• WELCOME
Welcome to the Myantispyware - free site offering help and assistance on spyware, malware and adware removal. As a guest you can only browse and view the various topics in the forums, but can not create a new topic and reply to an existing topic. If you are seeking help, you will need to be a logged into the forums with a registered account. Registering is free.
Click here to Create a free account and read How to use Spyware Removal Forum

Another spyware soft stop victim

Moderator: Moderators

Another spyware soft stop victim

Postby neilT » Sat Jun 23, 2007 5:47 am

Hello Patrik ... could you examine this for me please

Thanks

-------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:38:04 PM, on 20/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\DOCUME~1\Susan\LOCALS~1\Temp\frmwrk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Install Source\tomcoyote.org_HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-dcf7-f96da086b434} - C:\DOCUME~1\Susan\LOCALS~1\Temp\sthbdm32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {6C6B8C69-9285-4D94-8492-9E920C8C2B65} - C:\WINDOWS\System32\mstsk32.dll
O2 - BHO: (no name) - {74f25a2c-22b3-4023-8f1a-ca616c30a8b5} - C:\Documents and Settings\Susan\stubext.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {c5183abc-eb6e-4e05-b8c9-500a16b6cf94} - C:\Documents and Settings\Susan\krnl32.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {3ceff6cd-6f08-4e4d-bccd-ff7415288c3b} - C:\WINDOWS\System32\uncwqs.dll
O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - C:\DOCUME~1\Susan\LOCALS~1\Temp\regdll32.exe
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {5AA06644-BC46-4220-A460-47A6EB47C96D} - C:\WINDOWS\System32\uncwqs.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMixerTray] C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.2\SetHook.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [WMDM PMSP Service] C:\WINDOWS\system32\cssrss.exe
O4 - HKLM\..\Run: [Windows Framework] C:\DOCUME~1\Susan\LOCALS~1\Temp\frmwrk.exe
O4 - HKLM\..\Run: [bxproxy] C:\DOCUME~1\Susan\LOCALS~1\Temp\mxcrtp.dll
O4 - HKLM\..\Run: [mmnext06] C:\DOCUME~1\Susan\LOCALS~1\Temp\svhc32.dll
O4 - HKLM\..\Run: [shellbn] C:\DOCUME~1\Susan\LOCALS~1\Temp\winsys32.exe
O4 - HKLM\..\Run: [new.net startup] C:\Documents and Settings\Susan\param32.ocx
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?3e09406453ca45b2833217f52d792556
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?3e09406453ca45b2833217f52d792556
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: pptp32 - pptp32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe" -f (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
neilT
 
Posts: 5
Joined: Sat Jun 23, 2007 5:37 am

Postby patrik » Sun Jun 24, 2007 11:59 pm

Hello neilT, welcome to the Myantispyware forums!

You have a trojan HAXDOOR infection. Please follow these instructions step by step.

Download haxfix.exe.
Save it to your desktop.
Double click on haxfix.exe to install haxfix. (standard installation path is c:\program Files\haxfix)
Checkmark "Create a desktop icon".
Click "Next".
When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed.
Click "Finish".
A red "dos window" (dos box) will open.
Select option 1. Make logfile by typing 1 and then pressing Enter.
Haxfix will start scanning the computer. When it is finished a logfile will open.
Copy the contents of that logfile and paste it into this thread.

Post the results from the scan in your next reply
patrik
Site Admin
 
Posts: 9276
Joined: Sun Jan 08, 2006 1:11 pm

Haxfix logfile

Postby neilT » Tue Jun 26, 2007 12:03 am

Thanks Patrik for your help
-------------------


HAXFIX logfile - by Marckie

version 4.47
25/06/2007 15:39:45.78

--- Checking for Haxdoor ---

checking for a3d files
a3d files found
ps.a3d

checking for matching notify keys
matching notify keys found
pptp

checking for matching services
matching services found
Aspi32
pptp32
pptp64

checking for matching safeboot services
matching safeboot services found
pptp32.sys
pptp64.sys

checking for other Haxdoor-files
no other Haxdoor-files found


--- Checking for Goldun ---

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for other Goldun-files
no other Goldun-files found

checking iexplore.exe
iexplore.exe is not infected


--- Catchme logfile - thank you Gmer ---

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-25 15:39:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

? [1088]

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\Documents and Settings\Administrator\Recent
C:\Documents and Settings\Administrator\Recent\Desktop.ini
C:\Documents and Settings\All Users\Application Data\Avery\DesignPro5\Wizard\Graphics\recycle.png
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsIEFirewallBypass.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NewDotNet.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz10.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz2.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz3.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz4.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz5.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz6.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz7.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz8.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Cimuz9.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DailyToolbar.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DailyToolbar1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FaSSt.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FaSSt1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NewDotNet1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NewDotNet2.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NewDotNet3.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NewDotNet4.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NewDotNet5.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCEbayBill.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCEbayBill1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCEbayBill2.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCEbayBill3.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCEbayBill4.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCEbayBill5.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCEbayBill6.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCEbayBill7.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake10.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake11.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake12.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake2.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake3.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake4.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake5.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake6.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake7.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake8.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TelekomBillFake9.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfuc.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDelfuc1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsIEFirewallBypass1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallBypass.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallBypass1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallDisableNotify.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterUpdateDisableNotify.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NavExcelWebsearch.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NavExcelWebsearch1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NavExcelWebsearch2.zip
C:\Documents and Settings\Default User\Recent
C:\Documents and Settings\Default User\Templates\quattro.wb2
C:\Documents and Settings\Guest\Application Data\Microsoft\Internet Explorer\Quick Launch
C:\Documents and Settings\Guest\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Documents and Settings\Guest\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
C:\Documents and Settings\Guest\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
C:\Documents and Settings\Guest\Recent
C:\Documents and Settings\Guest\Recent\Desktop.ini
C:\Documents and Settings\Guest\Templates\quattro.wb2
C:\Documents and Settings\Susan\Application Data\Adobe\Acrobat\7.0\Reception-PC.err
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\9 am liturgy.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Annual Report 2006.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\April 2 06 bulletin.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\ARM Article - revise.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\ARM mailings.rtf.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\ARM.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Bio of David Short Mar 20-06 Word doc.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Leaders' Council 1.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\LETTERHEAD.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Liturgical Planning.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\March 12 06 bulletin.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\March 26 06 bulletin.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\March 26 2006 music.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Marion.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\MUSIC.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\My Disc (D).LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\My Documents.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\My Pictures.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\OLK2.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Parish List February 06.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Parish List January 05.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Parish List November 23.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\parish list to September 1 04.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Parish Lists.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Photo Better One of Man Woman Talk.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Photo Male Hands.jpg.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Photo Man on Computer.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Photo Man with Computer.jpg.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Photo Man Woman Talk.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\prophecy for this place.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Prophecy.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\BULLETINS.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Call On Me brochure 1.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\CHURCH GENERL.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\CONFERENCES.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Desktop.ini
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Discipleship 2 Feb 11 01.ppt.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\DrPhilTest.pps.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Special Parish Meeting March 20 06.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Spring 06.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\St. Peter's Music Book Feb 06.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\St. Peter's.DOC.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Summer 06.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\The Year Ahead.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Tickle their fancy. Malcolm for sumer doc.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Employee Expense Report Michael March.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Employee Expense Report Susan February.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Employee Expense Report Susan March.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\essentials conference financial report.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Essentials.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\family1.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\FINANCE.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\General.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Gospel Works Anglican.pub.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Employee Expense Report Michael February.xls.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\index.dat
C:\Documents and Settings\Susan\Application Data\Microsoft\Office\Recent\Prophetic Words 06.doc.LNK
C:\Documents and Settings\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch
C:\Documents and Settings\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Documents and Settings\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
C:\Documents and Settings\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
C:\Documents and Settings\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
C:\Documents and Settings\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
C:\Documents and Settings\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Live Messenger.lnk
C:\Documents and Settings\Susan\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
C:\Documents and Settings\Susan\Local Settings\Temp\pft57A.tmp\Rdr708.msp
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\gfx\Query1_background.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\gfx\query2_background.PNG
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\gfx\Query_Blocked_background.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\gfx\Query_Blocked_background_grad.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\gfx\recentprogactivity_64.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\translations\english\gfx\Query1_background.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\translations\english\html\qc.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\translations\english\html\qcfailed.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\translations\english\html\qlpu.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\2k_2k3_xp\translations\english\html\qpu_r.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\gfx\Query1_background.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\gfx\query2_background.PNG
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\gfx\Query_Blocked_background.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\gfx\Query_Blocked_background_grad.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\gfx\recentprogactivity_64.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\translations\english\gfx\Query1_background.png
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\translations\english\html\qc.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\translations\english\html\qcfailed.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\translations\english\html\qlpu.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\img\bins\AMD64\translations\english\html\qpu_r.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$0\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\2k_2k3_xp\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\2k_2k3_xp\translations\english\html\qc.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\2k_2k3_xp\translations\english\html\qcfailed.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\2k_2k3_xp\translations\english\html\qlpu.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\2k_2k3_xp\translations\english\html\qpu_r.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\AMD64\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\AMD64\translations\english\html\qc.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\AMD64\translations\english\html\qcfailed.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\AMD64\translations\english\html\qlpu.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\img\bins\AMD64\translations\english\html\qpu_r.html
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$1\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$2\img\bins\2k_2k3_xp\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$2\img\bins\AMD64\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$2\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$3\img\bins\2k_2k3_xp\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$3\img\bins\AMD64\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\PrevxSetup$3\qt-mt336.dll
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF284.tmp\Installers\QuickMessage.2005-05-13.ProModule.exe
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF284.tmp\Installers\QuickVerseSupport.2005-12-08.ProModule.exe
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF284.tmp\ReadMe\QuickMessage
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF284.tmp\ReadMe\QuickMessage\ReadMe.html
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF284.tmp\ReadMe\QuickVerse Support
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF284.tmp\ReadMe\QuickVerse Support\ReadMe.html
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF30F.tmp\Installers\QuickMessage.2005-05-13.ProModule.exe
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF30F.tmp\Installers\QuickVerseSupport.2005-12-08.ProModule.exe
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF30F.tmp\ReadMe\QuickMessage
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF30F.tmp\ReadMe\QuickMessage\ReadMe.html
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF30F.tmp\ReadMe\QuickVerse Support
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF30F.tmp\ReadMe\QuickVerse Support\ReadMe.html
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF328.tmp\Installers\QuickMessage.2005-05-13.ProModule.exe
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF328.tmp\Installers\QuickVerseSupport.2005-12-08.ProModule.exe
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF328.tmp\ReadMe\QuickMessage
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF328.tmp\ReadMe\QuickMessage\ReadMe.html
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF328.tmp\ReadMe\QuickVerse Support
C:\Documents and Settings\Susan\Local Settings\Temp\sspGLF328.tmp\ReadMe\QuickVerse Support\ReadMe.html
C:\Documents and Settings\Susan\Local Settings\Temp\Temporary Internet Files\Content.IE5\5LGNQSJT\recipes_on[1].gif
C:\Documents and Settings\Susan\Local Settings\Temp\Temporary Internet Files\Content.IE5\KB5162LF\recipes[1].gif
C:\Documents and Settings\Susan\Local Settings\Temp\Temporary Internet Files\Content.IE5\KB5162LF\recipes_on[1].gif
C:\Documents and Settings\Susan\Local Settings\Temp\Temporary Internet Files\Content.IE5\MUHO41WB\recipes_over[1].gif
C:\Documents and Settings\Susan\Local Settings\Temp\Temporary Internet Files\Content.IE5\PMCHWHKT\recipes[1].gif
C:\Documents and Settings\Susan\Local Settings\Temp\Temporary Internet Files\Content.IE5\PMCHWHKT\recipes_over[1].gif
C:\Documents and Settings\Susan\Local Settings\Temp\QVDDFDKU.htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\2HXI765S\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\quant[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\335UHY5Z\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[15].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[16].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[14].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\63WHFPUK\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\87GTQ9U9\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\9ZZZM753\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\AXWJIHGP\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\AXWJIHGP\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\AXWJIHGP\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\CLQVIVWT\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\CLQVIVWT\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\CLQVIVWT\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\CLQVIVWT\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\CLQVIVWT\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\F7D3RLC8\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\F7D3RLC8\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\F7D3RLC8\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\F7D3RLC8\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\F7D3RLC8\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\F7D3RLC8\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\F7D3RLC8\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\GNA7ALI1\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\GNA7ALI1\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\GNA7ALI1\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\GNA7ALI1\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\GNA7ALI1\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\GNA7ALI1\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[14].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[15].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\JQ9E9F10\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[14].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[15].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\K7L7AQBD\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\KPIZ0HI7\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\KPIZ0HI7\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\KPIZ0HI7\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\KPIZ0HI7\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\LG8NTHO9\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[14].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[15].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\N7OYME73\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\PR3ZPD0Q\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\0000000000001851000068170007[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\01[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\bg[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\calgary.anglican[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\cmdatatagutils[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\home-top[1].jpg
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\icon_biggrin[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\icon_feed[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\icon_quote[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\icon_smile[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\icon_wink[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\import_category_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\import_navigation_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\shipping_banner_functions[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\ShopperGreeting[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\shopper_greeting_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\shopping_bag_count_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\opendns_125[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\prefs[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\logo[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\main_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\main_style[2].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\activity;src=1021148;type=provi107;cat=provi335;ord=1;num=3881951167837[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\advanced_search_template_style[2].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\0801012945.01._SCTHUMBZZZ_V36354848_[1].jpg
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\3177250[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\sapphirebody[1].jpg
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\SearchBar[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\stylesheets[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\stylesheets[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\download[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\eluminate[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\EmailUpdate[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\email_update_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\emptyshoppingbag_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\menuicon[1].jpg
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\oo_engine[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\events_synods_off[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\example_advanced[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\favicon[1].ico
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\favicon[2].ico
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\searchresults_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\shared[3].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\stylesheets[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\transpix[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\ttg-r[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\url_constructor_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\take[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\timesselect[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\topnav_main_functions[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\topnav_main_functions[2].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\wish_list_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\wx[1].png
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\stylesheets[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\search_bar_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\AllServices[1].xml
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\anglicannetwork[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\anglican[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\arrow_orange_white_right_large[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\authorization[2].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\banner_back[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\base_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\BG-XTG_sw[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\bg-xtm_sw[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\style[2].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\tab_row_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\global_header_container_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\desktop.ini
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\full[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\shared[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\shared[2].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\general-synod-morning-session-24607[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\gift_finder_creative_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\global_footer_container_style[1].css
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\Common[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\common[2].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\configure[1].xml
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\count[1].png
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\count[2].png
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\count[3].png
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\count[4].png
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\crossword[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\c_bot[1].gif
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\google[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\flash_detect[1].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\flash_detect[1].vbs
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\flash_detect[2].js
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\QLZKTOBE\flash_detect[2].vbs
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RU4NBLOL\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[14].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[15].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[16].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\RUXUZB5R\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YJGNMD0F\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YJGNMD0F\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YJGNMD0F\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YJGNMD0F\recentupdates[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YJGNMD0F\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YJGNMD0F\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[10].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[11].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[12].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[13].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[14].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[15].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[16].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[17].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[1].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[2].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[3].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[4].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[5].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[6].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[7].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[8].htm
C:\Documents and Settings\Susan\Local Settings\Temporary Internet Files\Content.IE5\YZBSP4LS\recipe_wide_opt[9].htm
C:\Documents and Settings\Susan\My Documents\ADMINISTRATION\Christmas\quote used at StPeter's dinner wrap-up.htm
C:\Documents and Settings\Susan\My Documents\Ministries\Children's Church\JEN V CM\recital christmas 03.pub
C:\Documents and Settings\Susan\My Documents\Quick Books Data
C:\Documents and Settings\Susan\My Documents\Quick Books Data\lions.qbb
C:\Documents and Settings\Susan\My Documents\Quick Books Data\LIONS.QWB
C:\Documents and Settings\Susan\My Documents\Quick Books Data\new98.qbw
C:\Documents and Settings\Susan\My Documents\Quick Books Data\Okotoks_.QBW
C:\Documents and Settings\Susan\My Documents\Quick Books Data\Payrol02.QBW
C:\Documents and Settings\Susan\My Documents\Quick Books Data\STP05.QBW
C:\Documents and Settings\Susan\My Documents\Quick Books Data\STP2000.qbw
C:\Documents and Settings\Susan\My Documents\Quick Books Data\stpet02.qbw
C:\Documents and Settings\Susan\My Documents\Quick Books Data\ST_PETER.QBW
C:\Documents and Settings\Susan\My Documents\PERSONAL\KORALEY\ARTREACH\questionaire.pub
C:\Documents and Settings\Susan\My Documents\PERSONAL\ROQUEFORT DRESSING Recipe at Epicurious_com_files\recipeAdUtils.js
C:\Documents and Settings\Susan\My Documents\PERSONAL\ROQUEFORT DRESSING Recipe at Epicurious_com_files\recipecollections.gif
C:\Documents and Settings\Susan\My Documents\PERSONAL\ROQUEFORT DRESSING Recipe at Epicurious_com_files\recipes_wide_opt.css
C:\Documents and Settings\Susan\My Documents\PERSONAL\TUSCAN-STYLE PEPPERED CHICKEN Recipe at Epicurious_com_files\recipecollections.gif
C:\Documents and Settings\Susan\My Documents\PERSONAL\TUSCAN-STYLE PEPPERED CHICKEN Recipe at Epicurious_com_files\recipes_wide_opt.css
C:\Documents and Settings\Susan\My Documents\QPPriv
C:\Documents and Settings\Susan\My Documents\QPPriv\come to me.pub
C:\Documents and Settings\Susan\My Documents\Financial\FINANCE\receipt for charitable donations.wpd
C:\Documents and Settings\Susan\My Documents\Financial\FINANCE\Record of Givings 2004.xls
C:\Documents and Settings\Susan\My Documents\RECTORS REFLECTIONS
C:\Documents and Settings\Susan\My Documents\RECTORS REFLECTIONS\Monday Feb 2.doc
C:\Documents and Settings\Susan\My Documents\RECTORS REFLECTIONS\Monday. May 10.doc
C:\Documents and Settings\Susan\My Documents\RECTORS REFLECTIONS\RECTOR'S REFLECTIONS 1.doc
C:\Documents and Settings\Susan\My Documents\RECTORS REFLECTIONS\RECTOR'S REFLECTIONS 2.doc
C:\Documents and Settings\Susan\My Documents\RECTORS REFLECTIONS\RECTOR'S REFLECTIONS 3.doc
C:\Documents and Settings\Susan\My Documents\RECTORS REFLECTIONS\Rector's Reflections April 1.doc
C:\Documents and Settings\Susan\My Documents\RECTORS REFLECTIONS\RR April 20.doc
C:\Documents and Settings\Susan\My Documents\VESTRY\ANNUAL REPORTS\Annual Report 2001\Rector's Report [00].doc
C:\Documents and Settings\Susan\My Documents\VESTRY\ANNUAL REPORTS\Annual Report 2003\Rector's Report 20031.doc
C:\Documents and Settings\Susan\My Documents\ZipDisk\CHURCH GENERL\questionaire.doc
C:\Documents and Settings\Susan\My Documents\ZipDisk\CHURCH GENERL\questionaire.wpd
C:\Documents and Settings\Susan\Recent
C:\Documents and Settings\Susan\Recent\Desktop.ini
C:\Documents and Settings\Susan\Recent\test
C:\Documents and Settings\Susan\Templates\quattro.wb2
C:\Documents and Settings\Susan\UserData\QBC96RCP
C:\Documents and Settings\Susan\UserData\QBC96RCP\oWindowsUpdate[1].xml
C:\Install Source\i386\COMPDATA\QIC117.HTM
C:\Install Source\i386\COMPDATA\QIC117.TXT
C:\Install Source\i386\COMPDATA\QUICK3.HTM
C:\Install Source\i386\COMPDATA\QUICK3.TXT
C:\Install Source\i386\LANG\QUICK.IM_
C:\Install Source\i386\QAPPSRV.EX_
C:\Install Source\i386\QASF.DL_
C:\Install Source\i386\QCAP.DL_
C:\Install Source\i386\QDV.DL_
C:\Install Source\i386\QDVD.DL_
C:\Install Source\i386\QEDIT.DL_
C:\Install Source\i386\QL1080.SY_
C:\Install Source\i386\QL10WNT.SY_
C:\Install Source\i386\QL12160.SY_
C:\Install Source\i386\QL1240.SY_
C:\Install Source\i386\QL1280.SY_
C:\Install Source\i386\QMARK.AC_
C:\Install Source\i386\QMARK.GI_
C:\Install Source\i386\QMGR.DL_
C:\Install Source\i386\QMGR.IN_
C:\Install Source\i386\QMGRPRXY.DL_
C:\Install Source\i386\QOSCONW.CH_
C:\Install Source\i386\QOSNAME.DL_
C:\Install Source\i386\QPROCESS.EX_
C:\Install Source\i386\QUARTZ.DL_
C:\Install Source\i386\QUATTRO.WB_
C:\Install Source\i386\QUERY.AS_
C:\Install Source\i386\QUERY.DL_
C:\Install Source\i386\QUERY.EX_
C:\Install Source\i386\QUOTES._
C:\Install Source\i386\QWINSTA.EX_
C:\Install Source\i386\RDBSS.SY_
C:\Install Source\i386\RDCHOST.DL_
C:\Install Source\i386\RDPCDD.SY_
C:\Install Source\i386\RDPCFGEX.DL_
C:\Install Source\i386\RDPCLIP.EX_
C:\Install Source\i386\RDPDD.DL_
C:\Install Source\i386\RDPSND.DL_
C:\Install Source\i386\RDPWD.SY_
C:\Install Source\i386\RDPWSX.DL_
C:\Install Source\i386\RDSADDIN.EX_
C:\Install Source\i386\RDSHOST.EX_
C:\Install Source\i386\RDTONE.HT_
C:\Install Source\i386\RECAGENT.SY_
C:\Install Source\i386\RECOVER.EX_
C:\Install Source\i386\RECYCLE.CH_
C:\Install Source\i386\RECYCLE.WA_
C:\Install Source\i386\QEDWIPES.DL_
C:\Install Source\i386\QUSER.EX_
C:\Install Source\i386\RDSKTPW.CH_
C:\Install Source\Video & DVD Software\DGMPGDec\dgmpgdec146\QuickStart.html
C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\Q2561405.CAB
C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\Q3561405.CAB
C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\Q4561405.CAB
C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\QV561405.CAB
C:\notsub32.txt

C:\Program Files\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\Images\rectangle.gif
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\plug_ins\PaperCapture\Server\Roman\Dbase\PJCR\Recog.dbs
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\plug_ins\PaperCapture\Server\Roman\Dbase\PJCR\Recog_p.inf
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\plug_ins\PaperCapture\Server\Roman\Recogn.dll
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\plug_ins\PaperCapture\Server\Roman\Recore32.dll
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\plug_ins\AcroForm\PMP\QRCode.pmp
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\plug_ins\Multimedia\MPP\QuickTime.mpp
C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\Images\rectangle.gif
C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\ENU\RdrMsgENU.pdf
C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\RdrMsgSplash.pdf
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\PMP\QRCode.pmp
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\MPP\QuickTime.mpp
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\ENU
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig705
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig705\ENU
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\0x0409.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\Abcpy.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\Adobe Reader 7.0.7.msi
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\Data1.cab
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\instmsiw.exe
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\Rdr70.itw
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\setup.exe
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\Setup.ini
C:\Program Files\Adobe\Acrobat 7.0\Update\RdrCore705_708.rtp
C:\Program Files\Common Files\Adobe\Color\Profiles\Recommended
C:\Program Files\Common Files\Adobe\Color\Profiles\Recommended\AdobeRGB1998.icc
C:\Program Files\Common Files\Adobe\Color\Profiles\Recommended\AppleRGB.icc
C:\Program Files\Common Files\Adobe\Color\Profiles\Recommended\ColorMatchRGB.icc
C:\Program Files\Common Files\Adobe\Color\Profiles\Recommended\EuropeISOCoatedFOGRA27.icc
C:\Program Files\Common Files\Adobe\Color\Profiles\Recommended\EuroscaleCoated.icc
C:\Program Files\Common Files\Adobe\Color\Profiles\Recom
neilT
 
Posts: 5
Joined: Sat Jun 23, 2007 5:37 am

Postby patrik » Tue Jun 26, 2007 11:46 pm

neilT, you have Haxdoor trojan infection.

Run haxfix again, Select option 2. Run auto fix by typing 2, and then pressing Enter. If an infection is found, you’ll get a message to close all other open windows. Close them, except the red dos window from haxfix and then press Enter. The computer will reboot.

Run hijackthis, make new log.
Post with you answer haxfix and hijackthis logs.
patrik
Site Admin
 
Posts: 9276
Joined: Sun Jan 08, 2006 1:11 pm

Haxfix and hijackthis logfiles

Postby neilT » Thu Jun 28, 2007 2:18 am

Patrik ... here is the logfiles of haxFix and hijackThis.
Sorry to have to give you bad news; the Haxfix exe found no infections with this scan;
But the spyware soft stop intrusion on the notification area of the toolbar and the installing of it's own desktop background still remains.


HAXFIX logfile - by Marckie

version 4.47
27/06/2007 19:35:42.96

--- Checking for Haxdoor ---

checking for a3d files
a3d files found
ps.a3d

checking for matching notify keys
matching notify keys found
pptp

checking for matching services
matching services found
Aspi32

checking for matching safeboot services
no matching safeboot services found

checking for other Haxdoor-files
no other Haxdoor-files found


--- Checking for Goldun ---

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for other Goldun-files
no other Goldun-files found

checking iexplore.exe
iexplore.exe is not infected


--- Catchme logfile - thank you Gmer ---

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-27 19:35:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

? [2216]

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\OLD-PC\C\Program Files\Logitech\SetPoint\Quicktour\Common\css
C:\OLD-PC\C\Program Files\Logitech\SetPoint\Quicktour\Common\css\kodiak.css
C:\OLD-PC\C\WINDOWS\PCHEALTH\HELPCTR\System\css
C:\OLD-PC\C\WINDOWS\PCHEALTH\HELPCTR\System\css\Behaviors.css
C:\OLD-PC\C\WINDOWS\PCHEALTH\HELPCTR\System\css\Layout.css
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service -- Paul
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Expectations fo…ip Ministry.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Mission Statement
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sun. Report
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Schedule
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Schedule.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service -- Paul
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service -- Paul.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Vision in process
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Flowchart
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Leaders Meeting
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Ministr…Core Values.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Team Expectations
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Expectations fo…ip Ministry.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Mission Statement
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sun. Report
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Schedule
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Schedule.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service -- Paul.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process\._Worship Values and Priorities
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process\Worship Values and Priorities
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Flowchart
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Leaders Meeting
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Ministr…Core Values.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Team Expectations
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\.DS_Store
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\.DS_Store
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._1 Chronicles 16.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._1 Corinthians 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Isaiah 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Nehemiah 9.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 121.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 150.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 84.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Undivided - June 17 06.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\1 Chronicles 16.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\1 Corinthians 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Isaiah 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Nehemiah 9.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 121.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 150.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 84.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Undivided - June 17 06.doc
C:\WINDOWS\system32\cssrss.exe
C:\WINDOWS\pchealth\helpctr\System\css
C:\WINDOWS\pchealth\helpctr\System\css\Behaviors.css
C:\WINDOWS\pchealth\helpctr\System\css\Layout.css

scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 58


--- Analysing Catchme logfile ---

no matching regkeys found


Finished!


------------------------------------------------------



Logfile of HijackThis v1.99.1
Scan saved at 8:02:50 PM, on 27/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\DOCUME~1\Susan\LOCALS~1\Temp\frmwrk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SpywareSoftStop\SpywareSoftStop.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Install Source\tomcoyote.org_HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\system32\ipv6monl.dll
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-dcf7-f96da086b434} - C:\Documents and Settings\Susan\svhc32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {6C6B8C69-9285-4D94-8492-9E920C8C2B65} - C:\WINDOWS\System32\winhid64.dll
O2 - BHO: (no name) - {74f25a2c-22b3-4023-8f1a-ca616c30a8b5} - C:\WINDOWS\System32\wintst.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {c5183abc-eb6e-4e05-b8c9-500a16b6cf94} - C:\DOCUME~1\Susan\LOCALS~1\Temp\stubext.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {3ceff6cd-6f08-4e4d-bccd-ff7415288c3b} - C:\Documents and Settings\Susan\winsys32.exe
O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - C:\DOCUME~1\Susan\LOCALS~1\Temp\regdll32.exe
O3 - Toolbar: (no name) - {5AA06644-BC46-4220-A460-47A6EB47C96D} - C:\Documents and Settings\Susan\svhc32.dll
O3 - Toolbar: (no name) - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\DOCUME~1\Susan\LOCALS~1\Temp\mxcrtp.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMixerTray] C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.2\SetHook.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [WMDM PMSP Service] C:\WINDOWS\system32\cssrss.exe
O4 - HKLM\..\Run: [Windows Framework] C:\DOCUME~1\Susan\LOCALS~1\Temp\frmwrk.exe
O4 - HKLM\..\Run: [bxproxy] C:\Documents and Settings\Susan\wintst.dll
O4 - HKLM\..\Run: [mmnext06] C:\DOCUME~1\Susan\LOCALS~1\Temp\stubext.dll
O4 - HKLM\..\Run: [shellbn] C:\DOCUME~1\Susan\LOCALS~1\Temp\uncwqs.dll
O4 - HKLM\..\Run: [new.net startup] C:\DOCUME~1\Susan\LOCALS~1\Temp\mstsk32.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpywareSoftStop] "C:\Program Files\SpywareSoftStop\SpywareSoftStop.exe"
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?9badffbfe3ba44d4b92f468407dccf64
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?9badffbfe3ba44d4b92f468407dccf64
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: pptp32 - pptp32.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe" -f (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
neilT
 
Posts: 5
Joined: Sat Jun 23, 2007 5:37 am

Postby patrik » Thu Jun 28, 2007 9:35 am

ok, neilT
We try another way.

Reboot your computer in Safe Mode.

1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.


Run hijackthis, scan and place a check mark next to any of the following that remain. Then press the "fix checked" button.

O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\system32\ipv6monl.dll
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-dcf7-f96da086b434} - C:\Documents and Settings\Susan\svhc32.dll
O2 - BHO: (no name) - {6C6B8C69-9285-4D94-8492-9E920C8C2B65} - C:\WINDOWS\System32\winhid64.dll
O2 - BHO: (no name) - {74f25a2c-22b3-4023-8f1a-ca616c30a8b5} - C:\WINDOWS\System32\wintst.dll
O2 - BHO: (no name) - {c5183abc-eb6e-4e05-b8c9-500a16b6cf94} - C:\DOCUME~1\Susan\LOCALS~1\Temp\stubext.dll
O3 - Toolbar: (no name) - {3ceff6cd-6f08-4e4d-bccd-ff7415288c3b} - C:\Documents and Settings\Susan\winsys32.exe
O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - C:\DOCUME~1\Susan\LOCALS~1\Temp\regdll32.exe
O3 - Toolbar: (no name) - {5AA06644-BC46-4220-A460-47A6EB47C96D} - C:\Documents and Settings\Susan\svhc32.dll
O3 - Toolbar: (no name) - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\DOCUME~1\Susan\LOCALS~1\Temp\mxcrtp.dll
O4 - HKLM\..\Run: [WMDM PMSP Service] C:\WINDOWS\system32\cssrss.exe
O4 - HKLM\..\Run: [Windows Framework] C:\DOCUME~1\Susan\LOCALS~1\Temp\frmwrk.exe
O4 - HKLM\..\Run: [bxproxy] C:\Documents and Settings\Susan\wintst.dll
O4 - HKLM\..\Run: [mmnext06] C:\DOCUME~1\Susan\LOCALS~1\Temp\stubext.dll
O4 - HKLM\..\Run: [shellbn] C:\DOCUME~1\Susan\LOCALS~1\Temp\uncwqs.dll
O4 - HKLM\..\Run: [new.net startup] C:\DOCUME~1\Susan\LOCALS~1\Temp\mstsk32.dll
O4 - HKCU\..\Run: [SpywareSoftStop] "C:\Program Files\SpywareSoftStop\SpywareSoftStop.exe"


Run haxdoor, Select option 2. Run auto fix by typing 2, and then pressing Enter.
If an infection is found, you'll get a message to close all other open windows.
Close them, except the red dos window from haxfix and then press Enter.
The computer will reboot.
After reboot a logfile will open.

Post the contents of that logfile along with a new hijackthislog.
patrik
Site Admin
 
Posts: 9276
Joined: Sun Jan 08, 2006 1:11 pm

Hijack Haxfix Log files

Postby neilT » Thu Jul 05, 2007 5:45 am

Patrik ... the desktop seems to be free so far
Thanks

HAXFIX logfile - by Marckie

version 4.47
04/07/2007 23:30:48.28

--- Checking for Haxdoor ---

checking for a3d files
a3d files not found

checking for matching notify keys
matching notify keys found
pptp

checking for matching services
matching services found
Aspi32

checking for matching safeboot services
no matching safeboot services found

checking for other Haxdoor-files
no other Haxdoor-files found


--- Checking for Goldun ---

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for other Goldun-files
no other Goldun-files found

checking iexplore.exe
iexplore.exe is not infected


--- Catchme logfile - thank you Gmer ---

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-04 23:30:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\notsub32.txt
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service -- Paul
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Expectations fo…ip Ministry.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Mission Statement
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sun. Report
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Schedule
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Schedule.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service -- Paul
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service -- Paul.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Vision in process
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Flowchart
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Leaders Meeting
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Ministr…Core Values.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Team Expectations
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Expectations fo…ip Ministry.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Mission Statement
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sun. Report
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Schedule
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Schedule.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service -- Paul.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process\._Worship Values and Priorities
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process\Worship Values and Priorities
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Flowchart
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Leaders Meeting
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Ministr…Core Values.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Team Expectations
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\.DS_Store
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\.DS_Store
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._1 Chronicles 16.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._1 Corinthians 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Isaiah 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Nehemiah 9.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 121.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 150.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 84.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Undivided - June 17 06.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\1 Chronicles 16.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\1 Corinthians 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Isaiah 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Nehemiah 9.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 121.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 150.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 84.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Undivided - June 17 06.doc

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 50


--- Analysing Catchme logfile ---

no matching regkeys found


Finished!

-----------------------------------------------------------------------------






Logfile of HijackThis v1.99.1
Scan saved at 11:38:02 PM, on 04/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Install Source\tomcoyote.org_HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-dcf7-f96da086b434} - C:\WINDOWS\System32\dfgaert.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMixerTray] C:\Program Files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.2\SetHook.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [mmnext06] C:\WINDOWS\System32\mstsk32.dll
O4 - HKLM\..\Run: [bxproxy] C:\DOCUME~1\Susan\LOCALS~1\Temp\dfgaert.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?9badffbfe3ba44d4b92f468407dccf64
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?9badffbfe3ba44d4b92f468407dccf64
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: pptp32 - pptp32.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe" -f (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
neilT
 
Posts: 5
Joined: Sat Jun 23, 2007 5:37 am

Postby patrik » Fri Jul 06, 2007 12:50 am

ok, looks more good.
But one question, after run HaxFix, you have selected Option 2 or no ?

If no, you should make it:
run HaxFix (HaxFix.bat) (not haxfix.exe - it`s only install package), you should view meny with options:
1. ...
2. Run auto fix by typing 2
3. ...
4. ...
....

Press key 2 for select option 2.

Post with you answer haxfix log
patrik
Site Admin
 
Posts: 9276
Joined: Sun Jan 08, 2006 1:11 pm

HaxFix logfiles

Postby neilT » Sun Jul 08, 2007 7:00 pm

Thanks Patrik

HAXFIX logfile - by Marckie

version 4.47
08/07/2007 12:56:42.09

--- Checking for Haxdoor ---

checking for a3d files
a3d files not found

checking for matching notify keys
matching notify keys found
pptp

checking for matching services
matching services found
Aspi32

checking for matching safeboot services
no matching safeboot services found

checking for other Haxdoor-files
no other Haxdoor-files found


--- Checking for Goldun ---

checking for SSODL keys
no ssodl keys found

checking for notify keys
no notify keys found

checking for services
no services found

checking for other Goldun-files
no other Goldun-files found

checking iexplore.exe
iexplore.exe is not infected


--- Catchme logfile - thank you Gmer ---

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-08 12:56:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service -- Paul
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Expectations fo…ip Ministry.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Mission Statement
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sun. Report
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Schedule
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Schedule.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service -- Paul
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service -- Paul.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Sunday Service.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Vision in process
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Flowchart
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Leaders Meeting
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Ministr…Core Values.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\._Worship Team Expectations
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Expectations fo…ip Ministry.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Mission Statement
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sun. Report
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Schedule
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Schedule.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service -- Paul.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Sunday Service.pdf
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process\._Worship Values and Priorities
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Vision in process\Worship Values and Priorities
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Flowchart
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Leaders Meeting
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Ministr…Core Values.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Worship Team Docs.\Worship Team Expectations
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\.DS_Store
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\.DS_Store
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._1 Chronicles 16.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._1 Corinthians 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Isaiah 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Nehemiah 9.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 121.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 150.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Psalm 84.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\._Undivided - June 17 06.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\1 Chronicles 16.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\1 Corinthians 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Isaiah 6.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Nehemiah 9.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 121.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 150.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Psalm 84.doc
C:\Shared Data\Everybody\Worship -- From Mike's Computer\Undivided Docs.\June 17\Undivided - June 17 06.doc

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 49


--- Analysing Catchme logfile ---

no matching regkeys found


Finished!
neilT
 
Posts: 5
Joined: Sat Jun 23, 2007 5:37 am


Return to Archived Logs

Who is online

Users browsing this forum: No registered users and 0 guests