Weird Websites\FREE SMS.mht » MIME - is OK (internal scanning not performed)
C:\i386\COMPDATA\MSMQCOMP.TXT » MIME - is OK (internal scanning not performed)
C:\Nero\nero6316.exe » RAR » Nero\CDI\CDI_VCD.CFG » MIME - is OK (internal scanning not performed)
C:\Program Files\Ahead\Nero\CDI\CDI_VCD.CFG » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/deploy/ffjcext.zip » ZIP » {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}/chrome.manifest » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » com/sun/org/apache/xerces/internal/impl/msg/XIncludeMessages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » com/sun/xml/internal/fastinfoset/resources/ResourceBundle.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\core3.zip » ZIP » lib/resources.jar » ZIP » javax/xml/bind/Messages.properties » MIME - is OK (internal scanning not performed)
C:\Program Files\DJ Mix Master\Readme.txt » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_de.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_en.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_en_US.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_es.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_fr.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_it.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_ja_jp.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_ko.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_nl.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_pt.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_ru.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_zh.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Attach To Email\ReadMe\ReadMe_zh_TW.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_de.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_en_US.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_es.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_fr.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_it.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_ko.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_nl.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_pt.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_ru.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_zh.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\ReadMe_zh_TW.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Copy Utility\ReadMe\License\fr\License.txt » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_de.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_en_GB.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_en_US.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_es.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_fr.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_it.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_ko.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_nl.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_pt.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_ru.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_zh_CN.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Help\Help_zh_TW.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_de.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_en_GB.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_en_US.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_es.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_fr.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_it.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_ko.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_nl.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_pt.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_ru.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_zh_CN.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\Easy Photo Print\Readme\ReadMe_zh_TW.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_de.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_en_GB.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_en_US.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_es.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_fr.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_it.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_ko.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_nl.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_pt.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_ru.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_zh_CN.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Help\Help_zh_TW.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_de.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_en_GB.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_en_US.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_es.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_fr.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_it.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_ko.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_nl.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_pt.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_ru.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_zh_CN.def » MIME - is OK (internal scanning not performed)
C:\Program Files\epson\Creativity Suite\File Manager\Readme\ReadMe_zh_TW.def » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\genius_maxfighter_f16u.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\logitech_attack3.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\logitech_extreme_3d.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\logitech_force_3d.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\logitech_freedom.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\saitek_cyborg_evo.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\saitek_x52.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\speed_link_black_hawk.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\speed_link_black_widow.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\speed_link_cougar_flightstick.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\speed_link_dark_tornado.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Google\Google Earth\res\flightsim\controller\xbox_360.ini » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Default.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Round 05.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Round 10.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Round 25.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Round 50.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Square 01.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Square 05.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Square 10.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Square 25.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_+Square 50.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_Line horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_Line left.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_Line Right.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\BrushTip_Line vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Crosshatch.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Curl.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Rake fading.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Rake hard.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Spiky twirl large.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Spiky twirl medium.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Spiky twirl small.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Star points.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Surreal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_Twirly star.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Artistic\BrushTip_X.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Calligraphy tablet pen.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Fuzz soft.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Marble1.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Marble2.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Marble3.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Marble4.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Smoke puff.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Smoke wisp large.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Smoke wisp medium.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Smoke wisp small.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Media Brushes\BrushTip_Wavey.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Stamps\BrushTip_Pointy flower.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Brushes\Stamps\BrushTip_Rounded flower.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AddNoise_Photo grain high.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AddNoise_Photo grain low.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AddNoise_Photo grain medium.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AgedNewspaper_10 years.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AgedNewspaper_100 years.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AgedNewspaper_30 years.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AgedNewspaper_50 years.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AgedNewspaper_80 years.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoColorBalance_Strong cool.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoColorBalance_Strong warm.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoColorBalance_Weak cool.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoColorBalance_Weak warm.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoSmallScratchRemoval_Dark aggressive.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoSmallScratchRemoval_Dark mild.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoSmallScratchRemoval_Increase softness.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoSmallScratchRemoval_Light aggressive.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoSmallScratchRemoval_Light mild.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoSmallScratchRemoval_Line refine.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_AutoSmallScratchRemoval_Soften lines.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BackgroundEraser_Large sky.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BackgroundEraser_Small detail.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BlackPencil_High detail.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BlackPencil_Light pencil.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BlackPencil_Medium pencil.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BrushStrokes_More speckles.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BrushStrokes_More sticks.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BrushStrokes_Speckles.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_BrushStrokes_Sticks.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Burn_Large blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Burn_Small blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Charcoal_High detail.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Charcoal_Light charcoal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Charcoal_Medium charcoal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Chrome_Dark and rough.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Chrome_Smooth and bright.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Chrome_Smooth crimson.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Chrome_Toxic.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Chrome_Underwater.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Circle_Aqua.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Circle_Black.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Circle_Repeat.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Circle_White.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Circle_Wrap.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Clarify_Medium.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Clarify_Strong.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Clarify_Weak.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_CloneBrush_Large blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_CloneBrush_Medium blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_CloneBrush_Small blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustBrightnessContrast_Bright.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustBrightnessContrast_Dull.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustBrightnessContrast_High contrast.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustBrightnessContrast_Low contrast.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustColorBalance_Cool tone.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustColorBalance_Green.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustColorBalance_Warm tone.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustHSL_Aged color shift.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustHSL_Blue becomes red.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustHSL_Green becomes yellow.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustHSL_Intense blue.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColorAdjustHSL_Ultraviolet glow.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredChalk_High detail.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredChalk_Light chalk.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredChalk_Low detail.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredChalk_Medium chalk.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredEdges_Blue edge.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredEdges_Blurry.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredEdges_Green edge.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredEdges_Pastel and white.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredEdges_Red edge.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredEdges_Yellow edge.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredPencil_Edges.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredPencil_Light color.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ColoredPencil_Soft color.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Colorize_Blue bright.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Colorize_Blue neutral.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Colorize_Green bright.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Colorize_Green neutral.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Colorize_Red bright.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Colorize_Red neutral.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Colorize_Sepia overtone.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Cutout_Blue edge gold.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Cutout_Blue edge.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Cutout_Upper left fade.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Cutout_Upper right fade.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Dodge_Large blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Dodge_Small blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_DropShadow_Above wide left.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_DropShadow_Above wide right.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_DropShadow_Below wide left.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_DropShadow_Below wide right.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_EdgePreservingSmooth_Smooth high.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_EdgePreservingSmooth_Smooth low.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_EdgePreservingSmooth_Smooth maximum.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_EdgePreservingSmooth_Smooth medium.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Eraser_Large blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Eraser_Medium blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Eraser_Small blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_FadeCorrection_High correction.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_FadeCorrection_Small correction.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_FineLeather_Long and spread.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_FineLeather_More speckles.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_FineLeather_Small and spread.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_FineLeather_Sprayed.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_FineLeather_Spread speckles.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Fur_Smaller stitches.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Fur_Stitches long.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Fur_Stitches transparent.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Fur_Stitches.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_GaussianBlur_Radius 2.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_GaussianBlur_Radius 5.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_GaussianBlur_Radius 8.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_HorizontalCylinder_Medium.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_HorizontalCylinder_Strong.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_HorizontalCylinder_Weak.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_InnerBevel_Frosted.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_InnerBevel_Grass stained.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_InnerBevel_Under the sea.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_JPEGArtifactRemoval_High.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_JPEGArtifactRemoval_Low.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_JPEGArtifactRemoval_Medium.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_MosaicGlass_Glass bars horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_MosaicGlass_Glass bars square.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_MosaicGlass_Glass bars vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_MosaicGlass_Glass cubes.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_1024 x 768.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_120 x 240 vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_1200 x 800.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_125 x 125 Square Button.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_234 x 60 Half Banner.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_3.5 x 5 in horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_3.5 x 5 in vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_4 x 6 in horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_4 x 6 in vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_468 x 60 Full Banner.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_5 x 7 in horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_5 x 7 in vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_640 x 480.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_72 x 392 Full Vertical Navbar.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_8 x 10 in horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_8 x 10 in vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_800 x 600.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_88 x 31 Micro Button.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_Business Card horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_Business Card vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_CD Insert.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_Japanese Postcard horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_Japanese Postcard vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_Panorama.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_Postcard horizontal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_Postcard vertical.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_NewFile_Square.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_OuterBevel_Lower left.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_OuterBevel_Lower right.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_OuterBevel_Underwater.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_PaintBrush_Large hard edge.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_PaintBrush_Small blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pencil_Blurred streaks.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pencil_Bright lime.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pencil_Intense red.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pencil_Soft blue cover.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_PerspectiveTransform_Last Applied.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pixelate_Horizontal lines.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pixelate_Large squares.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pixelate_Tall blocks.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pixelate_Vertical lines.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Pixelate_Wide blocks.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Posterize_High contrast.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Posterize_Low contrast.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Posterize_Medium contrast.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RedEyeRemoval_Blue.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RedEyeRemoval_Brown.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RedEyeRemoval_Dark photo.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RedEyeRemoval_Eye sparkle.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RedEyeRemoval_Green.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RedEyeRemoval_Grey.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RedEyeRemoval_Lifeless.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RedEyeRemoval_Violet.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Ripple_Big waves left.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Ripple_Big waves right.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Ripple_Small waves left.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Ripple_Small waves right.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RoughLeather_Contrast.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RoughLeather_High contrast blurred.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_RoughLeather_Low contrast.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sandstone_Detail high blurred.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sandstone_Detail high.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sandstone_Detail low blurred.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sandstone_Detail low.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ScratchRemover_Large scratches.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_ScratchRemover_Small scratches.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sculpture_Deep metal smooth.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sculpture_Deep metal.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sculpture_Deep red smooth.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sculpture_Deep red.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sepia_Fully aged.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sepia_Medium age.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_Sepia_Slight age.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SharpenBrush_Large blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SharpenBrush_Medium blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SharpenBrush_Small blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SmudgeBrush_Medium coarse.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SmudgeBrush_Medium smooth.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SoftenBrush_Large blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SoftenBrush_Medium blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SoftenBrush_Small blend.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SoftFocus_Halo large.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SoftFocus_Halo medium.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SoftFocus_Halo small.PspScript » MIME - is OK (internal scanning not performed)
C:\Program Files\Jasc Software Inc\Paint Shop Pro Studio\Presets\Preset_SoftFocus_Light ripple.PspScript » MIME - is OK (internal sca

Hi skiesaregrey,

You mis-read my post. It wasn't CNET scanner it is ESET scanner, which cannot be downloaded, it is an online scan.

Try again by clicking on the blue link below;

Please Run the ESET Online Scanner and attach the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is Un-checked at this time (we may have it clean what it finds at a later time), and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.
Reboot the compute

Sorry that was a typing mistake it is ESET NOD32 Anti virus. And that site will not let me on it.

Still the wrong site. What you are trying to enter is the download site for ESET NOD32 onboard virus program.
I don't want you to download their anti-virus program I wanted you to do their online scan which is called ESET ONLINE SCANNER.
Try to do this one HOUSECALL

oh ok isee.
HOUSE CALL doesnt load up either...
same prompt "unable to open at this time"

Ok give me a bit to go through your log.
But first, go to Add/Remove and UNINSTALL that ESET NOD32 program you installed. You shouldn't have two antivirus programs on one computer, and now you do.

Forgive me for getting a bit confused here but in your first post here you said

I also used Eset

I thought at that time you meant the Online Scanner. Sorry for my confusion.

I would like you to try to boot the computer into Safe mode with Networking. To do this do the following;
Using the F8 Method

1. Restart your computer.
2. When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
3. Select the option for Safe Mode using the arrow keys.
4. Then press enter on your keyboard to boot into Safe Mode with Networking.
This should allow you to go online without unnecessary programs running in the background, hopefully whatever infection is causing this problem.

When you are in Safe Mode, first try the ESET Online Scanner link again and see if you can access.
If you can then do the scan and save the log.

If you cannot access it then do this please;
Download ComboFix
Click on the Save button and then when it asks you where to save it, make sure you save it directly to your Windows Desktop.
Once the download is complete you will see the Combofix on the desktop.
Reboot the computer to NORMAL mode.
Once you have rebooted you MUST do the following;
* Close all open Windows including this one.
* Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix It is VITAL that you do this or the program may not run correctly.
* Doubleclick the combofix icon on the desktop to run the program.

Windows will issue a prompt asking whether you wish to run the program, click Run
You will then see a Disclaimer screen asking you to agree to the disclaimer. Press the number 1 key to accept the disclaimer.

Now just sit back and allow the program to run

Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.

When ComboFix has finished running, you will see a screen stating that it is preparing the log report.
This can take a while, so please be patient. If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.

When all is complete then please post back here with that log.
Judy

Hi,

I went online in safe networking mode. The net still will not let me access ESET. I tried to download combofix from bleeping computer but it also would not let me go on that site. After a lot of scouting around I eventually found it on someone elses site who had mirrored it?? anyway i saved it to the desktop. Rebooted the pc turned off my virus checked, firewall etc and then double clicked on the icon. A prompt came up saying Combo fix had detected Rootkit activity and need to reboot the machine. So it rebooted, i clicked again, same message. This is the final point i have reached...
(what a nightmare!!!)
Thankyou for your continued support, much oblidged

Ok you are going to need to run Blacklight which is a rootkit revealer and remover. Just click on the above in Blue & hopefully you can download it onto your computer, if not then see if you can find a way to download to another computer and bring it to yours. You do NOT need to go to the site itself, this is a stand alone installer

Please follow the instructions below which I have copy/pasted from BleepingComputer's Using Blacklight to detect and remove Rootkits from your computer

Once you click on the download link you will be presented with a prompt asking what you would like to do with the file. I suggest you save the file directly to your desktop where we will run it from there. Once the file has finished downloading you will see the program icon on your desktop.
To start the program simply double-click on the blbeta.exe icon and you will be presented with the license agreemen.t Select the option that is labeled I accept the agreement and then press the Next button.
You will now be presented with a new screen with a Scan button on the lower left.
To start scanning your computer for possible rootkits, press the Scan button. Blacklight will now start scanning your computer for any hidden files or processes. As it scans your processes and files it will update its status to reflect what it is scanning and if it has found any hidden items.
When the scanning is done, the Next button will become available and you should click on it. If Blacklight did not find any hidden items you will see a screen showing that no hidden items were found. You can then press the Exit button to exit the program as Blacklight did not find any rootkits on your computer. If on the other hand, Blacklight did find some hidden items, you will be presented with a screen showing a list of the processes and files hidden on your computer.
In the Clean hidden items screen you will see a list of the processes and programs that are hidden on your computer.
In order to tag a particular file or process that you would like to clean, you need to left-click once on an entry with your mouse so that it is highlighted, and then press the Rename button. When you do this, the action will change from None to Rename. Once you set a file to Rename, you can untag it by pressing the None button so that no action is performed on this particular item.

If you would like more information about the entry, you can double-click on it with your mouse. This will bring up a small screen showing you more detailed information about the file or process such as the location of the file, the description information, and the company information. It is common for the description and company information to be blank so do not be worried if there is nothing listed there.
It is important to note that rootkits can hide legitimate processes and files. So when selecting the files you would like to rename please make sure you are only renaming the malware files as renaming the wrong files can cause problems with your Windows installation.

After you have selected all of the files you would like to rename, you should press the Next button. A warning screen will now show stating that renaming legitimate files can cause Windows not to operate properly. If you would still like to continue renaming the files, put a checkmark in the checkbox labeled I have understood the warning and wish to continue and then press the OK button. You should then press the Restart Now, and then the OK button again, to restart your computer and rename the select files.
When the computer reboots it will rename the files with a .ren extension. Because these files are no longer be loaded at startup, they will now become visible so that you can delete them. For example, if we had renamed the files:

klgcptini.dat
fux87.ini

They would now be named:

klgcptini.dat.ren
fux87.ini.ren

As long as these files are confirmed as being malware, you can then delete them from your computer. Blacklight when it performs a scan will create a log file in the same folder that you ran the program from. If you followed the steps in this tutorial, that folder would be your Windows Desktop. The file name of the log file will start with fsbl- followed by the data and some other numbers. An example is fsbl-20060518203951.log.

Once these rootkit files have been deleted, it is advised that you scan your computer with an antivirus and an antispyware software in order to remove any leftover files.

Let us know how things go and post that Blacklight log here when complete.
Judy

Hi Judy,

Blacklight did not find anything...
heres the generated report.

09/29/08 15:25:44 [Info]: BlackLight Engine 1.0.70 initialized
09/29/08 15:25:44 [Info]: OS: 5.1 build 2600 (Service Pack 3)
09/29/08 15:25:45 [Note]: 7019 4
09/29/08 15:25:45 [Note]: 7005 0
09/29/08 15:25:54 [Note]: 7006 0
09/29/08 15:25:54 [Note]: 7011 1752
09/29/08 15:25:54 [Note]: 7035 0
09/29/08 15:25:54 [Note]: 7026 0
09/29/08 15:25:54 [Note]: 7026 0
09/29/08 15:25:57 [Note]: FSRAW library version 1.7.1024
09/29/08 15:26:47 [Note]: 7007 0

thanks

Ok that's good. Let's try one more time with Combofix and see if it will run. If it will not then try this, Right Click on the combofix icon and choose Rename.
Then rename it to daniweb.exe. Then try to run it and see if it works.
Judy

Running combofix didnt work. Same message about it detecting rootkit activity and needs to shut my laptop down.
This also happened when I renamed combofix to daniweb.exe.

Dan

Ok thanks. Now this software worked.
19 discrepancies were found... although there was no option to fix these problems. Unsure if it was done by the program or what..

HKU\.DEFAULT\Control Panel\International 28/09/2008 12:48 0 bytes Security mismatch.
HKU\.DEFAULT\Control Panel\International\Geo 28/09/2008 12:48 0 bytes Security mismatch.
HKU\S-1-5-21-4111454303-2817279294-1250794735-1006\Control Panel\International 28/09/2008 12:48 0 bytes Security mismatch.
HKU\S-1-5-21-4111454303-2817279294-1250794735-1006\Control Panel\International\Geo 28/09/2008 12:48 0 bytes Security mismatch.
HKU\S-1-5-21-4111454303-2817279294-1250794735-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21FDCA1A-0219-94C5-9C37-490FAC3155B7}* 15/02/2007 00:40 0 bytes Key name contains embedded nulls (*)
HKU\S-1-5-18\Control Panel\International 28/09/2008 12:48 0 bytes Security mismatch.
HKU\S-1-5-18\Control Panel\International\Geo 28/09/2008 12:48 0 bytes Security mismatch.
HKLM\SECURITY\Policy\Secrets\SAC* 11/08/2004 02:23 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 11/08/2004 02:23 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\webcal\URL Protocol 15/09/2005 09:13 13 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssData 29/09/2008 11:11 0 bytes Hidden from Windows API.
HKLM\SOFTWARE\TDSS 29/09/2008 18:27 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\TDSSserv.sys 27/09/2008 18:54 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\TDSSserv.sys 27/09/2008 18:54 0 bytes
HKLM\SYSTEM\ControlSet001\Services\TDSSserv 29/09/2008 18:33 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\TDSSserv.sys 27/09/2008 18:54 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\TDSSserv.sys 27/09/2008 18:54 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\TDSSserv 29/09/2008 18:27 0 bytes Hidden from Windows API.
C: 01/01/1601 01:00 0 bytes Error mounting volume


(Thanks again for your support Judy!)
Dan

Well, I am researching all I can here. Have gone back through your logs posted to see if there were things that I missed, of course since I was so concerned that you had not run the requested online scan but a different one I had not actually "combed" through that log close enough, one thing I noticed in that CNET SCAN LOG were these entries;

C:\Documents and Settings\Peresh Gela\Desktop\ComboFix\ComboFix.exe » UPX v12_m2 - is OK
C:\Documents and Settings\Peresh Gela\Desktop\ComboFix\ComboFix.exe » RAR » ComboFixT\ntp.exe » AUTOIT » file.bin - archive damaged

This was BEFORE I asked you to download Combofix. In your original post you said you had run the following programs

I have used ccleaner, superantispyware, vundofix, hostxpert and I also used Malwarebytes' Anti-Malware. I saved the log but have used ccleaner again since and loaded up the net to post this message.

Nowhere does it mention Combofix. When did you run combofix before? Was it because of this problem or something else? This isn't a tool which should be used unless specifically directed to do so by a helper. It should never be consider for private use like spybot, malwarebytes', ccleaner, superantispyware. Using this tool incorrectly could adversely impact your system. Plus there was a bug in combofix in one of the earlier versions so I wonder what version that was.
You need to remove combofix from the computer please follow these instructions.
* Click START then RUN
* Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
When shown the disclaimer, Select "2"

You said you used hostxpert, who told you to use this? It too is a good program but you need to know exactly what you are doing. Which version did you use?

Combofix and hostxpert (2007) were both used from before this post was created.
I know I should have made a post but i was anxious to sort this mess out. Apologies.

I have clicked Start then Run and typed in Combofix /u and pressed ok...
"Combofix has detected the presence of rootkit activity and needs to reboot the machine".

Dan

See if you can just delete it, without using Start Run..

On that restart i just recieved this message on a blue screen just before windows icons start loading up...
"Windows cannot find C:\windows\system32\CF26406.exe..."

I am having the same exact problems as you Dan. I haven't gotten a virus in literally 3 years on my computer, and I've never seen something this nasty. It is seeming impossible to get rid of.

I am having the same exact problems as you Dan. I haven't gotten a virus in literally 3 years on my computer, and I've never seen something this nasty. It is seeming impossible to get rid of.

This is not good. Don't know I got it or how to shift it. Hopefully Judys going to work some magic.

Ok... I have just noticed that on the google search engine the text is back to normal size :) and also its not opening new windows with adds!! However its still not loading certain pages eg bleeping computer and is also running slow. Halfway there?
dan

This is not good. Don't know I got it or how to shift it. Hopefully Judys going to work some magic.

I really appreciate the help you guys are giving us, and I really hope we can resolve this without costly professional involvement!

Ok... I have just noticed that on the google search engine the text is back to normal size :) and also its not opening new windows with adds!! However its still not loading certain pages eg bleeping computer and is also running slow. Halfway there?
dan

Mine did that for awhile once today too, but then unfortunately after awhile Google went back into the hijacked one. :[

Let me know if yours goes back too.

In that case of scared of shutting it down for the night... Does that message = "Windows cannot find C:\windows\system32\CF26406.exe..."
come up everytime you load up windows? or was it the once?

In that case of scared of shutting it down for the night... Does that message = "Windows cannot find C:\windows\system32\CF26406.exe..."
come up everytime you load up windows? or was it the once?

That's the only thing different about your situtation than mine. I've never had that error. Perhaps it is unrelated to this virus?

Mine did that for awhile once today too, but then unfortunately after awhile Google went back into the hijacked one. :[

Let me know if yours goes back too.

You were right. What a nightmare!!!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.