Hi Gringo
Sorry for posting the wrong log earlier. I had them both open on the task bar and obviously posted the same one twice. Here are my new logs.
ComboFix 08-05-11.1 - Boss 2008-05-12 21:51:14.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.134 [GMT 10:00]
Running from: C:\Documents and Settings\Boss\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Boss\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-04-12 to 2008-05-12 )))))))))))))))))))))))))))))))
.
2008-05-06 19:38 . 2008-05-06 19:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-04 18:12 . 2008-05-04 18:12 <DIR> d-------- C:\Program Files\CleanUp!
2008-05-04 11:40 . 2008-05-04 11:40 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-04 11:39 . 2008-05-04 11:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-02 14:56 . 2008-05-04 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-28 17:15 . 2008-04-28 17:15 12,297,167 --------- C:\avg7qt.dat
2008-04-21 16:45 . 2008-05-05 12:39 <DIR> d-------- C:\Program Files\NavigationTool
2008-04-15 21:06 . 2008-04-15 21:06 <DIR> d-------- C:\Program Files\Red Kawa
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 11:03 --------- d-----w C:\Program Files\NavigationEnhancer
2008-05-12 10:56 --------- d-----w C:\Documents and Settings\Boss\Application Data\AVG7
2008-05-04 08:05 --------- d-----w C:\Program Files\LimeWire
2008-05-04 08:00 --------- d-----w C:\Documents and Settings\Boss\Application Data\LimeWire
2008-05-02 04:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-02 04:39 --------- d-----w C:\Program Files\Google
2008-04-21 06:47 --------- d-----w C:\Program Files\FBrowserAdvisor
2008-04-07 08:12 --------- d-----w C:\Program Files\Picasa2
2008-04-01 10:39 --------- d-----w C:\Program Files\Java
2008-04-01 10:35 --------- d-----w C:\Program Files\Common Files\Java
2008-03-27 13:45 --------- d-----r C:\Documents and Settings\Boss\Application Data\Brother
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\win32k.sys
2008-03-14 06:05 385,024 ----a-w C:\WINDOWS\system32\WinNB55.dll
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2006-03-15 04:19 212,992 ------w C:\WINDOWS\inf\WG311v3\CopyWHQLDriver.exe
2006-01-26 07:55 280,576 ------w C:\WINDOWS\inf\WG311v3\WG311v3.sys
2005-10-06 05:17 280,576 ------w C:\WINDOWS\inf\WG311v3\WG311v3XP.sys
.
((((((((((((((((((((((((((((( snapshot@2008-05-12_ 7.57.18.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-11 21:41:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-12 06:25:46 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{391C0909-C026-3B63-FFDB-93FFF4E81675}]
2007-12-31 06:48 1019904 --a------ C:\Program Files\NavigationEnhancer\NavigationEnhancer-4.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-22 19:44 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"SiSPower"="SiSPower.dll" [2007-10-03 15:58 53248 C:\WINDOWS\system32\SiSPower.dll]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
"PE2CKFNT SE"="C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 12:51 25088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-16 19:37 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"MDNS"="C:\WINDOWS\system32\service.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-24 09:33 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 06:05:56 65588]
NETGEAR WG311v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe [2006-01-26 17:55:04 1486848]
Photo Express Calendar Checker SE.lnk - C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2008-01-22 13:43:38 55296]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R2 ScFBPNT2;CanoScan FBP2 Port Driver;C:\WINDOWS\system32\drivers\ScFBPNT2.SYS [1999-05-21 01:00]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-12 21:53:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-12 21:54:44
ComboFix-quarantined-files.txt 2008-05-12 11:54:37
ComboFix2.txt 2008-05-11 21:57:34
Pre-Run: 9,018,957,824 bytes free
Post-Run: 8,995,475,456 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
102 --- E O F --- 2008-04-14 12:51:01
ComboFix 08-05-11.1 - 2008-05-12 22:06:24.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.112 [GMT 10:00]Running from: C:\Documents and Settings\Boss\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Boss\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\service.exe
C:\WINDOWS\system32\WinNB55.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\NavigationTool
C:\Program Files\NavigationTool\NavigationTool.dat
C:\Program Files\NavigationTool\pcre3.dll
C:\Program Files\NavigationTool\uninstall.exe
C:\WINDOWS\system32\WinNB55.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-12 to 2008-05-12 )))))))))))))))))))))))))))))))
.
2008-05-06 19:38 . 2008-05-06 19:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-04 18:12 . 2008-05-04 18:12 <DIR> d-------- C:\Program Files\CleanUp!
2008-05-04 11:40 . 2008-05-04 11:40 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-04 11:39 . 2008-05-04 11:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-02 14:56 . 2008-05-04 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-28 17:15 . 2008-04-28 17:15 12,297,167 --------- C:\avg7qt.dat
2008-04-15 21:06 . 2008-04-15 21:06 <DIR> d-------- C:\Program Files\Red Kawa
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 10:56 --------- d-----w C:\Documents and Settings\Boss\Application Data\AVG7
2008-05-04 08:00 --------- d-----w C:\Documents and Settings\Boss\Application Data\LimeWire
2008-05-02 04:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-02 04:39 --------- d-----w C:\Program Files\Google
2008-04-21 06:47 --------- d-----w C:\Program Files\FBrowserAdvisor
2008-04-07 08:12 --------- d-----w C:\Program Files\Picasa2
2008-04-01 10:39 --------- d-----w C:\Program Files\Java
2008-04-01 10:35 --------- d-----w C:\Program Files\Common Files\Java
2008-03-27 13:45 --------- d-----r C:\Documents and Settings\Boss\Application Data\Brother
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2006-03-15 04:19 212,992 ------w C:\WINDOWS\inf\WG311v3\CopyWHQLDriver.exe
2006-01-26 07:55 280,576 ------w C:\WINDOWS\inf\WG311v3\WG311v3.sys
2005-10-06 05:17 280,576 ------w C:\WINDOWS\inf\WG311v3\WG311v3XP.sys
.
((((((((((((((((((((((((((((( snapshot@2008-05-12_ 7.57.18.01 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-11 21:41:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-12 06:25:46 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-12 12:08:16 53,248 ----a-w C:\WINDOWS\TEMP\catchme.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-22 19:44 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"SiSPower"="SiSPower.dll" [2007-10-03 15:58 53248 C:\WINDOWS\system32\SiSPower.dll]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
"PE2CKFNT SE"="C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 12:51 25088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-16 19:37 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-24 09:33 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 06:05:56 65588]
NETGEAR WG311v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe [2006-01-26 17:55:04 1486848]
Photo Express Calendar Checker SE.lnk - C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2008-01-22 13:43:38 55296]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
R2 ScFBPNT2;CanoScan FBP2 Port Driver;C:\WINDOWS\system32\drivers\ScFBPNT2.SYS [1999-05-21 01:00]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-12 22:08:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-12 22:09:48
ComboFix-quarantined-files.txt 2008-05-12 12:09:40
ComboFix2.txt 2008-05-12 11:54:45
ComboFix3.txt 2008-05-11 21:57:34
Pre-Run: 8,993,153,024 bytes free
Post-Run: 8,984,059,904 bytes free
99 --- E O F --- 2008-04-14 12:51:01
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:54 PM, on 12/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\NETGEAR\WG311v3\WinDomainlogon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NETGEAR WG311v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) -
http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) -
http://www.sis.com/ocis/SiSAutodetectNT.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
--
End of file - 5140 bytes
A friend of my sons installed MSN and Limewire on to his computer. I have tried to uninstall both. Limewire does not appear on add/remove programs list and I have deleted the Limewire folder in Program files. Is there anything else I need to do to be assured that all traces of Limewire are completely removed from his computer. Also can you tell me how to be sure that I can completely remove all trace of MSN from his system as well.
Thanks for your help. It is much appreicated.