Help - Search - Members - Calendar
Full Version: help me plz
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
bylanta
I have recently run into a couple virus/trojans that won't seem to go away. starring: PSW.Banker3.SXK and
including:worm/vb.ayf
trojan horse SHeur.BOZ
obfustat.HM
here is my HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:54 AM, on 7/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ZyXEL\G-302v3\G-302v3.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\YPOPs\ypops.exe
C:\Program Files\Poker Indicator\PokerIndicator.exe
C:\Program Files\Poker-Spy\Poker-Spy.exe
C:\Program Files\PokerStars\PokerStars.exe
C:\Program Files\PokerStars\PokerStarsCommunicate.exe
C:\Program Files\Poker Indicator\piexec.exe
C:\Program Files\Poker Indicator\PokerIndicator.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZyXEL G-302 v3 Utility.lnk = C:\Program Files\ZyXEL\G-302v3\G-302v3.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{17043109-CFB1-4635-B82C-FAA39D24F316}: NameServer = 68.87.76.178,66.87.66.196
O17 - HKLM\System\CS1\Services\Tcpip\..\{17043109-CFB1-4635-B82C-FAA39D24F316}: NameServer = 68.87.76.178,66.87.66.196
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe

--
End of file - 10758 bytes
LoPhatPhuud
Your HJT log is clean. What are the file names and where are they located?

Please download SilentRunners from here:
http://www.silentrunners.org/Silent%20Runners.zip

Unzip it to the desktop and double-click on it.
Silent Runners will ask if you want to skip the supplementary search.
Please select 'No' to include them.

The program will take longer to run, but will give us more information.

If you get any kind of warning message about scripts, please choose to allow the script to run.

When the scan is finished, a message will pop up and a logfile will have been created on the desktop.
The logfile is named 'Startup Programs' by default and will be located where the program is.

Please post the entire contents of this logfile for me to see.
bylanta
here is the virus found and file name and location you requested.
"" "" "Trojan horse PSW.Banker3.SXK" "C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP402\A0060279.exe" "7/25/2007 5:33:33 PM" "A0060279.exe" "12.5 KB"
"" "" "Trojan horse PSW.Banker3.SXK" "C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP402\A0060278.exe" "7/24/2007 5:34:24 PM" "A0060278.exe" "12.5 KB"
"" "" "Trojan horse PSW.Banker3.SXK" "C:\Program Files\Poker Indicator\Poker Indicator 1.7.0\Patch\PokerIndicatorv170_- Read our board rules -.exe" "7/23/2007 8:44:23 AM" "PokerIndicatorv170_- Read our board rules -.exe" "12.5 KB"
"" "" "Trojan horse PSW.Banker3.SXK" "C:\Program Files\Poker Indicator\PokerIndicatorv170_- Read our board rules -.exe" "7/23/2007 8:44:23 AM" "PokerIndicatorv170_- Read our board rules -.exe" "12.5 KB"
"" "" "Trojan horse PSW.Banker3.SXK" "C:\Program Files\Poker Indicator\PokerIndicatorv169_- Read our board rules -.exe" "7/23/2007 8:44:23 AM" "PokerIndicatorv169_- Read our board rules -.exe" "13 KB"
"" "" "Trojan horse PSW.Banker3.SXK" "C:\Program Files\Poker Indicator\PokerIndicatorv162_- Read our board rules -.exe" "7/23/2007 8:44:23 AM" "PokerIndicatorv162_- Read our board rules -.exe" "12.5 KB"
"" "" "Trojan horse PSW.Banker3.SXK" "C:\Program Files\Poker Indicator\PokerIndicatorv154_- Read our board rules -.exe" "7/23/2007 8:44:23 AM" "PokerIndicatorv154_- Read our board rules -.exe" "12.5 KB"
"" "" "Trojan horse PSW.Banker3.SXK" "C:\Program Files\Common Files\system32\Global Poker Center 2007\install\Docs\PokerIndicatorv170_- Read our board rules -.exe" "7/23/2007 8:44:22 AM" "PokerIndicatorv170_- Read our board rules -.exe" "12.5 KB"
"" "" "Virus identified Obfustat.HM" "C:\Program Files\BitComet\Downloads\180 Portable Progs - GIGA Collection [MUST HAVE]\Portable Partition_Magic v8.05\Portable Partition Magic v8.05.exe" "7/21/2007 11:44:51 PM" "Portable Partition Magic v8.05.exe" "8.38 MB"
"" "" "Trojan horse SHeur.BOZ" "C:\DOCUME~1\ROADDO~1\LOCALS~1\Temp\IXP000.TMP\Win.exe" "7/21/2007 11:27:59 PM" "Win.exe" "179.5 KB"
"" "" "Trojan horse SHeur.BOZ" "C:\DOCUME~1\ROADDO~1\LOCALS~1\Temp\IXP000.TMP\Win.exe" "7/21/2007 11:27:47 PM" "Win.exe" "179.5 KB"
"" "" "Virus identified Worm/VB.AYF" "D:\HOODLUM\hoodlum.exe" "7/20/2007 9:26:21 PM" "hoodlum.exe" "169.5 KB"
"" "" "Virus identified Worm/VB.AYF" "D:\HOODLUM\hoodlum.exe" "7/20/2007 9:17:24 PM" "hoodlum.exe" "169.5 KB"
"" "" "Virus identified Worm/VB.AYF" "D:\HOODLUM\hoodlum.exe" "7/20/2007 9:17:22 PM" "hoodlum.exe" "169.5 KB"
"" "" "Virus identified Worm/VB.AYF" "D:\HOODLUM\hoodlum.exe" "7/20/2007 9:17:18 PM" "hoodlum.exe" "169.5 KB"
"" "" "Virus identified Worm/VB.AYF" "D:\HOODLUM\hoodlum.exe" "7/20/2007 9:16:38 PM" "hoodlum.exe" "169.5 KB"
"" "" "Virus identified Worm/VB.AYF" "D:\HOODLUM\hoodlum.exe" "7/20/2007 9:12:58 PM" "hoodlum.exe" "169.5 KB"
bylanta
the silent runners log

"Silent Runners.vbs", revision R51, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"TivoTransfer" = ""C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer" ["TiVo Inc."]
"TivoNotify" = ""C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify" ["TiVo Inc."]
"TivoServer" = ""C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry" ["TiVo Inc."]
"swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" ["Google Inc."]
"RoboForm" = ""C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"" ["Siber Systems"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]
"nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
"NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit" [MS]
"DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
"SmcService" = "C:\PROGRA~1\Sygate\SPF\smc.exe -startgui" ["Sygate Technologies, Inc."]
"CanonMyPrinter" = "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon" ["CANON INC."]
"SSBkgdUpdate" = ""C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot" ["Scansoft, Inc."]
"OpwareSE4" = ""C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"" ["ScanSoft, Inc."]
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["GRISOFT s.r.o."]
"KernelFaultCheck" = "C:\WINDOWS\system32\dumprep 0 -k"

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]
{5CA3D70E-1895-11CF-8E15-001234567890}\(Default) = (no title provided)
-> {HKLM...CLSID} = "DriveLetterAccess"
\InProcServer32\(Default) = "C:\WINDOWS\System32\DLA\DLASHX_W.DLL" ["Sonic Solutions"]
{68F9551E-0411-48E4-9AAF-4BC42A6A46BE}\(Default) = "Canon Easy Web Print Helper"
-> {HKLM...CLSID} = "EWPBrowseObject Class"
\InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll" [null data]
{724d43a9-0d85-11d4-9908-00400523e39a}\(Default) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Siber Systems\AI RoboForm\roboform.dll" ["Siber Systems"]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
-> {HKLM...CLSID} = "SSVHelper Class"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar5.dll" ["Google Inc."]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Notifier BHO"
\InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll" ["Google Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM...CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {HKLM...CLSID} = "Portable Media Devices Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{5CA3D70E-1895-11CF-8E15-001234567890}" = "DriveLetterAccess"
-> {HKLM...CLSID} = "DriveLetterAccess"
\InProcServer32\(Default) = "C:\WINDOWS\System32\DLA\DLASHX_W.DLL" ["Sonic Solutions"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{0561EC90-CE54-4f0c-9C55-E226110A740C}" = "Haali Column Provider"
-> {HKLM...CLSID} = "Haali Column Provider"
\InProcServer32\(Default) = "C:\Program Files\Avi2Dvd\Programs\Filters\Haali media splitter\mmfinfo.dll" [null data]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> {HKLM...CLSID} = "DesktopContext Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> {HKLM...CLSID} = "NVIDIA CPL Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> {HKLM...CLSID} = "Desktop Explorer"
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
-> {HKLM...CLSID} = "nView Desktop Context Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> {HKLM...CLSID} = "AVG7 Shell Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> {HKLM...CLSID} = "AVG7 Find Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
<<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
-> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["GRISOFT s.r.o."]
<<!>> "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" = (no title provided)
-> {HKLM...CLSID} = "SABShellExecuteHook Class"
\InProcServer32\(Default) = "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" ["SuperAdBlocker.com"]

HKLM\System\CurrentControlSet\Control\Session Manager\
<<!>> "BootExecute" = "autocheck autochk *"|"lsdelete" [null data]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> !SASWinLogon\DLLName = "C:\Program Files\SUPERAntiSpyware\SASWINLO.dll" ["SUPERAntiSpyware.com"]
<<!>> igfxcui\DLLName = "igfxdev.dll" ["Intel Corporation"]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{0561EC90-CE54-4f0c-9C55-E226110A740C}\(Default) = "Haali Column Provider"
-> {HKLM...CLSID} = "Haali Column Provider"
\InProcServer32\(Default) = "C:\Program Files\Avi2Dvd\Programs\Filters\Haali media splitter\mmfinfo.dll" [null data]
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM...CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["GRISOFT s.r.o."]
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {HKLM...CLSID} = "AVG7 Shell Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
-> {HKLM...CLSID} = "CContextScan Object"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["GRISOFT s.r.o."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {HKLM...CLSID} = "AVG7 Shell Extension Class"
\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\

"Mn@iboddPubswLfov" = (REG_DWORD) hex:0x00000000
{unrecognized setting}

"Mn@mlrf" = (REG_DWORD) hex:0x00000000
{unrecognized setting}

"MnOndNeg" = (REG_DWORD) hex:0x00000000
{unrecognized setting}

"MnQtm" = (REG_DWORD) hex:0x00000000
{unrecognized setting}

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\

"NoCDBurning" = (REG_DWORD) hex:0x00000000
{unrecognized setting}

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"Ghp`amfUbrhLds" = (REG_DWORD) hex:0x00000000
{unrecognized setting}

"DisableRegistryTools" = (REG_DWORD) hex:0x00000000
{Prevent access to registry editing tools}

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "\\Roaddog\storage (E)\Setups\digitalblasphemy_wallpapers\daybreak1600.jpg"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Road Dog\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\system32\scrnsave.scr" [MS]


Startup items in "Road Dog" & "All Users" startup folders:
----------------------------------------------------------

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Digital Line Detect" -> shortcut to: "C:\Program Files\Digital Line Detect\DLG.exe" ["BVRP Software"]
"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]
"ZyXEL G-302 v3 Utility" -> shortcut to: "C:\Program Files\ZyXEL\G-302v3\G-302v3.exe /H" [null data]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 13
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {HKLM...CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar5.dll" ["Google Inc."]
"{724D43A0-0D85-11D4-9908-00400523E39A}"
-> {HKLM...CLSID} = "&RoboForm"
\InProcServer32\(Default) = "C:\Program Files\Siber Systems\AI RoboForm\roboform.dll" ["Siber Systems"]

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {HKLM...CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar5.dll" ["Google Inc."]
"{724D43A0-0D85-11D4-9908-00400523E39A}"
-> {HKLM...CLSID} = "&RoboForm"
\InProcServer32\(Default) = "C:\Program Files\Siber Systems\AI RoboForm\roboform.dll" ["Siber Systems"]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"
-> {HKLM...CLSID} = "Easy-WebPrint"
\InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
-> {HKLM...CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar5.dll" ["Google Inc."]
"{724D43A0-0D85-11D4-9908-00400523E39A}" = (no title provided)
-> {HKLM...CLSID} = "&RoboForm"
\InProcServer32\(Default) = "C:\Program Files\Siber Systems\AI RoboForm\roboform.dll" ["Siber Systems"]

Explorer Bars

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Real.com"
\InProcServer32\(Default) = "C:\WINDOWS\system32\Shdocvw.dll" [MS]

HKLM\Software\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\(Default) = "Easy-WebPrint"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"
-> {HKCU...CLSID} = "Java Plug-in"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
-> {HKLM...CLSID} = "Java Plug-in 1.5.0_06"
\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."]

{320AF880-6646-11D3-ABEE-C5DBF3571F46}\
"ButtonText" = "Fill Forms"
"MenuText" = "Fill Forms"
"Script" = "file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html" [file not found]

{320AF880-6646-11D3-ABEE-C5DBF3571F49}\
"ButtonText" = "Save"
"MenuText" = "Save Forms"
"Script" = "file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html" [file not found]

{724D43AA-0D85-11D4-9908-00400523E39A}\
"ButtonText" = "RoboForm"
"MenuText" = "RoboForm Toolbar"
"Script" = "file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html" [file not found]

{AC9E2541-2814-11D5-BC6D-00B0D0A1DE45}\
"ButtonText" = "AIM"
"Exec" = "C:\Program Files\AIM\aim.exe" ["America Online, Inc."]

{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\
"ButtonText" = "Real.com"

{F47C1DB5-ED21-4DC1-853E-D1495792D4C5}\
"ButtonText" = "Bodog Poker"
"Exec" = "C:\Program Files\Bodog Poker\BPGame.exe" ["Bodog"]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ad-Aware 2007 Service, aawservice, ""C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe"" ["Lavasoft AB"]
AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["GRISOFT s.r.o."]
AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" ["GRISOFT, s.r.o."]
AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" ["GRISOFT, s.r.o."]
NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"]
Sygate Personal Firewall Pro, SmcService, "C:\Program Files\Sygate\SPF\smc.exe" ["Sygate Technologies, Inc."]
Symantec Core LC, Symantec Core LC, ""C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe"" ["Symantec Corporation"]
TiVo Beacon, TivoBeacon2, ""C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe" /service" ["TiVo Inc."]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
Canon BJ Language Monitor MP160\Driver = "CNMLM83.DLL" ["CANON INC."]
Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]


---------- (launch time: 2007-07-26 14:05:31)
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 154 seconds.
---------- (total run time: 205 seconds)



thanks for your help so far it is much appreciated.
LoPhatPhuud
The info you posted shows three programs as being infected:
Poker Indicator
HOODLUM
Portable Partition_Magic v8.05

Use Add/Remove Programs and uninstall each one. Then make sure any remaining folder is deleted. The detect may be a false positive but it is better to err on the side of safety.

The first two you listed are in the System Restore area and you will need to reset it to remove them.

Now that your PC is clean, make sure all programs are running properly and then you'll need to reset your restore point in Windows XP.......why?

One of the best features of Windows XP is the System Restore option, however if a virus infects a computer with this operating system the virus can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after a virus removal.

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(Windows XP)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

How to Turn On and Turn Off System Restore in Windows XP
http://support.microsoft.com/default.aspx?...kb;en-us;310405

Next, we highly recommend you get some extra protection to prevent future infections. Here are some things you can do and some free programs to help

How to Stop Hijackers & Spyware Infections, And other malware too!
http://forum.gladiator-antivirus.com/index...?showtopic=9857
bylanta
I tried what you suggested and my computer came up clean on a virus sweep, but then it later detects another one.
today it is spybot.aul in a system restore file.
LoPhatPhuud
Files in the System Restore area shoudl be removed by resetting System Restore. This will erase all current restore points and you will need to create a new one after turning System Restore bck on.


Now that your PC is clean, make sure all programs are running properly and then you'll need to reset your restore point in Windows XP.......why?

One of the best features of Windows XP is the System Restore option, however if a virus infects a computer with this operating system the virus can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after a virus removal.

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(Windows XP)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

How to Turn On and Turn Off System Restore in Windows XP
http://support.microsoft.com/default.aspx?...kb;en-us;310405

Next, we highly recommend you get some extra protection to prevent future infections. Here are some things you can do and some free programs to help

How to Stop Hijackers & Spyware Infections, And other malware too!
http://forum.gladiator-antivirus.com/index...?showtopic=9857
bylanta
That is what I am saying though, I have done the turn system restore on/off step and then I scan and it is clean, but in the next day or two this same virus will pop up.
LoPhatPhuud
Then the infected files are on your computer before they get to restore. Have any programs detected them? If a program detects a file in the restore area, I would expect it to detect that same file before it get to the restore file.

Do a full system scan, including archives as follows:

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      Extended (if available otherwise Standard)
    • Scan Options:
      Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
      Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
bylanta
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, August 02, 2007 1:13:07 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 2/08/2007
Kaspersky Anti-Virus database records: 370729
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 98904
Number of viruses found: 3
Number of infected objects: 4
Number of suspicious objects: 0
Duration of the scan process: 01:46:03

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1AA029FE.tmp Infected: Trojan.Win32.KillAV.is skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1AA353FB.tmp Infected: Trojan.Win32.KillAV.is skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30E027A7.exe Infected: Backdoor.Win32.VB.ate skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6CA877F0.exe Infected: Backdoor.Win32.Agent.abc skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Road Dog\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Road Dog\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Road Dog\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Road Dog\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Road Dog\Local Settings\Temp\~DF28F.tmp Object is locked skipped
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Road Dog\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Road Dog\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Sygate\SPF\debug.log Object is locked skipped
C:\Program Files\Sygate\SPF\rawlog.log Object is locked skipped
C:\Program Files\Sygate\SPF\seclog.log Object is locked skipped
C:\Program Files\Sygate\SPF\syslog.log Object is locked skipped
C:\Program Files\Sygate\SPF\tralog.log Object is locked skipped
C:\Program Files\YPOPs\ypops.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\RTacDbg.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.



thx again!
LoPhatPhuud
Interesting. You have items in a stranded Norton quarantine folder. THey are safe, but still, the Norton/Symatnec leftovers need to be removed. Use this: http://service1.symantec.com/SUPPORT/tsgen...v=&osv_lvl=


Then do a full scan with AVG. Also check the AVG support site for recent false positives.
bylanta
Ran the norton and then the AVG and it came up clean. I searched around but I could not find a good list of false positives, and I have already individually searched for the virus names I had. I'll post back again in a few days with hopefully a clear cpu. Thanks again for your help, most appreciated.
bylanta
avg isn't finding anything still, but i have very little faith that I am actually virus free right now. ESPN.com won't even load right, and that is my homepage. My bandwidth feels stunted as well, do you have any other ideas I can try?
LoPhatPhuud
Clean the temp files and folders (info follows) and then check for rootkits (info for that follows too)


First:
Download and scan with CCleaner
1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.

2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

3. Then select the items you wish to clean up.

In the Windows Tab:
• Clean all entries in the "Internet Explorer" section except Cookies.
• Clean all the entries in the "Windows Explorer" section.
• Clean all entries in the "System" section.
• Clean all entries in the "Advanced" section.
• Clean any others that you choose.


In the Applications Tab:
• Clean all except cookies in the Firefox/Mozilla section if you use it.
• Clean all in the Opera section if you use it.
• Clean Sun Java in the Internet Section.
• Clean any others that you choose.

4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.


Second:
Please download RootKitRevealer from here:
http://www.sysinternals.com/files/rootkitrevealer.zip
Unzip it to the desktop, run it, and click Scan. This will generate a log file; please post the entire contents of the log file here for me to see.
bylanta
I ran the CCleaner and the rootkit revealer link didn't work for me so i got it elsewhere. When I went to save the log on the desktop the program crashed. So i don't have the original log, and it doesnt seem to want to save them. This is the best I could come up with right here.

HKLM\SOFTWARE\Classes\webcal\URL Protocol 4/18/2006 5:10 PM 13 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf40 8/6/2007 12:15 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf41 8/6/2007 12:15 AM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\d347prt\Cfg\0Jf42 8/6/2007 12:15 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Application Data\Macromedia\Flash Player\#SharedObjects 8/6/2007 12:36 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Application Data\Macromedia\Flash Player\#SharedObjects\J48HRSGX 8/6/2007 12:36 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Application Data\Macromedia\Flash Player\macromedia.com 8/6/2007 12:36 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Application Data\Macromedia\Flash Player\macromedia.com\support 8/6/2007 12:36 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer 8/6/2007 12:36 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys 8/6/2007 12:36 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 8/6/2007 12:36 AM 348 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Cookies\road dog@ad.yieldmanager[1].txt 8/6/2007 12:36 AM 553 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Cookies\road dog@ad.yieldmanager[2].txt 8/6/2007 12:30 AM 533 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Cookies\road dog@clicktorrent[1].txt 8/3/2007 2:53 PM 1.69 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Cookies\road dog@clicktorrent[2].txt 8/6/2007 12:36 AM 1.75 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Cookies\road dog@imdb[2].txt 8/6/2007 12:37 AM 514 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Cookies\road dog@www.imdb[1].txt 8/6/2007 12:37 AM 80 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\Oldboy.DVDRip.by-PLuS-[www.emwreloaded.com]\Thumbs.db 8/6/2007 12:39 AM 5.50 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\Oldboy.DVDRip.by-PLuS-[www.emwreloaded.com]\Thumbs.db:encryptable 8/6/2007 12:39 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice 8/6/2007 12:43 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E01.DSR.XviD-NoTV 8/6/2007 12:42 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV 8/6/2007 12:43 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.nfo 8/6/2007 12:43 AM 8.85 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part01.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part02.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part03.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part04.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part05.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part06.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part07.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part08.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part09.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part10.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part11.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part12.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part13.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part14.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part15.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part16.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part17.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part18.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part19.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part20.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part21.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part22.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part23.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part24.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part25.rar 8/6/2007 12:43 AM 6.77 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.sfv 8/6/2007 12:43 AM 1.25 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\Sample 8/3/2007 3:47 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E03.DSR.XviD-NoTV\Sample\burn.notice.103.dsr.xvid.notv-sample.avi 8/6/2007 12:43 AM 8.35 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV 8/6/2007 12:43 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.nfo 8/6/2007 12:43 AM 8.85 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part01.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part02.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part03.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part04.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part05.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part06.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part07.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part08.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part09.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part10.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part11.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part12.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part13.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part14.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part15.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part16.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part17.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part18.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part19.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part20.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part21.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part22.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part23.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part24.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.part25.rar 8/6/2007 12:43 AM 5.84 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\burn.notice.104.dsr.xvid.notv.sfv 8/6/2007 12:43 AM 3.27 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\Sample 8/3/2007 4:29 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E04.DSR.XviD-NoTV\Sample\burn.notice.104.dsr.xvid.notv-sample.avi 8/6/2007 12:43 AM 5.92 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS 8/6/2007 12:43 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.nfo 8/6/2007 12:43 AM 5.52 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r00 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r01 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r02 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r03 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r04 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r05 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r06 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r07 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r08 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r09 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r10 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r11 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r12 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r13 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r14 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r15 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r16 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r17 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r18 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r19 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r20 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r21 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r22 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.r23 8/6/2007 12:43 AM 1.49 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.rar 8/6/2007 12:43 AM 14.31 MB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Desktop\downloads to shar\tv\Burn Notice\Burn.Notice.S01E05.DSR.XviD-SYS\burn.notice.105.dsr.xvid-sys.sfv 8/6/2007 12:43 AM 1.05 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temp\Perflib_Perfdata_134.dat 8/6/2007 12:40 AM 16.00 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temp\Perflib_Perfdata_8ac.dat 8/6/2007 12:43 AM 16.00 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\130140813712[1].jpg 8/6/2007 12:36 AM 2.03 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\4-1x1_tracking_pixel[1].gif 8/6/2007 12:38 AM 49 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\707fe58e9e174a2383bbb4792a8f27d515da8741a4db43c5aacb548f79573f2fa[1].js 8/6/2007 12:37 AM 23.97 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\98t[1].jpg 8/6/2007 12:37 AM 395 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\adbox_trailers[1].xml 8/6/2007 12:37 AM 1.46 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\ads[1].htm 8/6/2007 12:36 AM 5.89 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\attcpd7036_Park_300x250[1].gif 8/6/2007 12:37 AM 7.80 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\b[1].gif 8/6/2007 12:37 AM 43 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\b[2].gif 8/6/2007 12:37 AM 43 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\lhs_overview[1].gif 8/6/2007 12:37 AM 455 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\messageboard_header_bgd[1].gif 8/6/2007 12:37 AM 390 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\optn=1[1].htm 8/6/2007 12:37 AM 991 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\th-lo5[1].jpg 8/6/2007 12:37 AM 24.75 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\2VY50V63\tpblogo_sm_ny[1].gif 8/6/2007 12:36 AM 5.24 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\06m[1].jpg 8/6/2007 12:37 AM 4.21 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\10m[1].jpg 8/6/2007 12:37 AM 8.50 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\29t[1].jpg 8/6/2007 12:37 AM 692 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\468x60_10[1].jpg 8/6/2007 12:36 AM 1.21 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\49[1].gif 8/6/2007 12:37 AM 4.37 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\49[2].gif 8/6/2007 12:37 AM 1.97 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\78m[1].jpg 8/6/2007 12:37 AM 5.24 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\CAOPMPBW.swf 8/6/2007 12:37 AM 100 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\header_funstuff[1].gif 8/6/2007 12:37 AM 428 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\icon_messageboard[1].gif 8/6/2007 12:37 AM 451 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\iframe[2].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\lhs_promotional[1].gif 8/6/2007 12:37 AM 491 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\limited_03[1].gif 8/6/2007 12:35 AM 8.88 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\shop_background[1].gif 8/6/2007 12:37 AM 676 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\shop_logos[1].gif 8/6/2007 12:37 AM 5.83 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\476JYTEH\tpb[1].jpg 8/6/2007 12:35 AM 18.73 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\10f[1].jpg 8/6/2007 12:37 AM 6.14 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\10m[1].jpg 8/6/2007 12:37 AM 6.53 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\10m[2].jpg 8/6/2007 12:37 AM 7.34 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\22t[1].jpg 8/6/2007 12:37 AM 572 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\290146500777[1].jpg 8/6/2007 12:36 AM 3.75 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\ads[1].htm 8/6/2007 12:36 AM 5.85 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\CAD003LX.swf 8/6/2007 12:37 AM 31.73 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\header_usercomments[1].gif 8/6/2007 12:37 AM 618 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\img%20(13)[1].jpg 8/6/2007 12:36 AM 2.87 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\lhs_quicklinks[1].gif 8/6/2007 12:37 AM 473 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\lhs_selected_bgd[1].gif 8/6/2007 12:37 AM 321 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\optn=1[1].htm 8/6/2007 12:37 AM 318 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\TopLayer.V2e[1].js 8/6/2007 12:37 AM 51.40 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\tpb[1].js 8/6/2007 12:35 AM 942 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\6LOVONG9\tt0427470[1].htm 8/6/2007 12:37 AM 42.60 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\10m[1].jpg 8/6/2007 12:37 AM 3.84 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\25t[1].jpg 8/6/2007 12:37 AM 662 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\controls[2].js 8/6/2007 12:35 AM 27.38 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\dice_q207_bsod_468x60[1].gif 8/6/2007 12:37 AM 18.05 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\dragdrop[2].js 8/6/2007 12:35 AM 28.92 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\header_additionaldetails[1].gif 8/6/2007 12:37 AM 708 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\iframe[2].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\kanoodle-find[1].htm 8/6/2007 12:37 AM 961 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\lhs_toplinks[1].gif 8/6/2007 12:37 AM 426 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\MA_Cyard_Q207bagel_468x60[1].gif 8/6/2007 12:37 AM 13.76 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\meter_help[1].gif 8/6/2007 12:37 AM 322 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\my[1].htm 8/6/2007 12:34 AM 8.53 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\navbar[1].gif 8/6/2007 12:37 AM 17.57 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\optn=1[1].htm 8/6/2007 12:38 AM 1.33 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\89IBGHMF\trace[1].htm 8/6/2007 12:37 AM 103 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\10[1].gif 8/6/2007 12:37 AM 3.39 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\12t[1].jpg 8/6/2007 12:37 AM 1.58 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\12t[2].jpg 8/6/2007 12:37 AM 1.52 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\280140044244[1].jpg 8/6/2007 12:36 AM 5.06 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\84t[1].jpg 8/6/2007 12:37 AM 615 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\amazon_logo[1].gif 8/6/2007 12:37 AM 505 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\btn_yes[1].gif 8/6/2007 12:37 AM 504 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\f110[1].gif 8/6/2007 12:37 AM 515 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\flashwrite_1_2[1].js 8/6/2007 12:38 AM 801 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\imdb[1].htm 8/6/2007 12:37 AM 36.88 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\lhs_plotandquotes[1].gif 8/6/2007 12:37 AM 542 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\optn=1[1].htm 8/6/2007 12:37 AM 318 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\optn=64[1].htm 8/6/2007 12:37 AM 3.81 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\8PYBO1IR\prototype[2].js 8/6/2007 12:35 AM 53.86 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\10m[1].jpg 8/6/2007 12:37 AM 4.70 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\10m[2].jpg 8/6/2007 12:37 AM 6.12 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\707fe58e9e174a2383bbb4792a8f27d515da8741a4db43c5aacb548f79573f2f[1].js 8/6/2007 12:37 AM 24.13 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\a[1].js 8/6/2007 12:38 AM 60 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\bnum=95737556[1] 8/6/2007 12:37 AM 4.94 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\header_faq[1].gif 8/6/2007 12:37 AM 323 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\icon_trailer[1].gif 8/6/2007 12:37 AM 477 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\iframe[2].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\nonnude2[1].jpg 8/6/2007 12:36 AM 2.60 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\pic5a[1].jpg 8/6/2007 12:36 AM 4.68 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\slider[2].js 8/6/2007 12:35 AM 10.54 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\th-lo3[1].jpg 8/6/2007 12:37 AM 23.95 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\thepiratebay[1].htm 8/6/2007 12:35 AM 5.50 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDINGLIJ\update[1].gif 8/6/2007 12:37 AM 908 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\02[1].txt 8/6/2007 12:37 AM 579 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\10m[1].jpg 8/6/2007 12:37 AM 6.25 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\10t[1].jpg 8/6/2007 12:37 AM 843 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\10t[2].jpg 8/6/2007 12:37 AM 800 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\68t[1].jpg 8/6/2007 12:37 AM 1.09 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\90[1].gif 8/6/2007 12:37 AM 654 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\adframe[1].htm 8/6/2007 12:36 AM 1015 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\banner[1].htm 8/6/2007 12:36 AM 3.07 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\go[1].gif 8/6/2007 12:37 AM 373 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\google[1].htm 8/6/2007 12:36 AM 5.66 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\index[1].htm 8/6/2007 12:41 AM 164.05 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\optn=1[1].htm 8/6/2007 12:37 AM 993 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\show_ads[1].js 8/6/2007 12:36 AM 2.47 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\starstiny[1].gif 8/6/2007 12:37 AM 997 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\th-889_400[1].jpg 8/6/2007 12:37 AM 2.93 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\th-lo4[1].jpg 8/6/2007 12:37 AM 29.22 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\CDYFG56J\tpb_k[1].gif 8/6/2007 12:35 AM 122 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\1x1_Pixel[1].gif 8/6/2007 12:37 AM 43 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\46t[1].jpg 8/6/2007 12:37 AM 932 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\context[1].htm 8/6/2007 12:38 AM 3.01 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\f111[1].gif 8/6/2007 12:37 AM 469 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\find[1].htm 8/6/2007 12:37 AM 18.10 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\google[1].htm 8/6/2007 12:32 AM 5.66 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\header_messageboards[1].gif 8/6/2007 12:37 AM 721 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\imp[1] 8/6/2007 12:36 AM 1.17 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\kanoodle-title[1].htm 8/6/2007 12:37 AM 962 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\lhs_funstuff[1].gif 8/6/2007 12:37 AM 414 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\logo[1].gif 8/6/2007 12:36 AM 8.36 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\optn=1[1].htm 8/6/2007 12:38 AM 318 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\pirate2[2].css 8/6/2007 12:35 AM 17.74 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\rightarrowlink[1].gif 8/6/2007 12:37 AM 53 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\shop_flags[1].gif 8/6/2007 12:37 AM 1.38 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\K92VKXEB\stars[1].gif 8/6/2007 12:37 AM 3.57 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167 8/6/2007 12:37 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\10m[1].jpg 8/6/2007 12:37 AM 7.48 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\14t[1].jpg 8/6/2007 12:37 AM 623 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\99t[1].jpg 8/6/2007 12:37 AM 638 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\button_addtomymovies[1].gif 8/6/2007 12:37 AM 1.96 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\desktop.ini 8/6/2007 12:37 AM 67 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\header_cast[1].gif 8/6/2007 12:37 AM 293 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\header_relatedlinks[1].gif 8/6/2007 12:37 AM 610 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\imdb_trailers_115[2].swf 8/6/2007 12:37 AM 18.04 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\STY34167\lhs_externallinks[1].gif 8/6/2007 12:37 AM 520 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\10m[1].jpg 8/6/2007 12:37 AM 5.65 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\10t[1].jpg 8/6/2007 12:37 AM 773 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\38t[1].jpg 8/6/2007 12:37 AM 738 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\79m[1].jpg 8/6/2007 12:37 AM 5.88 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\addtiny[1].gif 8/6/2007 12:37 AM 303 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\builder[2].js 8/6/2007 12:35 AM 3.28 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\effects[2].js 8/6/2007 12:35 AM 32.14 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\icon_photos[1].gif 8/6/2007 12:37 AM 445 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\imdb[1].css 8/6/2007 12:37 AM 6.98 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\optn=1[1].gif 8/6/2007 12:37 AM 37.55 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\optn=1[1].htm 8/6/2007 12:37 AM 440 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\optn=64[1].htm 8/6/2007 12:37 AM 3.57 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\shop_buttons[1].gif 8/6/2007 12:37 AM 4.06 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\sprocket[1].gif 8/6/2007 12:37 AM 397 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\W5ABC967\trace[1].htm 8/6/2007 12:37 AM 103 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\10[1].gif 8/6/2007 12:37 AM 1.71 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\10m[1].jpg 8/6/2007 12:37 AM 5.00 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\10t[1].jpg 8/6/2007 12:37 AM 758 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\49[1].gif 8/6/2007 12:37 AM 1.94 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\68t[1].jpg 8/6/2007 12:37 AM 694 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\banner[1].htm 8/6/2007 12:36 AM 3.94 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\CAY3UJ69.swf 8/6/2007 12:36 AM 16.85 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\context[1].htm 8/6/2007 12:37 AM 3.09 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\eyebrowcontainer[1].gif 8/6/2007 12:37 AM 2.32 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\f96[1].gif 8/6/2007 12:37 AM 60 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\header_overview[1].gif 8/6/2007 12:37 AM 487 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\header_recommendations[1].gif 8/6/2007 12:37 AM 684 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\index[1].htm 8/6/2007 12:33 AM 164.05 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\lhs_otherinfo[1].gif 8/6/2007 12:37 AM 446 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\scriptaculous[2].js 8/6/2007 12:35 AM 2.19 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\WT27SPM7\trivia[1].gif 8/6/2007 12:37 AM 1.98 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\04[1].txt 8/6/2007 12:37 AM 1006 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\10[1].gif 8/6/2007 12:37 AM 2.28 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\10[2].gif 8/6/2007 12:37 AM 255 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\200[1] 8/6/2007 12:36 AM 8.95 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\200[1].htm 8/6/2007 12:36 AM 70.41 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\230158456723[1].jpg 8/6/2007 12:36 AM 2.20 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\btn_no[1].gif 8/6/2007 12:37 AM 489 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\dl[1].gif 8/6/2007 12:36 AM 120 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\icon_pro[1].gif 8/6/2007 12:37 AM 567 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\iframe[1].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\iframe[2].htm 8/6/2007 12:33 AM 59 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\lhs_awardsreviews[1].gif 8/6/2007 12:37 AM 659 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\logo[1].gif 8/6/2007 12:37 AM 5.46 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\meter_down[1].gif 8/6/2007 12:37 AM 56 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\NFMP_blowClos_120x600_35k_s[1].swf 8/6/2007 12:38 AM 31.67 KB Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\rss[1].gif 8/6/2007 12:35 AM 119 bytes Hidden from Windows API.
C:\Documents and Settings\Road Dog\Local Settings\Temporary Internet Files\Content.IE5\YJ0H6B0D\searchbg[1].gif 8/6/2007 12:37 AM 820 bytes Hidden from Windows API.
C:\Program Files\BitComet\Downloads\Burn.Notice.S01E02.DSR.XviD-NoTV\burn.notice.102.dsr.xvid.notv.avi 7/5/2007 11:13 PM 350.24 MB Hidden from Windows API.
C:\Program Files\BitComet\Downloads\Burn.Notice.S01E03.DSR.XviD-NoTV 8/3/2007 4:31 AM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Program Files\BitComet\Downloads\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.nfo 8/3/2007 3:47 AM 8.85 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\BitComet\Downloads\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part01.rar 8/3/2007 4:30 AM 14.31 MB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\BitComet\Downloads\Burn.Notice.S01E03.DSR.XviD-NoTV\burn.notice.103.dsr.xvid.notv.part0
LoPhatPhuud
Rootkit Revealer did not indicate anyhing serious, but I'm not sure if that is all of it after your comments.

Run AVG Anti-Rootkit and post the results in this thread.

You can find here: http://www.grisoft.com/doc/download-free-a...ootkit/us/crp/0
bylanta
So I ran that program a couple times in both options for scanning and it came up with nothing. Is there a benchmark program or something that I might be able to run because I still feel like my computer isn't running like it did. I really do appreciate all your help, I don't know what I would have without it
LoPhatPhuud
Most of the major AntiVirus firms are now offering a free rootkit scanner/remover. So far we have two, both negative. You can try BLacklight, but I suspect it will be negative as well. (Info follows)

After running blacklight, run chkdsk for each hard disk on your system. If any return errors, then run it again in fix mode. After that, defrag all drives.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.