1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

adware everywhere

Discussion in 'Malware and Virus Removal Archive' started by Cael Weston, 2006/12/04.

Thread Status:
Not open for further replies.
  1. 2006/12/07
    Cael Weston

    Cael Weston Inactive Thread Starter

    Joined:
    2006/12/02
    Messages:
    36
    Likes Received:
    0
    autorun log 2 of 3

    r Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

    + MMC Icon Handler MMC Shell Extension DLL Microsoft Corporation c:\windows\system32\mmcshext.dll

    + MRU AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + Multimedia File Property Sheet Control Panel Drivers Applet Microsoft Corporation c:\windows\system32\mmsys.cpl

    + MyDocs Copy Hook My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

    + MyDocs Drop Target My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

    + MyDocs Properties My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

    + Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshell.dll

    + Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshell.dll

    + NTFS Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32.dll

    + Offline Files Folder Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

    + Offline Files Folder Options Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

    + Offline Files Menu Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

    + OLE Docfile Property Page OLE DocFile Property Page Microsoft Corporation c:\windows\system32\docprop.dll

    + PlusPack CPL Extension Windows Theme API Microsoft Corporation c:\windows\system32\themeui.dll

    + Portable Media Devices Portable Media Devices Shell Extension Microsoft Corporation c:\windows\system32\audiodev.dll

    + Portable Media Devices Menu Portable Media Devices Shell Extension Microsoft Corporation c:\windows\system32\audiodev.dll

    + PostAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

    + Print Ordering via the Web Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

    + Printers Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32.dll

    + Registry Tree Options Utility Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + Remote Sessions CPL Extension Remote Sessions CPL Extension Microsoft Corporation c:\windows\system32\remotepg.dll

    + Run... Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

    + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

    + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

    + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

    + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

    + Scheduled Tasks Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

    + Search Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    + Search Assistant OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    + Search Band Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendmail.dll

    + Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendmail.dll

    + Shell Application Manager Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl

    + Shell Automation Inproc Service Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    + Shell Band Site Menu Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + Shell DeskBar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + Shell DeskBarApp Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + Shell DocObject Viewer Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    + Shell extensions for Microsoft Windows Network objects Network object shell UI Microsoft Corporation c:\windows\system32\ntlanui2.dll

    + Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll

    + Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll

    + Shell extensions for Windows Script Host Microsoft (r) Shell Extension for Windows Script Host Microsoft Corporation c:\windows\system32\wshext.dll

    + Shell Image Data Factory Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

    + Shell Image Property Handler Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

    + Shell Image Verbs Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

    + Shell properties for a DS object Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

    + Shell Publishing Wizard Object Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

    + Shell Rebar BandSite Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + Shell Scrap DataHandler Shell scrap object handler Microsoft Corporation c:\windows\system32\shscrap.dll

    + Subscription Folder Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

    + Subscription Mgr Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

    + Summary Info Thumbnail handler (DOCFILES) Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

    + Taskbar and Start Menu Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

    + Tasks Folder Icon Handler Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

    + Tasks Folder Shell Extension Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

    + Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    + Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    + The Internet Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    + Track Popup Bar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + TrayAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

    + TridentImageExtractor Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + User Accounts Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

    + User Assist Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + Video Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

    + Video Thumbnail Extractor Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

    + Wav Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

    + Web Folders Microsoft Web Folders Microsoft Corporation c:\program files\common files\microsoft shared\web folders\msonsext.dll

    + Web Printer Shell Extension Print UI DLL Microsoft Corporation c:\windows\system32\printui.dll

    + Web Publishing Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

    + Web Search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

    + WebCheck Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

    + WebCheck SyncMgr Handler Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

    + WebCheckChannelAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

    + WebCheckWebCrawler Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

    + Windows Media Player Add to Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

    + Windows Media Player Burn Audio CD Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

    + Windows Media Player Play as Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

    + Yahoo! Mail YMMAPI Module Yahoo! Inc. c:\program files\yahoo!\common\ymmapi.dll

    HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

    + {0D2E74C4-3C34-11d2-A27E-00C04FC30871} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

    + {24F14F01-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

    + {24F14F02-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

    + {66742402-F9B9-11D1-A202-0000F81FEDEE} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

    + Windows Live Sign-in Helper WindowsLiveLogin.dll Microsoft Corporation c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll

    + Windows Live Toolbar Helper Windows Live Toolbar for Internet Explorer Microsoft Corporation c:\program files\windows live toolbar\msntb.dll

    + Yahoo! Toolbar Helper File not found: C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

    HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

    + shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

    HKLM\Software\Microsoft\Internet Explorer\Toolbar

    + msdxm.ocx Windows Media Player 2 ActiveX Control Microsoft Corporation c:\windows\system32\msdxm.ocx

    + msntb.dll Windows Live Toolbar for Internet Explorer Microsoft Corporation c:\program files\windows live toolbar\msntb.dll

    HKLM\Software\Microsoft\Internet Explorer\Extensions

    + Windows Messenger Messenger Microsoft Corporation c:\program files\messenger\msmsgs.exe

    Task Scheduler

    + Check Updates for Windows Live Toolbar.job MSN Search Toolbar Scheduled Update Utility Microsoft Corporation c:\program files\windows live toolbar\msntbup.exe

    HKLM\System\CurrentControlSet\Services

    + AOL ACS AOL Connectivity Service America Online, Inc. c:\program files\common files\aol\acs\acsd.exe

    + AudioSrv Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + AVG Anti-Spyware Guard AVG Anti-Spyware guard Anti-Malware Development a.s. c:\program files\grisoft\avg anti-spyware 7.5\guard.exe

    + Browser Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + CiSvc Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language. Microsoft Corporation c:\windows\system32\cisvc.exe

    + CryptSvc Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + Dhcp Manages network configuration by registering and updating IP addresses and DNS names. Microsoft Corporation c:\windows\system32\svchost.exe

    + Dnscache Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + ERSvc Allows error reporting for services and applictions running in non-standard environments. Microsoft Corporation c:\windows\system32\svchost.exe

    + Eventlog Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Microsoft Corporation c:\windows\system32\services.exe

    + helpsvc Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + lanmanserver Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + lanmanworkstation Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + LexBceS LexBce Service Lexmark International, Inc. c:\windows\system32\lexbces.exe

    + LmHosts Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Microsoft Corporation c:\windows\system32\svchost.exe

    + PlugPlay Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Microsoft Corporation c:\windows\system32\services.exe

    + PolicyAgent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Microsoft Corporation c:\windows\system32\lsass.exe

    + ProtectedStorage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Microsoft Corporation c:\windows\system32\lsass.exe

    + RpcSs Provides the endpoint mapper and other miscellaneous RPC services. Microsoft Corporation c:\windows\system32\svchost.exe

    + SamSs Stores security information for local user accounts. Microsoft Corporation c:\windows\system32\lsass.exe

    + Schedule Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + seclogon Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + SENS Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Microsoft Corporation c:\windows\system32\svchost.exe

    + SharedAccess Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. Microsoft Corporation c:\windows\system32\svchost.exe

    + ShellHWDetection Generic Host Process for Win32 Services Microsoft Corporation c:\windows\system32\svchost.exe

    + Spooler Loads files to memory for later printing. Microsoft Corporation c:\windows\system32\spoolsv.exe

    + srservice Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties Microsoft Corporation c:\windows\system32\svchost.exe

    + stisvc Provides image acquisition services for scanners and cameras. Microsoft Corporation c:\windows\system32\svchost.exe

    + Themes Provides user experience theme management. Microsoft Corporation c:\windows\system32\svchost.exe

    + TrkWks Maintains links between NTFS files within a computer or across computers in a network domain. Microsoft Corporation c:\windows\system32\svchost.exe

    + UMWdf Enables Windows user mode drivers. Microsoft Corporation c:\windows\system32\wdfmgr.exe

    + uploadmgr Manages synchronous and asynchronous file transfers between clients and servers on the network. If this service is stopped, synchronous and asynchronous file transfers between clients and servers on the network will not occur. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + w32time Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

    Microsoft Corporation c:\windows\system32\svchost.exe

    + WebClient Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + winmgmt Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

    + wuauserv Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Microsoft Corporation c:\windows\system32\svchost.exe

    + WZCSVC Provides automatic configuration for the 802.11 adapters Microsoft Corporation c:\windows\system32\svchost.exe

    HKLM\System\CurrentControlSet\Services

    + ACPI ACPI Driver for NT Microsoft Corporation c:\windows\system32\drivers\acpi.sys

    + aeaudio Andrea Audio Stub Driver Andrea Electronics Corporation c:\windows\system32\drivers\aeaudio.sys

    + aec Microsoft Acoustic Echo Canceller Microsoft Corporation c:\windows\system32\drivers\aec.sys

    + AFD Ancillary Function Driver for WinSock Microsoft Corporation c:\windows\system32\drivers\afd.sys

    + AsyncMac RAS Asynchronous Media Driver Microsoft Corporation c:\windows\system32\drivers\asyncmac.sys

    + atapi IDE/ATAPI Port Driver Microsoft Corporation c:\windows\system32\drivers\atapi.sys

    + Atmarpc ATM ARP Client Protocol Microsoft Corporation c:\windows\system32\drivers\atmarpc.sys

    + audstub AudStub Driver Microsoft Corporation c:\windows\system32\drivers\audstub.sys

    + AVG Anti-Spyware Driver c:\program files\grisoft\avg anti-spyware 7.5\guard.sys

    + AvgAsCln AVG7 Clean Driver GRISOFT, s.r.o. c:\windows\system32\drivers\avgascln.sys

    + bcm4sbxp Broadcom Corporation NDIS 5.1 ethernet driver Broadcom Corporation c:\windows\system32\drivers\bcm4sbxp.sys

    + Cdrom SCSI CD-ROM Driver Microsoft Corporation c:\windows\system32\drivers\cdrom.sys

    + d347bus PnP BIOS Extension c:\windows\system32\drivers\d347bus.sys

    + d347prt SCSI miniport c:\windows\system32\drivers\d347prt.sys

    + Disk PnP Disk Driver Microsoft Corporation c:\windows\system32\drivers\disk.sys

    + DMusic Microsoft Kernel DLS Synthesizer Microsoft Corporation c:\windows\system32\drivers\dmusic.sys

    + drmkaud Microsoft Kernel DRM Audio Descrambler Filter Microsoft Corporation c:\windows\system32\drivers\drmkaud.sys

    + EL90XBC 3Com EtherLink PCI Driver 3Com Corporation c:\windows\system32\drivers\el90xbc5.sys

    + Fdc Floppy Disk Controller Driver Microsoft Corporation c:\windows\system32\drivers\fdc.sys

    + Flpydisk Floppy Driver Microsoft Corporation c:\windows\system32\drivers\flpydisk.sys

    + Ftdisk FT Disk Driver Microsoft Corporation c:\windows\system32\drivers\ftdisk.sys

    + Gpc Generic Packet Classifier Microsoft Corporation c:\windows\system32\drivers\msgpc.sys

    + HidUsb USB Miniport Driver for Input Devices Microsoft Corporation c:\windows\system32\drivers\hidusb.sys

    + HSF_DP HSF_DP driver Conexant Systems c:\windows\system32\drivers\hsf_dp.sys

    + HSFHWCD2 HSFHWCD2 WDM driver Conexant Systems c:\windows\system32\drivers\hsfhwcd2.sys

    + i8042prt i8042 Port Driver Microsoft Corporation c:\windows\system32\drivers\i8042prt.sys

    + i81x Miniport Driver for Intel Graphics Driver Intel Corporation c:\windows\system32\drivers\i81xnt5.sys

    + iAimFP0 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\wadv01nt.sys

    + iAimFP1 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\wadv02nt.sys

    + iAimFP2 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\wadv05nt.sys

    + iAimFP3 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\wsiintxx.sys

    + iAimFP4 Local Flat Panel Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\wvchntxx.sys

    + iAimTV0 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\watv01nt.sys

    + iAimTV1 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\watv02nt.sys

    + iAimTV2 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\watv03nt.sys

    + iAimTV3 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\watv04nt.sys

    + iAimTV4 Digital Display Minidriver for Intel(R) Graphics Driver Intel Corporation c:\windows\system32\drivers\wch7xxnt.sys

    + ialm Controller Hub for Intel Graphics Driver Intel Corporation c:\windows\system32\drivers\ialmnt5.sys

    + Imapi IMAPI Kernel Driver Microsoft Corporation c:\windows\system32\drivers\imapi.sys

    + IpFilterDriver IP Traffic Filter Driver Microsoft Corporation c:\windows\system32\drivers\ipfltdrv.sys

    + IpInIp IP in IP Tunnel Driver Microsoft Corporation c:\windows\system32\drivers\ipinip.sys

    + IpNat IP Network Address Translator Microsoft Corporation c:\windows\system32\drivers\ipnat.sys

    + IPSec IPSEC driver Microsoft Corporation c:\windows\system32\drivers\ipsec.sys

    + IRENUM Infra-Red Bus Enumerator Microsoft Corporation c:\windows\system32\drivers\irenum.sys

    + isapnp PNP ISA Bus Driver Microsoft Corporation c:\windows\system32\drivers\isapnp.sys

    + Kbdclass Keyboard Class Driver Microsoft Corporation c:\windows\system32\drivers\kbdclass.sys

    + kmixer Kernel Mode Audio Mixer Microsoft Corporation c:\windows\system32\drivers\kmixer.sys

    + mdmxsdk Diagnostic Interface DRIVER Conexant c:\windows\system32\drivers\mdmxsdk.sys

    + Mouclass Mouse Class Driver Microsoft Corporation c:\windows\system32\drivers\mouclass.sys

    + MSKSSRV MS KS Server Microsoft Corporation c:\windows\system32\drivers\mskssrv.sys

    + MSPCLOCK MS Proxy Clock Microsoft Corporation c:\windows\system32\drivers\mspclock.sys

    + MSPQM MS Proxy Quality Manager Microsoft Corporation c:\windows\system32\drivers\mspqm.sys

    + NdisTapi Remote Access NDIS TAPI Driver Microsoft Corporation c:\windows\system32\drivers\ndistapi.sys

    + Ndisuio NDIS Usermode I/O Protocol Microsoft Corporation c:\windows\system32\drivers\ndisuio.sys

    + NdisWan Remote Access NDIS WAN Driver Microsoft Corporation c:\windows\system32\drivers\ndiswan.sys

    + NetBT NetBios over Tcpip Microsoft Corporation c:\windows\system32\drivers\netbt.sys

    + nv NVIDIA Compatible Windows 2000 Miniport Driver, Version 29.58 NVIDIA Corporation c:\windows\system32\drivers\nv4_mini.sys

    + NwlnkFlt IPX Traffic Filter Driver Microsoft Corporation c:\windows\system32\drivers\nwlnkflt.sys

    + NwlnkFwd IPX Traffic Forwarder Driver Microsoft Corporation c:\windows\system32\drivers\nwlnkfwd.sys

    + OlCamudp USB I/O Driver OLYMPUS Optical Co.,Ltd. c:\windows\system32\drivers\olcamudp.sys

    + omci OMCI Device Driver Dell Computer Corporation c:\windows\system32\drivers\omci.sys

    + P3 Processor Device Driver Microsoft Corporation c:\windows\system32\drivers\p3.sys

    + Parport Parallel Port Driver Microsoft Corporation c:\windows\system32\drivers\parport.sys

    + PCI NT Plug and Play PCI Enumerator Microsoft Corporation c:\windows\system32\drivers\pci.sys

    + PCIIde Generic PCI IDE Bus Driver Microsoft Corporation c:\windows\system32\drivers\pciide.sys

    + PptpMiniport WAN Miniport (PPTP) Microsoft Corporation c:\windows\system32\drivers\raspptp.sys

    + PRISM_A02 The Linksys Wireless-G USB Network Adapter provides wireless local area networking. Cisco-Linksys, LLC. c:\windows\system32\drivers\wusbgxp.sys

    + Processor Processor Device Driver Microsoft Corporation c:\windows\system32\drivers\processr.sys

    + PSched QoS Packet Scheduler Microsoft Corporation c:\windows\system32\drivers\psched.sys

    + Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\windows\system32\drivers\ptilink.sys

    + PxHelp20 Px Engine Device Driver for Windows 2000/XP Sonic Solutions c:\windows\system32\drivers\pxhelp20.sys

    + RasAcd Remote Access Auto Connection Driver Microsoft Corporation c:\windows\system32\drivers\rasacd.sys

    + Rasl2tp WAN Miniport (L2TP) Microsoft Corporation c:\windows\system32\drivers\rasl2tp.sys

    + RasPppoe Remote Access PPPOE Driver Microsoft Corporation c:\windows\system32\drivers\raspppoe.sys

    + Raspti Direct Parallel Microsoft Corporation c:\windows\system32\drivers\raspti.sys

    + RDPCDD RDP Miniport Microsoft Corporation c:\windows\system32\drivers\rdpcdd.sys

    + rdpdr Microsoft RDP Device redirector Microsoft Corporation c:\windows\system32\drivers\rdpdr.sys

    + redbook Redbook Audio Filter Driver Microsoft Corporation c:\windows\system32\drivers\redbook.sys

    + Secdrv SafeDisc driver Macrovision Europe Ltd c:\windows\system32\drivers\secdrv.sys

    + serenum Serial Port Enumerator Microsoft Corporation c:\windows\system32\drivers\serenum.sys

    + Serial Serial Device Driver Microsoft Corporation c:\windows\system32\drivers\serial.sys

    + smwdm SoundMAX Integrated Digital Audio Analog Devices, Inc. c:\windows\system32\drivers\smwdm.sys

    + SONYPVU1 Sony USB Lower Filter driver Sony Corporation c:\windows\system32\drivers\sonypvu1.sys

    + splitter Microsoft Kernel Audio Splitter Microsoft Corporation c:\windows\system32\drivers\splitter.sys

    + StreamDispatcher Conexant Stream Dispatcher Conexant Systems c:\windows\system32\drivers\strmdisp.sys

    + swenum Plug and Play Software Device Enumerator Microsoft Corporation c:\windows\system32\drivers\swenum.sys

    + swmidi Microsoft GS Wavetable Synthesizer Microsoft Corporation c:\windows\system32\drivers\swmidi.sys

    + sysaudio System Audio WDM Filter Microsoft Corporation c:\windows\system32\drivers\sysaudio.sys

    + Tcpip TCP/IP Protocol Driver Microsoft Corporation c:\windows\system32\drivers\tcpip.sys

    + TermDD Terminal Server Driver Microsoft Corporation c:\windows\system32\drivers\termdd.sys

    + Update Update Driver Microsoft Corporation c:\windows\system32\drivers\update.sys

    + usbaudio USB Audio Class Driver Microsoft Corporation c:\windows\system32\drivers\usbaudio.sys

    + usbccgp USB Common Class Generic Parent Driver Microsoft Corporation c:\windows\system32\drivers\usbccgp.sys

    + usbehci EHCI eUSB Miniport Driver Microsoft Corporation c:\windows\system32\drivers\usbehci.sys

    + usbhub Default Hub Driver for USB Microsoft Corporation c:\windows\system32\drivers\usbhub.sys

    + usbprint USB Printer driver Microsoft Corporation c:\windows\system32\drivers\usbprint.sys

    + usbscan USB Scanner Driver Microsoft Corporation c:\windows\system32\drivers\usbscan.sys

    + USBSTOR USB Mass Storage Class Driver Microsoft Corporation c:\windows\system32\drivers\usbstor.sys

    + usbuhci UHCI USB Miniport Driver Microsoft Corporation c:\windows\system32\drivers\usbuhci.sys
     
  2. 2006/12/07
    Cael Weston

    Cael Weston Inactive Thread Starter

    Joined:
    2006/12/02
    Messages:
    36
    Likes Received:
    0
    autoruns log 3 of 3

    + VgaSave VGA/Super VGA Video Driver Microsoft Corporation c:\windows\system32\drivers\vga.sys

    + Wanarp Remote Access IP ARP Driver Microsoft Corporation c:\windows\system32\drivers\wanarp.sys

    + wanatw Wan Miniport (ATW) America Online, Inc. c:\windows\system32\drivers\wanatw4.sys

    + wceusbsh Windows CE USB Serial Host Microsoft Corporation c:\windows\system32\drivers\wceusbsh.sys

    + wdmaud MMSYSTEM Wave/Midi API mapper Microsoft Corporation c:\windows\system32\drivers\wdmaud.sys

    + winachsf WinACHSF driver Conexant Systems c:\windows\system32\drivers\hsf_cnxt.sys

    + WpdUsb WPD USB Driver Microsoft Corporation c:\windows\system32\drivers\wpdusb.sys

    + {6080A529-897E-4629-A488-ABA0C29B635E} Intel Graphics Platform (SoftBIOS) Driver for Windows 2000(R) & Windows XP(TM) Intel Corporation c:\windows\system32\drivers\ialmsbw.sys

    + {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} Intel Graphics Chipset (KCH) Driver for Windows 2000(R) & Windows XP(TM) Intel Corporation c:\windows\system32\drivers\ialmkchw.sys

    HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

    + autocheck autochk * Auto Check Utility Microsoft Corporation c:\windows\system32\autochk.exe

    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

    + Your Image File Name Here without a path Symbolic Debugger for Windows 2000 Microsoft Corporation c:\windows\system32\ntsd.exe

    HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls

    + advapi32 Advanced Windows 32 Base API Microsoft Corporation c:\windows\system32\advapi32.dll

    + comdlg32 Common Dialogs DLL Microsoft Corporation c:\windows\system32\comdlg32.dll

    + gdi32 GDI Client DLL Microsoft Corporation c:\windows\system32\gdi32.dll

    + imagehlp Windows NT Image Helper Microsoft Corporation c:\windows\system32\imagehlp.dll

    + kernel32 Windows NT BASE API Client DLL Microsoft Corporation c:\windows\system32\kernel32.dll

    + lz32 LZ Expand/Compress API DLL Microsoft Corporation c:\windows\system32\lz32.dll

    + ole32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\ole32.dll

    + oleaut32 Microsoft OLE 3.50 for Windows NT(TM) and Windows 95(TM) Operating Systems Microsoft Corporation c:\windows\system32\oleaut32.dll

    + olecli32 Object Linking and Embedding Client Library Microsoft Corporation c:\windows\system32\olecli32.dll

    + olecnv32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olecnv32.dll

    + olesvr32 Object Linking and Embedding Server Library Microsoft Corporation c:\windows\system32\olesvr32.dll

    + olethk32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olethk32.dll

    + rpcrt4 Remote Procedure Call Runtime Microsoft Corporation c:\windows\system32\rpcrt4.dll

    + shell32 Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

    + url Internet Shortcut Shell Extension DLL Microsoft Corporation c:\windows\system32\url.dll

    + urlmon OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

    + user32 Windows XP USER API Client DLL Microsoft Corporation c:\windows\system32\user32.dll

    + version Version Checking and File Installation Libraries Microsoft Corporation c:\windows\system32\version.dll

    + wininet Internet Extensions for Win32 Microsoft Corporation c:\windows\system32\wininet.dll

    + wldap32 Win32 LDAP API DLL Microsoft Corporation c:\windows\system32\wldap32.dll

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost

    + logonui.exe Windows Logon UI Microsoft Corporation c:\windows\system32\logonui.exe

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

    + crypt32chain Crypto API32 Microsoft Corporation c:\windows\system32\crypt32.dll

    + cryptnet Crypto Network Related API Microsoft Corporation c:\windows\system32\cryptnet.dll

    + cscdll Offline Network Agent Microsoft Corporation c:\windows\system32\cscdll.dll

    + igfxcui igfxsrvc Module Intel Corporation c:\windows\system32\igfxsrvc.dll

    + ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

    + Schedule Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

    + sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation c:\windows\system32\sclgntfy.dll

    + SensLogn Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

    + termsrv Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

    + wlballoon Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

    HKCU\Control Panel\Desktop\Scrnsave.exe

    + C:\WINDOWS\System32\logon.scr Logon Screen Saver Microsoft Corporation c:\windows\system32\logon.scr

    HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{17903BE2-EA42-41B8-9DED-E893DC413AC5}] DATAGRAM 8 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{17903BE2-EA42-41B8-9DED-E893DC413AC5}] SEQPACKET 8 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{20AB84D8-8C64-4975-9AE5-A209CBD1946D}] DATAGRAM 9 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{20AB84D8-8C64-4975-9AE5-A209CBD1946D}] SEQPACKET 9 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{35F9485E-7D9C-41B6-80DB-6039E0208C50}] DATAGRAM 7 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{35F9485E-7D9C-41B6-80DB-6039E0208C50}] SEQPACKET 7 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{3CC2C5ED-0ABF-4CA9-86B4-B2618EF96664}] DATAGRAM 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{3CC2C5ED-0ABF-4CA9-86B4-B2618EF96664}] SEQPACKET 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{44016688-B966-458D-BBAA-B29FC516C8E1}] DATAGRAM 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{44016688-B966-458D-BBAA-B29FC516C8E1}] SEQPACKET 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{54E2847D-B911-403E-A79C-BD1B86040684}] DATAGRAM 10 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{54E2847D-B911-403E-A79C-BD1B86040684}] SEQPACKET 10 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}] DATAGRAM 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}] SEQPACKET 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{865E2FAE-36F8-401B-9D0E-9026EBF4DEB5}] DATAGRAM 5 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{865E2FAE-36F8-401B-9D0E-9026EBF4DEB5}] SEQPACKET 5 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{96D0A431-9C5D-4C2A-8ACD-5FFE16F50914}] DATAGRAM 6 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{96D0A431-9C5D-4C2A-8ACD-5FFE16F50914}] SEQPACKET 6 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{9B110AA9-4CDA-4C22-BCB8-194204A0F2CE}] DATAGRAM 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{9B110AA9-4CDA-4C22-BCB8-194204A0F2CE}] SEQPACKET 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{E5EC0A67-7EEA-48D6-BF30-90F5C13ABCA3}] DATAGRAM 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD NetBIOS [\Device\NetBT_Tcpip_{E5EC0A67-7EEA-48D6-BF30-90F5C13ABCA3}] SEQPACKET 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD Tcpip [RAW/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD Tcpip [TCP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + MSAFD Tcpip [UDP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

    + RSVP TCP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp.dll

    + RSVP UDP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp.dll

    HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

    + BJ Language Monitor Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation c:\windows\system32\cnbjmon.dll

    + Dell 962 Port Dell Communication System Dell c:\windows\system32\dlbxlmpm.dll

    + Dell Network Port LEXLMPM DLL Lexmark International, Inc. c:\windows\system32\lexlmpm.dll

    + Fax Monitor Port Fax Monitor DLL Microsoft Corporation c:\windows\system32\imgfx5mn.dll

    + Lexmark Network Port LEXLMPM DLL Lexmark International, Inc. c:\windows\system32\lexlmpm.dll

    + Local Port Local Spooler DLL Microsoft Corporation c:\windows\system32\localspl.dll

    + PJL Language Monitor PJL Language monitor Microsoft Corporation c:\windows\system32\pjlmon.dll

    + Standard TCP/IP Port Standard TCP/IP Port Monitor DLL Microsoft Corporation c:\windows\system32\tcpmon.dll

    + USB Monitor Standard Dynamic Printing Port Monitor DLL Microsoft Corporation c:\windows\system32\usbmon.dll

    HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders

    + digest.dll Digest SSPI Authentication Package Microsoft Corporation c:\windows\system32\digest.dll

    + msapsspc.dll DPA Client for 32 bit platforms Microsoft Corporation c:\windows\system32\msapsspc.dll

    + msnsspc.dll MSN Internet Access Microsoft Corporation c:\windows\system32\msnsspc.dll

    + schannel.dll TLS / SSL Security Provider Microsoft Corporation c:\windows\system32\schannel.dll

    HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages

    + msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation c:\windows\system32\msv1_0.dll

    HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages

    + scecli Windows Security Configuration Editor Client Engine Microsoft Corporation c:\windows\system32\scecli.dll

    HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages

    + kerberos Kerberos Security Package Microsoft Corporation c:\windows\system32\kerberos.dll

    + msv1_0 Microsoft Authentication Package v1.0 Microsoft Corporation c:\windows\system32\msv1_0.dll

    + schannel TLS / SSL Security Provider Microsoft Corporation c:\windows\system32\schannel.dll

    + wdigest Microsoft Digest Access Microsoft Corporation c:\windows\system32\wdigest.dll
     

  3. to hide this advert.

  4. 2006/12/07
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    OK, I'm seeing some Look2Me files, lets see what the special tool finds.


    Please download Look2Me-Destroyer.exe to your desktop.
    • Close all windows before continuing.
    • Double-click Look2Me-Destroyer.exe to run it.
    • Put a check next to Run this program as a task.
    • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
    • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
    • Once it's done scanning, click the Remove L2M button.
    • You will receive a Done Scanning message, click OK.
    • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
    • Your computer will then shutdown.
    • Turn your computer back on.
    • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
    If you receive a message from your firewall about this program accessing the internet please allow it.

    If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
    http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
     
  5. 2006/12/07
    Cael Weston

    Cael Weston Inactive Thread Starter

    Joined:
    2006/12/02
    Messages:
    36
    Likes Received:
    0
    logs

    Look2Me-Destroyer V1.0.12

    Scanning for infected files.....
    Scan started at 06-12-07 14:08:14


    Attempting to delete infected files...

    Making registry repairs.


    Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{273F07C0-CA03-41ED-9100-95593FF3FEF3} "
    HKCR\Clsid\{273F07C0-CA03-41ED-9100-95593FF3FEF3}

    Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B9ED2281-D7DE-4238-81CB-698ED6DB976C} "
    HKCR\Clsid\{B9ED2281-D7DE-4238-81CB-698ED6DB976C}

    Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{7B1C64A7-67AD-4560-B768-3A34E220FE5D} "
    HKCR\Clsid\{7B1C64A7-67AD-4560-B768-3A34E220FE5D}

    Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{C2982F74-9A2F-4200-B233-1D8AD12D94FF} "
    HKCR\Clsid\{C2982F74-9A2F-4200-B233-1D8AD12D94FF}

    Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{3A590FD5-712F-4BE6-AA14-8C2D3B2BAE00} "
    HKCR\Clsid\{3A590FD5-712F-4BE6-AA14-8C2D3B2BAE00}

    Restoring Windows certificates.

    Replaced hosts file with default windows hosts file


    Restoring SeDebugPrivilege for Administrators - Succeeded




    Logfile of HijackThis v1.99.1
    Scan saved at 14:37, on 06-12-07
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Broderbund\Mavis Beacon Teaches Typing Deluxe 15\minimavis.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Windows Live Toolbar\msn_sl.exe
    C:\Program Files\hijackthis\MommyThis.exe

    F1 - win.ini: load=c:\01comm32\bin\01comm32.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
    O4 - Global Startup: Personal Coach.lnk = ?
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?754580c39df648e79f4e5a5b6c4f9b83
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?754580c39df648e79f4e5a5b6c4f9b83
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo.com/applet-5.9.2.21/holdem/holdem-ob-assets.cab
    O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.1.1067.14/WinSSWebAgent.CAB
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,73/mcinsctl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1164933618296
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: dlbx_device - Dell - C:\WINDOWS\System32\dlbxcoms.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: PACSPTISVR - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

    Thanks.

    Cael
     
  6. 2006/12/07
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Ok, we need to kill a few files off.

    Download the Killbox from here and save it to the desktop.
    • Double-click the KillBox icon on your desktop to open it
    • Select "Delete on Reboot "
    • Then select "All files ".
    Copy the file names below to the clipboard by highlighting them and pressing Control-C:
    C:\WINDOWS\System32\bqbocqm.exe
    C:\WINDOWS\system32\ALCUPS.DLL
    C:\WINDOWS\system32\der6019se.dll
    C:\WINDOWS\system32\guard.tmp
    C:\WINDOWS\system32\mdorcl32.dll


    Return to Killbox
    • Go to the File menu, and choose "Paste from Clipboard ".
    • Click the red-and-white [Delete File] button.
    • Click "Yes" at the Delete on Reboot prompt. Click "No" at the Delete next Reboot prompt.

    Reboot the system, run AutoRuns again, but this time, once it has scanned go to the tool bar and select the 'Options' tab, and then from the drop down menu, ckeck the 'Hide Microsoft Entries' option, then copy what is remaining for me to see. That will give me considerably less to view.
     
  7. 2006/12/08
    Cael Weston

    Cael Weston Inactive Thread Starter

    Joined:
    2006/12/02
    Messages:
    36
    Likes Received:
    0
    killbox question

    Instead of rebooting, killbox gives this error: "PendingFileRenameOperations Registry Data has been removed by external process! "

    I will try rebooting manually, anyway, and checking to see if the files were deleted.

    Cael
     
  8. 2006/12/08
    Cael Weston

    Cael Weston Inactive Thread Starter

    Joined:
    2006/12/02
    Messages:
    36
    Likes Received:
    0
    reboot and new HJT log

    I tried searching for the files you mentioned and couldn't find them on my machine. Then I loaded them one at a time into killbox and always got the same message mentioned above.

    Then I rebooted, and generated a new hjt.

    By the way, the cpu is running great, and I left it on overnight and when I arrived this morning there were no adware windows open!

    Thanks. Also, I wanted to remove all instant message programs. I noticed in the hjt logs that remnants remain. I also want to get rid of all AOL, and Yahoo files. They've been removed as applications, but, again, I see remnant files in the hjt logs. Is this worth going after?

    Cael

    Logfile of HijackThis v1.99.1
    Scan saved at 10:06, on 06-12-08
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Broderbund\Mavis Beacon Teaches Typing Deluxe 15\minimavis.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\hijackthis\MommyThis.exe

    F1 - win.ini: load=c:\01comm32\bin\01comm32.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
    O4 - Global Startup: Personal Coach.lnk = ?
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?754580c39df648e79f4e5a5b6c4f9b83
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?754580c39df648e79f4e5a5b6c4f9b83
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo.com/applet-5.9.2.21/holdem/holdem-ob-assets.cab
    O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.1.1067.14/WinSSWebAgent.CAB
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,73/mcinsctl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1164933618296
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: dlbx_device - Dell - C:\WINDOWS\System32\dlbxcoms.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: PACSPTISVR - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
     
  9. 2006/12/08
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Everything looks good and I'm glad to hear your machine is running smoothly.

    You can fix all the items below related to any IM apps:
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet


    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE


    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab

    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab47946.cab


    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL


    ***WARNING!!:OK, now that you're all cleaned up, we need to get you properly updated over at MS. You only have XP SP1 installed, so you sre at risk with every click you take.

    So as soon as you finish reading this, hit windows update then go and get some protection, especially in the form of anti-virus and firewall. XP SP2 firewall is not enough.

    Here are a couple of recommendations for av and firewalls:
    Antivirus:Firewalls:All are free too, can't beat that with a stick

    Then, my regular recommendations for continued secure, safe surfing.

    We have 3 more things to do, mostly maintenance and then our recommendations:

    Empty the TIF (Temporary Internet Files)
    Delete all the files in (and any subfolders of) the C:\Windows\Temp folder
    The app below will help with temp files.
    Index.dat Suite

    Also, delete all your cookies, and empty your recycle bin. But remember, by deleting your cookies, you will have to re-enter any passwords and log-in info for any sites you are usually required to do so with.

    This would also be a good time to set a new system restore point for your machine.
    Set New System Restore Point. Do not do this unless there are no other user accounts to be diagnosed.

    Also, as you are an XP user, if there are any other accounts on this machine, they too, must be cleaned with AdAware, Spybot S&D, then HJT. Not all infections are global, nor are all the HJT fixes global. You can post each user account here into this thread, but please, do only one at a time to avoid confusion.

    Here is a link which describes how security apps work with WIN XP machines.
    XP User Accts Security Apps Operation

    To further prevent the installation of ad/mal/spyware, DL the apps below, which are just as good the fight against ad/mal/spyware as AdAware & Spybot S&D:

    SpywareBlaster
    With SpywareBlaster v3.5.1 , just DL, install and check for updates, enable Internet Explorer protection, and your done! I don't recommend using IE restricted sites protection as it's not a very large database. Use IE-SPYADs below.

    To avoid known malware infested sites from loading in IE install IESPY ADS.
    And MVPS Hosts File will accomplish a similar tactic and provide another layer of protection.

    And to prevent unknown applications from being inserted to start up on your machine install WinPatrol v10.0.5.

    Another thing I would suggest, is to install SiteAdvisor. It gives sites a few different 'ratings' and while not fool proof, a good additional layer of information about many sites.

    Links for tutorials for all the apps I mentioned can be found on my site as well.

    Confused about which apps are good or not? Read about Rogue/Approved Anti Security apps

    And just because you have security apps installed, they are useless unless updated regularly. Keep track of updates for ALL your security needs here:
    Calendar of Updates

    Subscribe to update alerts for all the above security apps here.

    You can also see my own ongoing security testing with all the above apps proving how securely you can safe with them installed.
    TeMerc Test Box Forum

    Happy surfing!!
    Tom :D
     
  10. 2006/12/08
    Cael Weston

    Cael Weston Inactive Thread Starter

    Joined:
    2006/12/02
    Messages:
    36
    Likes Received:
    0
    thanks

    I can't thank you enough, Tom.

    Cael
     
  11. 2006/12/08
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Glad we could be of assistance.

    Due to resolution this topic is closed.

    If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.