This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

win:32 parite file infected

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I need help trying to clean my son's computer.
I ran an avast scan and it shows 253 files infected with threat: win32:parite

I tried to move it to the chest but it says not enough disk space although there is 78 GB of free space.

Malwarebytes hasn't found any malicious threats.

Any help is greatly appreciated.

Here is the OTL log


OTL logfile created on: 22/7/2010 3:33:00 μμ - Run 4
OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\Alex\Τα έγγραφά μου\Ληφθέντα αρχεία
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000*** | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy

1.015,00 Mb Total Physical Memory | 395,00 Mb Available Physical Memory | 39,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 69,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149,04 Gb Total Space | 77,88 Gb Free Space | 52,26% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ***
Current User Name: ***
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/07/22 15:27:56 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Alex\Τα έγγραφά μου\Ληφθέντα αρχεία\OTL.exe
PRC - [2010/07/19 15:07:26 | 000,134,808 | —- | M] (Google Inc.) – C:\Documents and Settings\Alex\Local Settings\Application Data\Google\Update\1.2.183.29\GoogleCrashHandler.exe
PRC - [2010/07/09 22:04:34 | 003,493,776 | —- | M] (Xfire Inc.) – C:\Program Files\Xfire\Xfire.exe
PRC - [2010/07/04 22:51:26 | 000,017,408 | —- | M] () – C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2010/07/02 11:23:56 | 002,403,568 | —- | M] (SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
PRC - [2010/06/28 23:57:18 | 002,837,864 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/06/28 23:57:15 | 000,040,384 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/02/04 14:39:53 | 000,198,160 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/01/11 17:28:34 | 000,113,152 | —- | M] () – C:\WINDOWS\svcadmin.exe
PRC - [2009/10/27 21:46:16 | 000,323,392 | —- | M] (BitTorrent, Inc.) – C:\Program Files\DNA\btdna.exe
PRC - [2009/04/02 01:51:00 | 000,288,560 | —- | M] (syncables, LLC) – C:\Program Files\syncables\syncables desktop\MigoMapi.exe
PRC - [2009/04/02 01:51:00 | 000,173,360 | —- | M] (syncables, LLC) – C:\Program Files\syncables\syncables desktop\Syncables.exe
PRC - [2009/04/02 01:51:00 | 000,135,168 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\syncables\syncables desktop\jre\bin\javaw.exe
PRC - [2009/03/30 23:47:00 | 000,483,428 | —- | M] (IDT, Inc.) – C:\Program Files\IDT\WDM\sttray.exe
PRC - [2009/03/30 23:47:00 | 000,254,042 | —- | M] (IDT, Inc.) – c:\Program Files\IDT\WDM\stacsv.exe
PRC - [2009/03/30 16:02:08 | 000,319,488 | —- | M] () – C:\Program Files\HP\HPBTWD.exe
PRC - [2009/02/26 15:24:50 | 000,097,680 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
PRC - [2009/02/19 00:41:56 | 000,737,280 | —- | M] (Andrea Electronics Corporation) – C:\WINDOWS\system32\AESTFltr.exe
PRC - [2008/12/11 22:46:22 | 000,125,424 | —- | M] () – C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
PRC - [2008/07/07 15:12:42 | 000,600,680 | —- | M] (Broadcom Corporation.) – C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2008/04/16 15:00:00 | 001,038,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/10/23 10:45:40 | 001,336,632 | —- | M] () – C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe
PRC - [2003/05/28 12:37:00 | 000,118,784 | —- | M] () – C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe


========== Modules (SafeList) ==========

MOD - [2010/07/22 15:27:56 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Alex\Τα έγγραφά μου\Ληφθέντα αρχεία\OTL.exe
MOD - [2010/07/09 22:04:44 | 000,970,640 | —- | M] (Xfire Inc.) – C:\Program Files\Xfire\xfire_toucan_43094.dll
MOD - [2010/07/05 00:32:36 | 000,004,608 | —- | M] () – C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2008/07/07 15:11:06 | 000,073,728 | —- | M] (Broadcom Corporation.) – C:\WINDOWS\system32\BtMmHook.dll
MOD - [2008/07/07 15:08:46 | 000,040,960 | —- | M] () – C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
MOD - [2008/04/16 15:00:00 | 000,586,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mlang.dll
MOD - [2008/04/16 15:00:00 | 000,027,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wsock32.dll
MOD - [2004/01/12 00:00:00 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (RichVideo) Cyberlink RichVideo Service(CRVS)
SRV - File not found [On_Demand | Stopped] – – (gusvc)
SRV - File not found [Auto | Stopped] – – (gupdate) Google Update Service (gupdate)
SRV - [2010/06/28 23:57:15 | 000,040,384 | —- | M] (AVAST Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Web Scanner)
SRV - [2010/06/28 23:57:15 | 000,040,384 | —- | M] (AVAST Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Mail Scanner)
SRV - [2010/06/28 23:57:15 | 000,040,384 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2010/01/11 17:28:34 | 000,113,152 | —- | M] () [Auto | Running] – C:\WINDOWS\svcadmin.exe – (Anyplace Control Security)
SRV - [2009/10/12 00:27:07 | 003,369,044 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\System32\GameMon.des – (npggsvc)
SRV - [2009/03/30 23:47:00 | 000,254,042 | —- | M] (IDT, Inc.) [Auto | Running] – c:\Program Files\IDT\WDM\stacsv.exe – (STacSV)
SRV - [2008/12/11 22:46:22 | 000,125,424 | —- | M] () [Auto | Running] – C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe – (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269)


========== Driver Services (SafeList) ==========

DRV - [2010/06/28 23:37:52 | 000,046,672 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aswTdi.sys – (aswTdi)
DRV - [2010/06/28 23:37:30 | 000,165,456 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aswSP.sys – (aswSP)
DRV - [2010/06/28 23:33:13 | 000,023,376 | —- | M] (ALWIL Software) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\aswRdr.sys – (aswRdr)
DRV - [2010/06/28 23:32:45 | 000,100,176 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswmon2.sys – (aswMon2)
DRV - [2010/06/28 23:32:33 | 000,017,744 | —- | M] (ALWIL Software) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2010/06/28 23:32:16 | 000,028,880 | —- | M] (ALWIL Software) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2010/06/15 23:19:16 | 000,004,096 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nocashio.sys – (nocashio)
DRV - [2010/05/31 13:36:37 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 11:25:50 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2010/02/17 11:15:58 | 000,012,872 | R— | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM)
DRV - [2009/10/17 01:22:53 | 000,015,781 | —- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2009/08/05 22:48:42 | 000,054,752 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys – (fssfltr)
DRV - [2009/06/09 17:52:37 | 001,735,040 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2009/03/30 23:47:00 | 001,550,891 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA)
DRV - [2009/03/19 21:55:06 | 000,113,664 | —- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AESTAud.sys – (AESTAud)
DRV - [2009/03/03 00:03:48 | 000,038,912 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1c51x86.sys – (L1c)
DRV - [2009/01/16 05:41:00 | 000,206,512 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2008/12/11 01:00:00 | 000,025,584 | —- | M] (Sonic Solutions) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\SaibVd32.sys – (SaibVd32)
DRV - [2008/12/11 01:00:00 | 000,021,488 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\SahdIa32.sys – (SahdIa32)
DRV - [2008/12/11 01:00:00 | 000,015,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\SaibIa32.sys – (SaibIa32)
DRV - [2008/11/22 04:36:46 | 000,160,256 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RTS5121.sys – (RSUSBSTOR)
DRV - [2008/09/24 22:09:40 | 000,103,792 | —- | M] (Sonic Solutions) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\syscow32x.sys – (SysCow)
DRV - [2008/09/13 08:32:00 | 000,327,192 | —- | M] (Intel Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2008/07/25 04:37:04 | 000,047,272 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\btwusb.sys – (BTWUSB)
DRV - [2008/06/24 20:59:08 | 000,991,400 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\btkrnl.sys – (btkrnl)
DRV - [2008/04/16 15:00:00 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/04/16 15:00:00 | 000,088,320 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnkipx.sys – (NwlnkIpx)
DRV - [2008/04/16 15:00:00 | 000,063,232 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnknb.sys – (NwlnkNb)
DRV - [2008/04/16 15:00:00 | 000,055,936 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\nwlnkspx.sys – (NwlnkSpx)
DRV - [2008/04/14 17:06:40 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/14 17:06:40 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/02/16 01:12:06 | 005,854,752 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm)
DRV - [2007/08/14 08:12:44 | 000,005,760 | —- | M] (Sophos Plc) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\21D.tmp – (MEMSWEEP2)
DRV - [2005/10/16 08:00:00 | 000,012,928 | —- | M] (Bo Brantén) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\filedisk.sys – (FileDisk)
DRV - [2005/01/03 00:43:08 | 000,004,682 | —- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\npptNT2.sys – (NPPTNT2)
DRV - [2001/11/27 15:59:14 | 000,006,784 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2001/08/18 14:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/18 14:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/18 14:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/18 14:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/18 14:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/18 13:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/18 13:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/18 13:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/18 13:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/18 13:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/18 13:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/18 13:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/18 13:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/18 13:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.gr/firefox"
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21

FF - HKLM\software\mozilla\Firefox\extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\PremierOpinion
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/19 14:49:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/19 14:49:25 | 000,000,000 | —D | M]

[2010/07/13 19:25:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Alex\Application Data\Mozilla\Extensions
[2010/07/13 19:25:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Alex\Application Data\Mozilla\Extensions\[removed]
[2010/07/19 17:18:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\idww0b55.default\extensions
[2010/07/05 16:39:05 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Alex\Application Data\Mozilla\Firefox\Profiles\idww0b55.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/19 17:18:29 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/19 15:05:28 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/19 15:04:16 | 000,423,656 | —- | M] (Oracle) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/06/26 10:28:18 | 000,001,525 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/06/26 10:28:18 | 000,000,760 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/06/26 10:28:18 | 000,001,219 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-el.xml

O1 HOSTS File: ([2010/04/23 22:07:50 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (CescrtHlpr Object) - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.3.62.1\facemoods.dll (facemoods.com)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0559.0\msneshellx.dll File not found
O2 - BHO: (Nuclear Games Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll (Cooliris Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0559.0\msneshellx.dll File not found
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKLM\..\Toolbar: (Nuclear Games Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (facemoods Toolbar) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.3.62.1\facemoodsTlbr.dll (facemoods.com)
O3 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll File not found
O3 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006\..\Toolbar\WebBrowser: (Nuclear Games Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe File not found
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HP BTW Detect Program] C:\Program Files\HP\HPBTWD.exe ()
O4 - HKLM..\Run: [Syncables] C:\Program Files\syncables\syncables desktop\Syncables.exe (syncables, LLC)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe File not found
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe (Take-Two Interactive Software, Inc.)
O4 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006..\Run: [Steam] C:\Program Files\Steam\Steam.exe File not found
O4 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006..\Run: [STManager] C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe ()
O4 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O4 - Startup: C:\Documents and Settings\Alex\Start Menu\Προγράμματα\Εκκίνηση\LaunchU3.exe.lnk = C:\Documents and Settings\Alex\Application Data\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe ()
O4 - Startup: C:\Documents and Settings\Alex\Start Menu\Προγράμματα\Εκκίνηση\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Alex\Start Menu\Προγράμματα\Εκκίνηση\OneNote Table Of Contents.onetoc2 ()
O4 - Startup: C:\Documents and Settings\Alex\Start Menu\Προγράμματα\Εκκίνηση\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\Αlexandra\Start Menu\Προγράμματα\Εκκίνηση\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1329424299-2075852907-1434492207-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Αποστολή σε Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Αποστολή στη συσκευή &Bluetooth;… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll (Cooliris Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} http://view.conn-x.gr/surveillance/software/mpeg4_dec.cab (Moonlight MPEG-4 Video Decoder)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {67B1A88A-B5D2-48B1-BF93-EB74D6FCB077} http://view.conn-x.gr/surveillance/software/AMC.cab (AxisRTPSrcFilterEmb)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll File not found
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Τρέχουσα αρχική σελίδα) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Alex\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Alex\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{78366410-670e-11df-8dee-0025b37102d0}\Shell\AutoRun\command - "" = __DTMEDIA\DTMedia.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/10/04 01:38:50 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: midi - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - C:\WINDOWS\System32\midimap.dll (Microsoft Corporation)
Drivers32: mixer - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.imaadpcm - C:\WINDOWS\System32\imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - lhacm.acm File not found
Drivers32: msacm.msadpcm - C:\WINDOWS\System32\msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msaudio1 - C:\WINDOWS\System32\msaud32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - C:\WINDOWS\System32\msg711.acm (Microsoft Corporation)
Drivers32: msacm.msg723 - C:\WINDOWS\System32\msg723.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - C:\WINDOWS\System32\msgsm32.acm (Microsoft Corporation)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.IYUV - C:\WINDOWS\System32\iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.M261 - C:\WINDOWS\System32\msh261.drv (Microsoft Corporation)
Drivers32: vidc.M263 - C:\WINDOWS\System32\msh263.drv (Microsoft Corporation)
Drivers32: vidc.mrle - C:\WINDOWS\System32\msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - C:\WINDOWS\System32\msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.XFR1 - C:\WINDOWS\System32\xfcodec.dll ()
Drivers32: VIDC.YUY2 - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - C:\WINDOWS\System32\tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - C:\WINDOWS\System32\msyuv.dll (Microsoft Corporation)
Drivers32: wave - C:\WINDOWS\System32\wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - C:\WINDOWS\System32\msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/07/22 15:09:32 | 000,038,848 | —- | C] (ALWIL Software) – C:\WINDOWS\avastSS.scr
[2010/07/19 20:57:38 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\winhlp32.exe
[2010/07/19 20:57:37 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\taskman.exe
[2010/07/19 20:57:34 | 000,025,600 | —- | C] (Twain Working Group) – C:\WINDOWS\twunk_32.exe
[2010/07/19 16:29:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Τα έγγραφά μου\Ληφθέντα αρχεία
[2010/07/19 15:05:21 | 000,073,728 | —- | C] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/07/19 15:05:20 | 000,153,376 | —- | C] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/07/19 15:05:20 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/07/19 15:05:20 | 000,145,184 | —- | C] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/07/19 15:04:03 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/07/19 12:47:47 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/07/18 16:55:01 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/07/17 23:23:21 | 000,000,000 | —D | C] – C:\Program Files\Counter-Strike 1.6
[2010/07/17 15:19:44 | 000,165,456 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010/07/17 15:19:44 | 000,017,744 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/07/17 15:19:41 | 000,023,376 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/07/17 15:19:39 | 000,046,672 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/07/17 15:19:36 | 000,100,176 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/07/17 15:19:36 | 000,094,544 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010/07/17 15:19:35 | 000,028,880 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/07/17 15:17:25 | 000,165,032 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010/07/17 12:59:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Patch
[2010/07/17 12:54:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\system
[2010/07/16 13:59:08 | 000,000,000 | —D | C] – C:\Program Files\Wolfenstein - Enemy Territory
[2010/07/16 11:52:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Saved Games
[2010/07/16 11:52:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Floodlight Games
[2010/07/16 11:52:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\Floodlight Games
[2010/07/15 21:44:40 | 000,000,000 | —D | C] – C:\Program Files\Nice-Games
[2010/07/15 21:24:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/07/15 15:54:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\Sahmon Games
[2010/07/14 22:19:21 | 000,000,000 | —D | C] – C:\Program Files\Steam
[2010/07/14 21:11:18 | 000,000,000 | —D | C] – C:\Program Files\GameTop.com
[2010/07/14 13:32:16 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[2010/07/14 11:56:50 | 001,414,440 | —- | C] (Nero AG) – C:\WINDOWS\System32\ShellManager310E2D762.dll
[2010/07/13 19:28:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\Vivox
[2010/07/13 19:25:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\IMVU
[2010/07/13 19:24:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\IMVUClient
[2010/07/13 18:17:08 | 000,000,000 | —D | C] – C:\Netgame
[2010/07/13 13:50:36 | 000,000,000 | —D | C] – C:\Program Files\Z8Games
[2010/07/12 20:08:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\supertuxkart
[2010/07/12 17:52:39 | 000,000,000 | —D | C] – C:\Program Files\OpenAL
[2010/07/12 17:52:38 | 000,444,952 | —- | C] (Creative Labs) – C:\WINDOWS\System32\wrap_oal.dll
[2010/07/12 17:52:38 | 000,109,080 | —- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\WINDOWS\System32\OpenAL32.dll
[2010/07/12 17:46:32 | 000,000,000 | —D | C] – C:\Alien Arena 7_40
[2010/07/12 16:30:14 | 000,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2010/07/12 13:50:45 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Xfire
[2010/07/11 18:54:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Τα έγγραφά μου\Cross Fire
[2010/07/11 18:54:13 | 000,000,000 | —D | C] – C:\CFLog
[2010/07/11 18:13:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\facemoods.com
[2010/07/11 17:58:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\Xfire
[2010/07/11 17:57:35 | 000,000,000 | —D | C] – C:\Program Files\Xfire
[2010/07/11 11:40:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Local Settings\Application Data\Rockstar Games
[2010/07/11 11:38:12 | 000,000,000 | —D | C] – C:\Program Files\Rockstar Games
[2010/07/08 18:06:56 | 003,369,044 | —- | C] (INCA Internet Co., Ltd.) – C:\WINDOWS\System32\GameMon.des
[2010/07/08 18:06:27 | 000,004,682 | —- | C] (INCA Internet Co., Ltd.) – C:\WINDOWS\System32\npptNT2.sys
[2010/07/08 18:05:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\INCA Shared
[2010/07/08 16:29:41 | 000,000,000 | —D | C] – C:\Program Files\facemoods.com
[2010/07/08 15:36:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\uTorrent
[2010/07/07 14:27:39 | 000,000,000 | —D | C] – C:\Program Files\Windows Garbage Collector
[2010/07/07 14:24:00 | 000,000,000 | —D | C] – C:\Program Files\Unlocker
[2010/07/04 16:39:02 | 000,000,000 | —D | C] – C:\TEMP
[2010/07/04 15:26:15 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2010/07/04 13:28:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Anyplace Control 4
[2010/07/04 13:01:26 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Local Settings\Application Data\CrossLoop
[2010/07/03 19:39:08 | 000,038,912 | —- | C] (RealVNC Ltd.) – C:\vnchooks.dll
[2010/07/03 19:27:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\TeamViewer
[2010/07/03 18:55:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Ôá ÝããñáöÜ ìïõ
[2010/07/03 18:53:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Τα έγγραφά μου\Battlefield 2
[2010/07/03 18:41:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Τα έγγραφά μου\Crazy Taxi 3
[2010/07/03 12:48:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Jugilus
[2010/07/03 12:44:50 | 000,000,000 | —D | C] – C:\Program Files\bfgclient
[2010/07/01 13:05:29 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex\Application Data\Mozilla
[2010/07/01 12:41:55 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/05/30 16:45:33 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/05/29 18:49:12 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/02/12 17:05:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2009/10/26 21:04:00 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/10/26 20:59:05 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/10/04 01:38:11 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/10/04 01:38:11 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/22 15:12:05 | 000,001,274 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1329424299-2075852907-1434492207-1006UA.job
[2010/07/22 15:12:02 | 000,001,222 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1329424299-2075852907-1434492207-1006Core.job
[2010/07/22 15:09:33 | 000,003,023 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/07/22 15:01:37 | 000,000,454 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{654D911E-481C-43FE-81C7-99ED4C05CABD}.job
[2010/07/22 14:58:44 | 000,002,659 | —- | M] () – C:\Documents and Settings\Alex\Start Menu\Προγράμματα\Εκκίνηση\LaunchU3.exe.lnk
[2010/07/22 14:57:14 | 000,001,178 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/22 14:57:14 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/07/22 14:55:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/07/22 14:55:43 | 1064,620,032 | -HS- | M] () – C:\hiberfil.sys
[2010/07/22 14:28:55 | 009,699,328 | —- | M] () – C:\Documents and Settings\Alex\ntuser.dat
[2010/07/22 14:28:51 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Alex\ntuser.ini
[2010/07/22 14:28:18 | 003,766,370 | -H– | M] () – C:\Documents and Settings\Alex\Local Settings\Application Data\IconCache.db
[2010/07/22 02:01:04 | 000,000,924 | —- | M] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Συντόμευση για το HiJackThis.lnk
[2010/07/21 18:13:49 | 000,000,372 | —- | M] () – C:\Documents and Settings\Alex\Τα έγγραφά μου\spider.sav
[2010/07/21 17:03:49 | 001,162,174 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/21 17:03:49 | 000,548,378 | —- | M] () – C:\WINDOWS\System32\perfh008.dat
[2010/07/21 17:03:49 | 000,438,390 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/21 17:03:49 | 000,093,878 | —- | M] () – C:\WINDOWS\System32\perfc008.dat
[2010/07/21 17:03:49 | 000,070,320 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/21 16:54:00 | 000,001,182 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/21 16:49:52 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\{F897AA24-BDC3-11D1-B85B-00C04FB93981}_ΑΛΕΞ_Alex.job
[2010/07/19 17:03:50 | 000,000,747 | —- | M] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Counter-Strike 1.6.lnk
[2010/07/19 15:09:51 | 000,002,277 | —- | M] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Google Chrome.lnk
[2010/07/19 15:04:12 | 000,153,376 | —- | M] (Oracle) – C:\WINDOWS\System32\javaws.exe
[2010/07/19 15:04:12 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\javaw.exe
[2010/07/19 15:04:12 | 000,145,184 | —- | M] (Oracle) – C:\WINDOWS\System32\java.exe
[2010/07/19 15:04:12 | 000,073,728 | —- | M] (Oracle) – C:\WINDOWS\System32\javacpl.cpl
[2010/07/19 15:04:10 | 000,423,656 | —- | M] (Oracle) – C:\WINDOWS\System32\deployJava1.dll
[2010/07/18 14:18:10 | 269,350,966 | —- | M] () – C:\Documents and Settings\Alex\Τα έγγραφά μου\Counter Strike 1.6 Reloaded1.7z
[2010/07/17 14:22:28 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/16 15:20:58 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/07/14 12:20:41 | 000,000,000 | —- | M] () – C:\WINDOWS\lgfwup.ini
[2010/07/13 13:49:42 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/07/12 17:52:39 | 000,444,952 | —- | M] (Creative Labs) – C:\WINDOWS\System32\wrap_oal.dll
[2010/07/12 17:52:38 | 000,109,080 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\WINDOWS\System32\OpenAL32.dll
[2010/07/12 17:52:34 | 000,000,088 | —- | M] () – C:\WINDOWS\galaxy.ini
[2010/07/11 17:57:59 | 000,000,650 | —- | M] () – C:\Documents and Settings\Alex\Start Menu\Προγράμματα\Εκκίνηση\Xfire.lnk
[2010/07/09 22:04:40 | 000,041,872 | —- | M] () – C:\WINDOWS\System32\xfcodec.dll
[2010/07/08 19:32:46 | 000,000,765 | —- | M] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Lineage II.lnk
[2010/07/08 12:06:53 | 000,000,029 | —- | M] () – C:\WINDOWS\PControl.ini
[2010/07/03 19:31:56 | 000,053,248 | —- | M] () – C:\othread2.dll
[2010/07/03 19:31:56 | 000,038,912 | —- | M] (RealVNC Ltd.) – C:\vnchooks.dll
[2010/07/03 18:51:22 | 000,014,336 | —- | M] () – C:\Documents and Settings\Alex\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/02 18:47:31 | 000,000,124 | —- | M] () – C:\My Bluetooth Places (Οι θέσεις Bluetooth μου).lnk
[2010/07/02 14:48:54 | 000,000,100 | —- | M] () – C:\WINDOWS\dinksmallwood.ini
[2010/07/01 12:42:33 | 000,001,602 | —- | M] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Mozilla Firefox.lnk
[2010/06/28 23:57:33 | 000,038,848 | —- | M] (ALWIL Software) – C:\WINDOWS\avastSS.scr
[2010/06/28 23:57:12 | 000,165,032 | —- | M] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010/06/28 23:37:52 | 000,046,672 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/06/28 23:37:30 | 000,165,456 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010/06/28 23:33:13 | 000,023,376 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/06/28 23:32:45 | 000,100,176 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/06/28 23:32:42 | 000,094,544 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010/06/28 23:32:33 | 000,017,744 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/06/28 23:32:16 | 000,028,880 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/06/24 17:51:39 | 000,000,705 | —- | M] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Play Dink Smallwood.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/22 14:17:22 | 1064,620,032 | -HS- | C] () – C:\hiberfil.sys
[2010/07/22 02:01:04 | 000,000,924 | —- | C] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Συντόμευση για το HiJackThis.lnk
[2010/07/20 23:19:54 | 000,000,372 | —- | C] () – C:\Documents and Settings\Alex\Τα έγγραφά μου\spider.sav
[2010/07/19 17:03:50 | 000,000,747 | —- | C] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Counter-Strike 1.6.lnk
[2010/07/19 15:07:31 | 000,001,274 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1329424299-2075852907-1434492207-1006UA.job
[2010/07/19 15:07:30 | 000,001,222 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1329424299-2075852907-1434492207-1006Core.job
[2010/07/18 13:53:34 | 269,350,966 | —- | C] () – C:\Documents and Settings\Alex\Τα έγγραφά μου\Counter Strike 1.6 Reloaded1.7z
[2010/07/17 14:22:28 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/07/14 12:20:41 | 000,000,000 | —- | C] () – C:\WINDOWS\lgfwup.ini
[2010/07/14 11:56:51 | 000,784,384 | —- | C] () – C:\WINDOWS\System32\NEROINSTAEC43759.DB
[2010/07/12 17:52:34 | 000,000,088 | —- | C] () – C:\WINDOWS\galaxy.ini
[2010/07/11 17:57:59 | 000,000,650 | —- | C] () – C:\Documents and Settings\Alex\Start Menu\Προγράμματα\Εκκίνηση\Xfire.lnk
[2010/07/09 22:04:40 | 000,041,872 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2010/07/08 19:32:46 | 000,000,765 | —- | C] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Lineage II.lnk
[2010/07/08 18:06:27 | 000,005,174 | —- | C] () – C:\WINDOWS\System32\nppt9x.vxd
[2010/07/08 12:02:18 | 000,000,029 | —- | C] () – C:\WINDOWS\PControl.ini
[2010/07/03 19:39:08 | 000,053,248 | —- | C] () – C:\othread2.dll
[2010/07/02 18:47:31 | 000,000,124 | —- | C] () – C:\My Bluetooth Places (Οι θέσεις Bluetooth μου).lnk
[2010/07/01 12:42:33 | 000,001,602 | —- | C] () – C:\Documents and Settings\Alex\Επιφάνεια εργασίας\Mozilla Firefox.lnk
[2010/06/29 14:24:55 | 000,340,616 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/06/15 23:19:16 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\drivers\nocashio.sys
[2010/06/14 11:49:24 | 000,139,152 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/06/14 11:49:23 | 000,139,152 | —- | C] () – C:\Documents and Settings\Alex\Application Data\PnkBstrK.sys
[2010/05/29 21:56:02 | 000,054,461 | —- | C] () – C:\Documents and Settings\Alex\AdobeFnt10.lst
[2010/03/29 22:16:15 | 000,000,162 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/03/27 14:47:29 | 000,000,083 | —- | C] () – C:\Documents and Settings\Alex\Local Settings\Application Data\X-Plane Installer.prf
[2010/03/20 22:12:05 | 000,000,100 | —- | C] () – C:\WINDOWS\dinksmallwood.ini
[2010/02/28 14:00:07 | 000,000,088 | —- | C] () – C:\Documents and Settings\Alex\Application Data\usb.inf
[2010/02/27 21:01:30 | 000,000,111 | —- | C] () – C:\WINDOWS\LOGO.INI
[2010/02/03 11:44:51 | 002,128,896 | —- | C] () – C:\Documents and Settings\Alex\Local Settings\Application Data\cooliris-win-ie-release-1.11.7.31969.en-US.msi
[2010/01/30 23:54:35 | 000,000,430 | —- | C] () – C:\Documents and Settings\Alex\Application Data\wklnhst.dat
[2010/01/30 23:00:33 | 000,014,336 | —- | C] () – C:\Documents and Settings\Alex\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/15 10:51:55 | 000,093,162 | —- | C] () – C:\Documents and Settings\Alex\Local Settings\Application Data\cooliris-win-ie-release-1.11.6.31225.en-US.msi
[2009/11/08 12:56:55 | 000,000,008 | —- | C] () – C:\Documents and Settings\Alex\Application Data\usb.dat
[2009/11/07 20:12:30 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/10/23 22:53:36 | 000,000,070 | —- | C] () – C:\Documents and Settings\Alex\Local Settings\Application Data\FASTWiz.log
[2009/10/19 18:38:29 | 009,699,328 | —- | C] () – C:\Documents and Settings\Alex\ntuser.dat
[2009/10/03 15:55:58 | 000,000,127 | —- | C] () – C:\Documents and Settings\Alex\Local Settings\Application Data\fusioncache.dat
[2009/10/03 15:55:56 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Alex\ntuser.dat.LOG
[2009/10/03 15:55:56 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Alex\ntuser.ini
[2009/10/03 15:54:53 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2009/10/03 15:54:53 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2009/06/09 18:03:30 | 000,029,900 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/06/09 17:49:29 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2008/12/01 20:33:42 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/07/07 15:11:32 | 002,854,912 | —- | C] () – C:\WINDOWS\System32\btwicons.dll
[2005/02/17 12:41:32 | 000,000,603 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 12:41:30 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll

========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.* >
[2010/05/14 22:30:23 | 000,000,238 | —- | M] () – C:\Boot.bak
[2010/05/15 01:13:16 | 000,000,308 | RHS- | M] () – C:\boot.ini
[2009/10/03 16:00:34 | 003,170,304 | RHS- | M] () – C:\Boot.sdi
[2009/10/03 16:00:33 | 183,560,527 | RHS- | M] () – C:\BootENU.wim
[2008/04/16 15:00:00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[2009/10/03 16:00:34 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2010/04/01 13:25:51 | 000,003,695 | —- | M] () – C:\CLDMA.LOG
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/05/15 01:58:28 | 000,029,577 | —- | M] () – C:\ComboFix.txt
[2009/10/24 15:32:41 | 000,000,281 | —- | M] () – C:\debugInstaller.txt
[2009/10/10 00:23:32 | 000,000,000 | —- | M] () – C:\exit_c-g.jpg
[2009/10/18 17:51:07 | 000,000,000 | —- | M] () – C:\exit_c.jpg
[2009/10/10 00:23:32 | 000,000,000 | —- | M] () – C:\exit_o-g.jpg
[2009/10/18 17:51:07 | 000,000,000 | —- | M] () – C:\exit_o.jpg
[2010/07/22 14:55:43 | 1064,620,032 | -HS- | M] () – C:\hiberfil.sys
[2009/10/10 00:23:32 | 000,000,000 | —- | M] () – C:\home_c-g.jpg
[2009/10/18 17:51:07 | 000,000,000 | —- | M] () – C:\home_c.jpg
[2009/10/10 00:23:32 | 000,000,000 | —- | M] () – C:\home_o-g.jpg
[2009/10/18 17:51:07 | 000,000,000 | —- | M] () – C:\home_o.jpg
[2009/10/24 10:49:02 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/28 13:26:02 | 000,230,410 | —- | M] () – C:\Lemm_log.txt
[2010/04/30 12:14:20 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/11/09 22:51:21 | 000,071,696 | —- | M] () – C:\mdebug.log
[2009/10/24 10:49:02 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/07/02 18:47:31 | 000,000,124 | —- | M] () – C:\My Bluetooth Places (Οι θέσεις Bluetooth μου).lnk
[2008/04/16 15:00:00 | 000,047,564 | -HS- | M] () – C:\NTDETECT.COM
[2008/04/16 15:00:00 | 000,252,256 | -HS- | M] () – C:\NTLDR
[2010/07/03 19:31:56 | 000,053,248 | —- | M] () – C:\othread2.dll
[2010/07/22 14:55:41 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2009/10/10 00:23:32 | 000,000,000 | —- | M] () – C:\save_c-g.jpg
[2009/10/18 17:51:07 | 000,000,000 | —- | M] () – C:\save_c.jpg
[2009/10/10 00:23:32 | 000,000,000 | —- | M] () – C:\save_o-g.jpg
[2009/10/18 17:51:07 | 000,000,000 | —- | M] () – C:\save_o.jpg
[2009/10/03 16:18:08 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/10/03 20:04:13 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/10/03 20:26:58 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/10/03 21:19:53 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/10/03 22:52:06 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/10/04 10:39:50 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/10/03 16:18:08 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/10/03 20:04:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/10/03 20:26:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/10/03 21:19:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/10/03 22:52:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/10/04 10:39:50 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/10/18 17:51:07 | 000,000,000 | —- | M] () – C:\uk_c.bmp
[2009/10/18 17:51:07 | 000,000,000 | —- | M] () – C:\uk_o.bmp
[2010/07/03 19:31:56 | 000,038,912 | —- | M] (RealVNC Ltd.) – C:\vnchooks.dll
[2009/07/08 03:11:18 | 000,197,915 | —- | M] () – C:\wubildr
[2009/07/08 03:11:18 | 000,008,192 | —- | M] () – C:\wubildr.mbr

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/12/01 19:51:44 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 15:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >
[2010/06/28 23:57:33 | 000,038,848 | —- | M] (ALWIL Software) – C:\WINDOWS\avastSS.scr

< %systemroot%\*._sy >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/12/01 21:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/12/01 21:47:18 | 001,073,152 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/12/01 21:47:18 | 000,450,560 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/16 15:00:00 | 000,580,608 | —- | M] (Microsoft Corporation) MD5=5BB2A1C2290E910AE145C80DF491B600 – C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/16 15:00:00 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=EC57996DC47ADF15ECD1C65E6AB5613F – C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/16 15:00:00 | 000,019,968 | —- | M] (Microsoft Corporation) MD5=2AFC6866F8E07625D38CDE0991B20B4E – C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-06-23 07:14:54

========== Alternate Data Streams ==========

@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:F5F96E70
@Alternate Data Stream - 12 bytes -> C:\WINDOWS\system32:{DA6227CB-326B-4B4D-9A81-04B61F1538DD}
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:D0D0FFBF
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:5C321E34
< End of report >
Hello alexger and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Before we begin, please scan your system with the following tool. If you encounter any problems come back and let me know :)

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Hello JonTom,
Thank you very much for your reply.
I have tried running GMER but I encounter several problems even in safe mode. The scan does not complete and the computer restarts itself. Then I get a "your computer has recovered from a serious error" and sometimes a blue screen.
I managed to save a log before it completed therefore please keep in mind that it is incomplete.
I also ran an online scan with bit defender and it gave me this :
Found 1 infected file!———————-
C:\DOCUME~1\Alex\LOCALS~1\Temp\dvb4A.tmp –> Trojan.Generic.2616149
–> Process Explorer.EXE (1124)

Please let me know if you would like to see the whole Bit defender log.

Here is the incomplete gmer log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-25 09:18:55
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Alex\LOCALS~1\Temp\pxtdypow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAA2B4CD2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAA2B4B8E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xAA2B5142]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAA2B506C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAA2B4764]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAA2B4C68]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAA2B46A4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAA2B4708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAA2B4D88]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xAA2B5210]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAA2B4D48]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAA2B4EC8]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAA468620]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xAA2C1B9C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xAA2C19C0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xAA2C1AFA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP AA2C1AFE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB38E 7 Bytes JMP AA2C19C4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC502 5 Bytes JMP AA2BD5B4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2F86 5 Bytes JMP AA2BEF6C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP AA2C1BA0 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\Explorer.EXE[1128] SHELL32.dll!SHFileOperationW 7CA80924 5 Bytes JMP 00C51102 C:\Program Files\Unlocker\UnlockerHook.dll
.text C:\Program Files\Xfire\Xfire.exe[2064] kernel32.dll!CreateProcessA 7C80236B 3 Bytes JMP 040B2D09 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] kernel32.dll!CreateProcessA + 4 7C80236F 1 Byte [87]
.text C:\Program Files\Xfire\Xfire.exe[2064] kernel32.dll!CreateThread 7C8106D7 5 Bytes JMP 040B26AD C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] GDI32.dll!BitBlt 77EF6F79 5 Bytes JMP 040B2125 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!ReleaseDC 7E39869D 5 Bytes JMP 040B208A C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!GetDC 7E3986C7 5 Bytes JMP 040B1FF6 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!CreateDialogParamW 7E39EA3B 5 Bytes JMP 040B27F8 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!SetForegroundWindow 7E3A42ED 5 Bytes JMP 040B2946 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!DialogBoxParamW 7E3A47AB 5 Bytes JMP 040B2754 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!InvalidateRect 7E3A8FD5 5 Bytes JMP 040B226D C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!BeginPaint 7E3A8FE9 5 Bytes JMP 040B1F62 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!GetCursorPos 7E3A974E 5 Bytes JMP 040B2441 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!WindowFromPoint 7E3A9766 5 Bytes JMP 040B24D9 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!RedrawWindow 7E3A9944 5 Bytes JMP 040B2574 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!SetWindowPos 7E3A99F3 5 Bytes JMP 040B289C C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!IsWindowVisible 7E3A9E3D 7 Bytes JMP 040B2A97 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!SetFocus 7E3AB112 5 Bytes JMP 040B21D5 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!SetCapture 7E3AC35E 5 Bytes JMP 040B23A9 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!InvalidateRgn 7E3ACDFE 5 Bytes JMP 040B230B C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 040B29DE C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!RegisterClassA 7E3AEA5E 5 Bytes JMP 040B2615 C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)
.text C:\Program Files\Xfire\Xfire.exe[2064] USER32.dll!TrackPopupMenu 7E3E531E 5 Bytes JMP 040B2C5F C:\Program Files\Xfire\xfire_toucan_43094.dll (Xfire Toucan DLL/Xfire Inc.)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \FileSystem\Cdfs \Cdfs A90EF400

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3Γ\3Ν\3\xb3\3Η\3Α\3Ώ\3\xbd\3Ώ\3Β\3 \0ΐ\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0R\0A\0S 1?
Reg HKLM\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3ΐ\3µ\3Ε\3Έ\3µ\3\x2015\3\xb1\3Β\3 \0ΐ\3\xb1\3Α\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3 1?
Reg HKLM\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa0\3\xb1\3Ί\3\xad\3Δ\3Ώ\3 \0Η\3Α\3Ώ\3\xbd\3Ώ\3\x384\3Ή\3\xb1\3\xb3\3Α\3\xac\3Ό\3Ό\3\xb1\3Δ\3Ώ\3Β\3 \0M\0i\0n\0i\0p\0o\0r\0t 1?2?3?
Reg HKLM\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa3\3Ν\3\xbd\3\x384\3µ\3Γ\3\xb7\3 \0Δ\3\xb7\3\xbb\3µ\3Μ\3Α\3\xb1\3Γ\3\xb7\3Β\3/\0\xb2\3\x2015\3\xbd\3Δ\3µ\3Ώ\3 \0Δ\3\xb7\3Β\3 \0M\0i\0c\0r\0o\0s\0o\0f\0t 1?
Reg HKLM\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa0\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0\x384\3Ή\3Ί\3Δ\3Ν\3Ώ\3Ε\3 \0B\0r\0o\0a\0d\0c\0o\0m\0 \08\0000\0002\0.\0001\0001\0b\0/\0g 1?
Reg HKLM\SYSTEM\ControlSet001\Services\LanmanServer\Shares@\x2022\3Ί\3Δ\3Ε\3ΐ\3Ι\3Δ\3\xae\3Β\3 CSCFlags=0?MaxUses=4294967295?Path=Microsoft XPS Document Writer,LocalsplOnly?Permissions=0?Remark=Microsoft XPS Document Writer?Type=1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3Γ\3Ν\3\xb3\3Η\3Α\3Ώ\3\xbd\3Ώ\3Β\3 \0ΐ\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0R\0A\0S 1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3ΐ\3µ\3Ε\3Έ\3µ\3\x2015\3\xb1\3Β\3 \0ΐ\3\xb1\3Α\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3 1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa3\3Ν\3\xbd\3\x384\3µ\3Γ\3\xb7\3 \0Δ\3\xb7\3\xbb\3µ\3Μ\3Α\3\xb1\3Γ\3\xb7\3Β\3/\0\xb2\3\x2015\3\xbd\3Δ\3µ\3Ώ\3 \0Δ\3\xb7\3Β\3 \0M\0i\0c\0r\0o\0s\0o\0f\0t 1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa0\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0\x384\3Ή\3Ί\3Δ\3Ν\3Ώ\3Ε\3 \0B\0r\0o\0a\0d\0c\0o\0m\0 \08\0000\0002\0.\0001\0001\0b\0/\0g 1?
Reg HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares@\x2022\3Ί\3Δ\3Ε\3ΐ\3Ι\3Δ\3\xae\3Β\3 CSCFlags=0?MaxUses=4294967295?Path=Microsoft XPS Document Writer,LocalsplOnly?Permissions=0?Remark=Microsoft XPS Document Writer?Type=1?
Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3Γ\3Ν\3\xb3\3Η\3Α\3Ώ\3\xbd\3Ώ\3Β\3 \0ΐ\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0R\0A\0S 1?
Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3ΐ\3µ\3Ε\3Έ\3µ\3\x2015\3\xb1\3Β\3 \0ΐ\3\xb1\3Α\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3 1?
Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa3\3Ν\3\xbd\3\x384\3µ\3Γ\3\xb7\3 \0Δ\3\xb7\3\xbb\3µ\3Μ\3Α\3\xb1\3Γ\3\xb7\3Β\3/\0\xb2\3\x2015\3\xbd\3Δ\3µ\3Ώ\3 \0Δ\3\xb7\3Β\3 \0M\0i\0c\0r\0o\0s\0o\0f\0t 1?
Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa0\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0\x384\3Ή\3Ί\3Δ\3Ν\3Ώ\3Ε\3 \0B\0r\0o\0a\0d\0c\0o\0m\0 \08\0000\0002\0.\0001\0001\0b\0/\0g 1?
Reg HKLM\SYSTEM\ControlSet003\Services\LanmanServer\Shares@\x2022\3Ί\3Δ\3Ε\3ΐ\3Ι\3Δ\3\xae\3Β\3 CSCFlags=0?MaxUses=4294967295?Path=Microsoft XPS Document Writer,LocalsplOnly?Permissions=0?Remark=Microsoft XPS Document Writer?Type=1?
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts@C:\Config.Msi\20529.rbs 1022969650
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BDD73D2B-CF90-F639-5AFB-0F8D279F4A01}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BDD73D2B-CF90-F639-5AFB-0F8D279F4A01}@haebieojdiagcbgb 0x66 0x61 0x68 0x66 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BDD73D2B-CF90-F639-5AFB-0F8D279F4A01}@iafopjdefpcoljeaoa 0x69 0x61 0x68 0x66 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BDD73D2B-CF90-F639-5AFB-0F8D279F4A01}@hapnjlidepnndfem 0x69 0x61 0x68 0x66 …
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3261959974\Groups@\x2018\3\xb3\3\xb1\3ΐ\3\xb7\3Ό\3\xad\3\xbd\3\xb1\3 0
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3261959974\Groups@\x9f\3Ό\3\xac\3\x384\3µ\3Β\3 1
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\3261959974\Groups@\x2020\3\xbb\3\xbb\3µ\3Β\3 \0µ\3ΐ\3\xb1\3Ζ\3\xad\3Β\3





Thank you for your help! 0
Hello alexger

Thank you for the log.

It would be better if we could get a completed ARK scan before we start fixing your machine.

Lets try this:


  • GMER


    • If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".
      If GMER still fails to complete, please try RootRepeal:

  • RootRepeal


    • Please download RootRepeal to your desktop.
    • Physically disconnect your machine from the internet as your system will be unprotected.
    • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
    • Click the Report tab at the bottom and then the Scan button.
    • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
    • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
    • The scan will take a little while to run, so let it go unhindered.
    • Once it is done, click the "Save Report" button, call it RepealScan and save the log to your desktop.
    • Reconnect to the internet.

    Please provide the GMER/Rootrepeal log in your next reply. If you are still having trouble, come back and let me know.
Hello, Thank you for your reply. I tried GMER again as per your instructions. I couldn't get it to work. On safe mode the scan finishes but the save button is not visible because for some reason the screen resolution is different (and I can't change it). I try to pull it down with the cursor but it reaches until the stop button. I did see that it gave a lot of results like MBR and rootkit present and that doesn't look too good. :( I tried rootrepeal but it just froze at initializing and the computer had to be manually shut down. I will wait for your instructions. Thank you. :)
Hello alexger

I did see that it gave a lot of results like MBR and rootkit present and that doesn't look too good.

The thing that concerns me most is win32:parite. This is a polymorphic file infector that can cause large amounts of damage.

Lets see what an Online Scan can tell us:


  • Please perform the following scan:


  • This is a very deep scan that can take many hours. In some instances you may need to let it run overnight. Please be patient.


  • It is recommended that you disable your onboard antivirus program and antispyware programs while performing scans to eliminate software conflicts and to speed up scan time.
  • DO NOT surf the net while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your resident antivirus protection along with whatever antispyware applications you use.


  • Please perform a Kaspersky Online Scan of your computer by clicking here or here.


  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run (at times it may appear to stall).
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

  • Once the scan is complete, click on View scan report. To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.
  • If you need help performing the above steps, an animated tutorial can be found here.
Hello, Thank you for your reply. I was able to get a Kapersky scan in safe mode. Here are the results. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, July 26, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, July 26, 2010 05:15:37 Records in database: 4201584 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ Scan statistics: Objects scanned: 115286 Threats found: 2 Infected objects found: 415 Suspicious objects found: 0 Scan duration: 05:33:30 File name / Threat / Threats count C:\Documents and Settings\Administrator.ΑΛΕΞ\Επιφάνεια εργασίας\gmer\gmer.exe Infected: Virus.Win32.Parite.b 1 C:\othread2.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.l 1 C:\Program Files\Common Files\Java\Java Update\jaureg.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\java-rmi.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\javacpl.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\jbroker.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\jp2launcher.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\keytool.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\kinit.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\klist.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\ktab.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\orbd.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\pack200.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\policytool.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\rmid.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\rmiregistry.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\servertool.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\ssvagent.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\tnameserv.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Java\jre6\bin\unpack200.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Mozilla Firefox\crashreporter.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Mozilla Firefox\uninstall\helper.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\Mozilla Firefox\updater.exe Infected: Virus.Win32.Parite.b 1 C:\Program Files\OpenOffice.org 3\program\soffice.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\110\Target\Program Files\Counter-Strike 1.6\hl.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\110\Target\Program Files\Counter-Strike 1.6\hlds.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\110\Target\Program Files\Counter-Strike 1.6\hltv.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\110\Target\Program Files\Counter-Strike 1.6\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\7-Zip\7z.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\7-Zip\7zFM.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\7-Zip\7zG.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\7-Zip\Uninstall.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\common files\Java\Java Update\jaureg.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\common files\microsoft shared\MSInfo\msinfo32.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\common files\microsoft shared\Speech\sapisvr.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Counter-Strike 1.6\hl.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Counter-Strike 1.6\hlds.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Counter-Strike 1.6\hltv.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Counter-Strike 1.6\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard\icwconn1.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard\icwconn2.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard\icwrmind.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard\icwtutor.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard\inetwiz.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard\isignup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\iedw.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\java-rmi.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\javacpl.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\javaw.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\javaws.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\jbroker.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\jp2launcher.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\jqsnotify.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\keytool.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\kinit.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\klist.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\ktab.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\orbd.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\pack200.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\policytool.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\rmid.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\rmiregistry.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\servertool.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\ssvagent.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\tnameserv.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin\unpack200.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Mozilla Firefox\crashreporter.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Mozilla Firefox\uninstall\helper.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Mozilla Firefox\updater.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows\bckgzm.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows\chkrzm.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows\hrtzzm.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows\rvsezm.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows\shvlzm.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows\zclientm.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\netmeeting\conf.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\netmeeting\wb32.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\OpenOffice.org 3\program\soffice.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express\msimn.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express\oemig50.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express\setup50.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express\wab.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express\wabmig.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows media player\migrate.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows media player\setup_wm.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows media player\wmplayer.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows nt\dialer.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows nt\Pinball\pinball.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Common Files\Microsoft Shared\MSInfo\OLD4B.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Common Files\Microsoft Shared\Speech\OLD4D.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard\OLD51.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard\OLD53.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard\OLD55.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard\OLD57.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard\OLD59.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard\OLD5B.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\OLD4F.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows\OLD5D.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows\OLD5F.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows\OLD61.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows\OLD63.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows\OLD65.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows\OLD67.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\NetMeeting\OLD69.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\NetMeeting\OLD6B.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express\OLD6D.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express\OLD6F.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express\OLD71.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express\OLD73.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express\OLD75.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows Media Player\OLD77.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows Media Player\OLD79.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows Media Player\OLD7B.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows NT\OLD7D.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows NT\Pinball\OLD7F.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\7-Zip\7z.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\7-Zip\7zG.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\7-Zip\Uninstall.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\Counter-Strike 1.6\hl.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\Counter-Strike 1.6\hlds.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\Counter-Strike 1.6\hltv.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\Counter-Strike 1.6\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\132\Target\PROGRAM FILES\Java\jre6\bin\javaws.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe\Updater6\AdobeUpdaterInstallMgr.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\10\Intel 32\IDriver2.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriver.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriver2.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\9\Intel 32\IDriver.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\9\Intel 32\IDriver2.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\UpdateService\agent.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\UpdateService\issch.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Java\Java Update\jaucheck.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Java\Java Update\jucheck.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Equation\EQNEDT32.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\MSInfo\OINFOP12.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12\MSE7.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12\OFFDIAG.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\ODEPLOY.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\SETUP.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12\OFFLB.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Smart Tag\SmartTagInstall.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Works Shared\dw15.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Works Shared\WksCal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Real\Update_OB\r1puninst.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Real\Update_OB\upgrdhlp.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood\develop\compile.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood\develop\ffcreate.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood\DFArc.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood\dink.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood\dinkedit.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood\Uninstall.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Empire Interactive\Starsky&Hutch\Expand.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\ERUNT\AUTOBACK.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\ERUNT\ERUNT.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\ERUNT\NTREGOPT.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\ERUNT\unins000.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\facemoods.com\facemoods\1.3.62.1\uninstall.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\GameTop.com\Shark Attack\unins000.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\BrandIt\BrdItVer.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\HP Wireless Assistant\HPQWAVer.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\HP Wireless Assistant\HPQWA_UI.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\HP Wireless Assistant\Wireless.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\SDP\HPSdpApp.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\SDP\HPUpdater.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\SDP\HPWaitWindow.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\SDP\HPWriter.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\Shared\WizInstaller.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\Shared\WizLink.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\srvrtm\us\kb888111srvrtm.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\srvsp1\us\KB901105.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\win2k3\jpn\KB901105.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\win2k3\us\kb901105.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\win2ksp4\us\kb888111w2ksp4.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\win2k_xp\us\kb835221.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\xpsp1\us\kb888111xpsp1.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\xpsp2\us\kb888111xpsp2.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\WDM\AESTFltr.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\WDM\suhlp.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{01FB4998-33C4-4431-85ED-079E3EEFE75D}\Setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{08B3869E-D282-424C-9AFC-870E04A4BA14}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{12933722-E473-4846-9992-5EDAE2D362D0}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{3108C217-BE83-42E4-AE9E-A56A2A92E549}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{3FE31026-246F-4BAF-A313-8838962BCB95}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{69DAC00A-7665-4E9B-B441-093D40736429}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{96AE7E41-E34E-47D0-AC07-1091A8127911}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{CE6D39E2-D4CB-4C49-ABD9-8724B095D1EF}\Setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{CF149A60-8F5A-4632-B5DE-EC35BCB5ADFC}\Setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{E0AD4033-D89B-11D7-97C2-00055D0CA761}\Setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Internet Explorer\ExtExport.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Malwarebytes' Anti-Malware\unins000.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft\Search Enhancement Pack\Choice Guard\CGuard.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\1033\ONELEV.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\CLVIEW.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\CNFNOT32.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\DRAT.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\DSSM.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\EDITOR.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\EXCEL.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\excelcnv.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\GRAPH.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\GROOVE.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\GrooveAuditService.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\GrooveClean.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\GrooveMigrator.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\GrooveStdURLLauncher.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\INFOPATH.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\MSACCESS.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\MSOHTMED.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\MSPUB.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\MSQRY32.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\MSTORDB.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\MSTORE.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\ONENOTE.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\ORGWIZ.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\POWERPNT.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\PPTVIEW.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\PROJIMPT.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\REGFORM.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\SCANOST.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\SCANPST.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\SELFCERT.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\SETLANG.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\TLIMPT.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\VPREVIEW.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\Wordconv.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\PowerPoint Viewer\PPTVIEW.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Silverlight\4.0.50524.0\agcp.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Silverlight\4.0.50524.0\coregen.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Silverlight\4.0.50524.0\Silverlight.Configuration.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Silverlight\sllauncher.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\MSWorks.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\WkDStore.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\wkgdcach.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\wklnckml.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\wkplmstp.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\wksab.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\wksdb.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\WksSb.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\wksss.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works\wkwcestp.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\MSECACHE\WICU3\Ansi\MsiZap.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\MSECACHE\WICU3\MsiZapA.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\MSECACHE\WICU3\MsiZapU.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\MSECACHE\WICU3\Unicode\MsiZap.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Nice-Games\Tank-o-box\game\scripts\nicej2k.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Nice-Games\Tank-o-box\game\scripts\oggdec.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Nice-Games\Tank-o-box\game\Tank-o-box.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Nice-Games\Tank-o-box\uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenAL\oalinst.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program\gengal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program\nsplugin.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program\odbcconfig.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program\python-core-2.3.4\lib\distutils\command\wininst.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program\senddoc.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program\setofficelang.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\crashrep.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\python.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\quickstart.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\sbase.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\sdraw.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\simpress.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\smath.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\sweb.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\unoinfo.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program\unopkg.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\PicLensIE\LaunchCooliris.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\converter\convert.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\converter\RealConverter.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\converter\Update\r1puninst.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\fixrjb.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\realjbox.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\realplay.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\RecordingManager.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\rphelperapp.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\Setup\setup.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Realtek\USB2.0 Card Reader Software\revcon.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Roxio\BackOnTrack\Disaster Recovery\Drivers\SaibIa32Install.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVR.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Roxio\BackOnTrack\Main\Backup_Central10.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Contra Game - The Guns Nomads\Contra Game - The Guns Nomads.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Contra Game - The Guns Nomads\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Mario Forever Galaxy\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Mario Forever Lost Map\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Mario Online\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Old Super Mario Bros\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Steam Punk Rally\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Super Mario\Uninstal.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Softronics\Microsoft Windows Logo\logo32.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Sophos\Sophos Anti-Rootkit\helper.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Sophos\Sophos Anti-Rootkit\sarcli.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Sophos\Sophos Anti-Rootkit\sargui.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SpeedTouch\Dr SpeedTouch\php.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SpywareBlaster\sbautoupdate.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SpywareBlaster\spywareblaster.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SpywareBlaster\unins000.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Steam\Steam.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Steam\UNWISE.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Steam\WriteMiniDump.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Super Mario All-Stars\unins000.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware\BootSafe.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware\RUNSAS.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware\SASCORE.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware\SASINST.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware\SASUNINST.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware\SSUPDATE.EXE Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP\InstNT.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP\SynMood.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP\SynTPHelper.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP\SynZMetr.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP\Tutorial.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\java-rmi.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\java.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\javacpl.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\javaws.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\jucheck.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\jusched.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\keytool.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\kinit.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\klist.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\ktab.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\orbd.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\pack200.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\policytool.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\rmid.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\rmiregistry.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\servertool.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\tnameserv.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin\unpack200.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\MigoMobileHost.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\syncablesdesktop_Copy\syncablesdesktop.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\syncablesUSB.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Unlocker\uninst.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Unlocker\Unlocker.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software\bin\DPInst.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software\btsendto_explorer.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software\BtwHfConfig.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software\BtwHtmlPrint.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software\gzip.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Garbage Collector\unins000.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Garbage Collector\WindowsGarbageCollector.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Installer Clean Up\MsiZap.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Family Safety\fsssvc.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Family Safety\fsui.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Installer\wlarp.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Installer\wloobe.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Messenger\msvs.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live Safety Center\wlscUploader.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Media Connect 2\wmccds.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Media Connect 2\WMCCFG.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\92\Target\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regiis.exe Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Common Files\Microsoft Shared\MSInfo\OLD1A.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Internet Explorer\OLD1E.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\NetMeeting\OLD38.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\NetMeeting\OLD3A.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express\OLD3C.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express\OLD3E.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express\OLD40.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express\OLD42.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express\OLD44.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Windows Media Player\OLD46.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Windows Media Player\OLD48.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\Speech\OLD1C.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard\OLD20.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard\OLD22.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard\OLD24.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard\OLD26.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard\OLD28.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard\OLD2A.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows\OLD2C.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows\OLD2E.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows\OLD30.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows\OLD32.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows\OLD34.tmp Infected: Virus.Win32.Parite.b 1 C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows\OLD36.tmp Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\DW20.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\ODSERV.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OFFDIAG.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425\OFFLB.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.6425\DW20.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.6425\ODSERV.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.6425\OFFDIAG.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.6425\OFFLB.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518\CNFNOT32.EXE_0004 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518\ODSERV.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518\OFFDIAG.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518\OFFLB.EXE_0001 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518\SCANPST.EXE_0002 Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\{0517F875-BBB2-4812-A63E-733B33CEF215}\BackupCentral.exe Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}\BackupCentral.exe Infected: Virus.Win32.Parite.b 1 C:\WINDOWS\Installer\{87A83C6F-F53C-448A-B078-FF00E3EAEB29}\BackupCentral.exe Infected: Virus.Win32.Parite.b 1 Selected area has been scanned.
Hello alexger

Thank you for log.

Win32.Parite has indeed been confirmed. I have to say that the outlook is not good. Win32.Parite is a polymorphic file infector that damages the files that it infects. Whilst the infecting agent can sometimes be removed, the damage it causes is very difficult to repair.

Looking at the Online Scan log, the infection does not appear to have spread to any of your critical system files (but it may still do so). I can try to help you, but you must be aware that it is likely that you will be looking at a full system reformat if we cannot make any progress.


If you would like to continue, lets try the following and see where it leads:


  • Download Combofix and RE-NAME it BEFORE saving


  • Download Combofix from either of the links below. You must rename it to alexger.exe before saving it.
  • Save it to your desktop. Change the "save as file type" to "all files".
  • Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop.


  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.


  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.


  • Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Hello JonTom Thank you very much for your reply. I tried combo fix but it gives me a terminal error-missing file C:\windows\regedit.exe is missing. I have microsoft recovery console installed from before. Would I find this file there or somewhere else? Thank you in advance.
Hello alexger

me a terminal error-missing file C:\windows\regedit.exe is missing.

Before we continue lets check something out. Please do the following:


  • Please make all files and folders VISIBLE:


    • Click "Start" Go to My Computer-> Tools-> Folder Options-> View tab:
    • Choose to "Show hidden files and folders."
    • Uncheck the "Hide protected operating system files" and the "Hide extensions for know file types" boxes.
    • Close the window with "OK".


  • Please scan the following files


    • Please visit Virus Total by clicking here.
    • Click the Browse button and search for the following file (if present): C:\WINDOWS\system32\svchost.exe
    • Click Open.
    • Then click Send File.
    • Please be patient while the file is scanned.
    • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

    • Once the scan results appear, copy and paste them into Notepad and repeat the procedure for the following file(s):

    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\windows\system32\ctfmon.exe
    c:\windows\system32\userinit.exe
    C:\windows\regedit.exe


    • Please provide the results from the scans in your next reply.
Hello JonTom, Thank you for your reply. Here are the logs. File svchost.exe received on 2010.07.27 08:05:30 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/42 (0%) Loading server information… Your file is queued in position: ___. Estimated start time is between ___ and ___ . Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2010.07.27.00 2010.07.26 - AntiVir 8.2.4.26 2010.07.26 - Antiy-AVL 2.0.3.7 2010.07.26 - Authentium 5.2.0.5 2010.07.27 - Avast 4.8.1351.0 2010.07.26 - Avast5 5.0.332.0 2010.07.26 - AVG 9.0.0.851 2010.07.26 - BitDefender 7.2 2010.07.27 - CAT-QuickHeal 11.00 2010.07.27 - ClamAV 0.96.0.3-git 2010.07.27 - Comodo 5553 2010.07.27 - DrWeb 5.0.2.03300 2010.07.27 - Emsisoft 5.0.0.34 2010.07.27 - eSafe 7.0.17.0 2010.07.26 - eTrust-Vet 36.1.7738 2010.07.26 - F-Prot 4.6.1.107 2010.07.27 - F-Secure 9.0.15370.0 2010.07.27 - Fortinet 4.1.143.0 2010.07.24 - GData 21 2010.07.27 - Ikarus T3.1.1.84.0 2010.07.27 - Jiangmin 13.0.900 2010.07.26 - Kaspersky 7.0.0.125 2010.07.27 - McAfee 5.400.0.1158 2010.07.27 - McAfee-GW-Edition 2010.1 2010.07.27 - Microsoft 1.6004 2010.07.27 - NOD32 5315 2010.07.26 - Norman 6.05.11 2010.07.26 - nProtect 2010-07-27.01 2010.07.27 - Panda 10.0.2.7 2010.07.26 - PCTools 7.0.3.5 2010.07.27 - Prevx 3.0 2010.07.27 - Rising 22.58.01.03 2010.07.27 - Sophos 4.55.0 2010.07.27 - Sunbelt 6646 2010.07.27 - SUPERAntiSpyware 4.40.0.1006 2010.07.27 - Symantec 20101.1.1.7 2010.07.27 - TheHacker 6.5.2.1.326 2010.07.27 - TrendMicro 9.120.0.1004 2010.07.27 - TrendMicro-HouseCall 9.120.0.1004 2010.07.27 - VBA32 3.12.12.6 2010.07.27 - ViRobot 2010.7.28.3961 2010.07.27 - VirusBuster 5.0.27.0 2010.07.26 - Additional information File size: 14336 bytes MD5…: 274e9c78c12ebf74dc56b2bf64312f34 SHA1..: b35adb340f094acea0ba8860560c72d730c290fd SHA256: a26a20ef39db7f50ce21164250bed01ee7b8d50f06316fe1c5d34b40f5af0010 ssdeep: 384:Tdi+JmG6yqlCRaJt4RHS5LutGJae7g9VJnpWCNJbW:bcG6xlCRaJKGOA7SHJ PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x2509 timedatestamp…..: 0x48025bc0 (Sun Apr 13 19:15:12 2008) machinetype…….: 0x14c (I386) ( 3 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x2c00 0x2c00 6.29 48331595af9d9d52b478844a07357653 .data 0x4000 0x210 0x200 1.62 cbd504e46c836e09e8faabdcfbabaec2 .rsrc 0x5000 0x408 0x600 2.51 dcede0c303bbb48c6875eb64477e5882 ( 4 imports ) > ADVAPI32.dll: RegQueryValueExW, SetSecurityDescriptorDacl, SetEntriesInAclW, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, GetTokenInformation, OpenProcessToken, OpenThreadToken, SetServiceStatus, RegisterServiceCtrlHandlerW, RegCloseKey, RegOpenKeyExW, StartServiceCtrlDispatcherW > KERNEL32.dll: HeapFree, GetLastError, WideCharToMultiByte, lstrlenW, LocalFree, GetCurrentProcess, GetCurrentThread, GetProcAddress, LoadLibraryExW, LeaveCriticalSection, HeapAlloc, EnterCriticalSection, LCMapStringW, FreeLibrary, lstrcpyW, ExpandEnvironmentStringsW, lstrcmpiW, ExitProcess, GetCommandLineW, InitializeCriticalSection, GetProcessHeap, SetErrorMode, SetUnhandledExceptionFilter, RegisterWaitForSingleObject, InterlockedCompareExchange, LoadLibraryA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, LocalAlloc, lstrcmpW, DelayLoadFailureHook > ntdll.dll: NtQuerySecurityObject, RtlFreeHeap, NtOpenKey, wcscat, wcscpy, RtlAllocateHeap, RtlCompareUnicodeString, RtlInitUnicodeString, RtlInitializeSid, RtlLengthRequiredSid, RtlSubAuthoritySid, NtClose, RtlSubAuthorityCountSid, RtlGetDaclSecurityDescriptor, RtlQueryInformationAcl, RtlGetAce, RtlImageNtHeader, wcslen, RtlUnhandledExceptionFilter, RtlCopySid > RPCRT4.dll: RpcServerUnregisterIfEx, RpcMgmtWaitServerListen, RpcMgmtSetServerStackSize, RpcServerUnregisterIf, RpcServerListen, RpcServerUseProtseqEpW, RpcServerRegisterIf, I_RpcMapWin32Status, RpcMgmtStopServerListening ( 0 exports ) RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win32 Executable Generic (42.3%) Win32 Dynamic Link Library (generic) (37.6%) Generic Win/DOS Executable (9.9%) DOS Executable Generic (9.9%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher….: Microsoft Corporation copyright….: © Microsoft Corporation. All rights reserved. product……: Microsoft_ Windows_ Operating System description..: Generic Host Process for Win32 Services original name: svchost.exe internal name: svchost.exe file version.: 5.1.2600.5512 (xpsp.080413-2111) comments…..: n/a signers……: - signing date.: - verified…..: Unsigned ———————————————— File explorer.exe received on 2010.07.27 08:09:48 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/41 (0%) Loading server information… Your file is queued in position: 4. Estimated start time is between 70 and 100 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2010.07.27.00 2010.07.26 - AntiVir 8.2.4.26 2010.07.26 - Antiy-AVL 2.0.3.7 2010.07.26 - Authentium 5.2.0.5 2010.07.27 - Avast 4.8.1351.0 2010.07.26 - Avast5 5.0.332.0 2010.07.26 - AVG 9.0.0.851 2010.07.26 - BitDefender 7.2 2010.07.27 - CAT-QuickHeal 11.00 2010.07.27 - ClamAV 0.96.0.3-git 2010.07.27 - Comodo 5553 2010.07.27 - DrWeb 5.0.2.03300 2010.07.27 - Emsisoft 5.0.0.34 2010.07.27 - eSafe 7.0.17.0 2010.07.26 - eTrust-Vet 36.1.7738 2010.07.26 - F-Prot 4.6.1.107 2010.07.27 - F-Secure 9.0.15370.0 2010.07.27 - Fortinet 4.1.143.0 2010.07.24 - GData 21 2010.07.27 - Ikarus T3.1.1.84.0 2010.07.27 - Jiangmin 13.0.900 2010.07.26 - Kaspersky 7.0.0.125 2010.07.27 - McAfee 5.400.0.1158 2010.07.27 - McAfee-GW-Edition 2010.1 2010.07.27 - Microsoft 1.6004 2010.07.27 - NOD32 5315 2010.07.26 - Norman 6.05.11 2010.07.26 - nProtect 2010-07-27.01 2010.07.27 - Panda 10.0.2.7 2010.07.26 - PCTools 7.0.3.5 2010.07.27 - Prevx 3.0 2010.07.27 - Rising 22.58.01.03 2010.07.27 - Sophos 4.55.0 2010.07.27 - Sunbelt 6646 2010.07.27 - Symantec 20101.1.1.7 2010.07.27 - TheHacker 6.5.2.1.326 2010.07.27 - TrendMicro 9.120.0.1004 2010.07.27 - TrendMicro-HouseCall 9.120.0.1004 2010.07.27 - VBA32 3.12.12.6 2010.07.27 - ViRobot 2010.7.28.3961 2010.07.27 - VirusBuster 5.0.27.0 2010.07.26 - Additional information File size: 1038336 bytes MD5…: 8b93a11cda30dd8ad9902b59bb401411 SHA1..: 8e121364ead85812e1c728e709962f79ef46e1b1 SHA256: ab8072dd74d9dfa5544923407fb1bf31a52c3c7abd2fa7d3fe442a36cd3de0ac ssdeep: 12288:QHmcoCUyZtwAvAs4wTCyrPTRz0VezanHcoJpaz/g/J/v3S:ymfty/wAvN7 lrR0VesHTaz/g/J/f PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x1a55f timedatestamp…..: 0x48025c30 (Sun Apr 13 19:17:04 2008) machinetype…….: 0x14c (I386) ( 4 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x44c09 0x44e00 6.38 b61079098c7167c33a02efa89389211c .data 0x46000 0x1db4 0x1800 1.30 983f35021232560eaaa99fcbc1b7d359 .rsrc 0x48000 0xb34fc 0xb3600 6.67 da8f8ec7884ec57005e97be7b66c88d6 .reloc 0xfc000 0x374c 0x3800 6.78 ec335057489badbf6d8142b57175fd91 ( 13 imports ) > ADVAPI32.dll: RegSetValueW, RegEnumKeyExW, GetUserNameW, RegNotifyChangeKeyValue, RegEnumValueW, RegQueryValueExA, RegOpenKeyExA, RegEnumKeyW, RegCloseKey, RegCreateKeyW, RegQueryInfoKeyW, RegOpenKeyExW, RegQueryValueExW, RegCreateKeyExW, RegSetValueExW, RegDeleteValueW, RegQueryValueW > BROWSEUI.dll: -, -, -, - > GDI32.dll: GetStockObject, CreatePatternBrush, OffsetViewportOrgEx, GetLayout, CombineRgn, CreateDIBSection, GetTextExtentPoint32W, StretchBlt, CreateRectRgnIndirect, CreateRectRgn, GetClipRgn, IntersectClipRect, GetViewportOrgEx, SetViewportOrgEx, SelectClipRgn, PatBlt, GetBkColor, CreateCompatibleDC, CreateCompatibleBitmap, OffsetWindowOrgEx, DeleteDC, SetBkColor, BitBlt, ExtTextOutW, GetTextExtentPointW, GetClipBox, GetObjectW, SetTextColor, SetBkMode, CreateFontIndirectW, DeleteObject, GetTextMetricsW, SelectObject, GetDeviceCaps, TranslateCharsetInfo, SetStretchBltMode > KERNEL32.dll: GetSystemDirectoryW, CreateThread, CreateJobObjectW, ExitProcess, SetProcessShutdownParameters, ReleaseMutex, CreateMutexW, SetPriorityClass, GetCurrentProcess, GetStartupInfoW, GetCommandLineW, SetErrorMode, LeaveCriticalSection, EnterCriticalSection, ResetEvent, LoadLibraryExA, CompareFileTime, GetSystemTimeAsFileTime, SetThreadPriority, GetCurrentThreadId, GetThreadPriority, GetCurrentThread, GetUserDefaultLangID, Sleep, GetBinaryTypeW, GetModuleHandleExW, SystemTimeToFileTime, GetLocalTime, GetCurrentProcessId, GetEnvironmentVariableW, UnregisterWait, GlobalGetAtomNameW, GetFileAttributesW, MoveFileW, lstrcmpW, LoadLibraryExW, FindClose, FindNextFileW, FindFirstFileW, lstrcmpiA, SetEvent, AssignProcessToJobObject, GetDateFormatW, GetTimeFormatW, FlushInstructionCache, lstrcpynW, GetSystemWindowsDirectoryW, SetLastError, GetProcessHeap, HeapFree, HeapReAlloc, HeapSize, HeapAlloc, GetUserDefaultLCID, ReadProcessMemory, OpenProcess, InterlockedCompareExchange, LoadLibraryA, QueryPerformanceCounter, UnhandledExceptionFilter, SetUnhandledExceptionFilter, VirtualFree, VirtualAlloc, ResumeThread, TerminateProcess, TerminateThread, GetSystemDefaultLCID, GetLocaleInfoW, CreateEventW, GetLastError, OpenEventW, DelayLoadFailureHook, WaitForSingleObject, GetTickCount, ExpandEnvironmentStringsW, GetModuleFileNameW, GetPrivateProfileStringW, lstrcmpiW, CreateProcessW, FreeLibrary, GetWindowsDirectoryW, LocalAlloc, CreateFileW, DeviceIoControl, LocalFree, GetQueuedCompletionStatus, CreateIoCompletionPort, SetInformationJobObject, CloseHandle, LoadLibraryW, GetModuleHandleW, ActivateActCtx, DeactivateActCtx, GetFileAttributesExW, GetProcAddress, DeleteCriticalSection, CreateEventA, HeapDestroy, InitializeCriticalSection, MulDiv, InitializeCriticalSectionAndSpinCount, lstrlenW, InterlockedDecrement, InterlockedIncrement, GlobalAlloc, InterlockedExchange, GetModuleHandleA, GetVersionExA, GlobalFree, GetProcessTimes, lstrcpyW, GetLongPathNameW, RegisterWaitForSingleObject > msvcrt.dll: _itow, free, memmove, realloc, _except_handler3, malloc, _ftol, _vsnwprintf > ntdll.dll: RtlNtStatusToDosError, NtQueryInformationProcess > ole32.dll: CoFreeUnusedLibraries, RegisterDragDrop, CreateBindCtx, RevokeDragDrop, CoInitializeEx, CoUninitialize, OleInitialize, CoRevokeClassObject, CoRegisterClassObject, CoMarshalInterThreadInterfaceInStream, CoCreateInstance, OleUninitialize, DoDragDrop > OLEAUT32.dll: -, - > SHDOCVW.dll: -, -, - > SHELL32.dll: -, -, SHGetFolderPathW, -, -, -, -, -, ExtractIconExW, -, -, -, -, -, -, -, -, -, -, -, -, -, -, SHGetSpecialFolderLocation, ShellExecuteExW, -, -, -, SHGetSpecialFolderPathW, -, -, -, SHBindToParent, -, -, -, SHParseDisplayName, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, SHChangeNotify, SHGetDesktopFolder, SHAddToRecentDocs, -, -, -, DuplicateIcon, -, -, -, -, -, -, -, -, SHUpdateRecycleBinIcon, SHGetFolderLocation, SHGetPathFromIDListA, -, -, -, -, -, -, -, SHGetPathFromIDListW, -, -, - > SHLWAPI.dll: StrCpyNW, -, -, -, -, StrRetToBufW, StrRetToStrW, -, -, -, -, SHQueryValueExW, PathIsNetworkPathW, -, AssocCreate, -, -, -, -, -, StrCatW, StrCpyW, -, -, -, -, -, -, SHGetValueW, -, StrCmpNIW, PathRemoveBlanksW, PathRemoveArgsW, PathFindFileNameW, StrStrIW, PathGetArgsW, -, StrToIntW, SHRegGetBoolUSValueW, SHRegWriteUSValueW, SHRegCloseUSKey, SHRegCreateUSKeyW, SHRegGetUSValueW, SHSetValueW, -, PathAppendW, PathUnquoteSpacesW, -, -, PathQuoteSpacesW, -, SHSetThreadRef, SHCreateThreadRef, -, -, -, PathCombineW, -, -, -, SHStrDupW, PathIsPrefixW, PathParseIconLocationW, AssocQueryKeyW, -, AssocQueryStringW, StrCmpW, -, -, -, -, -, -, -, -, SHRegQueryUSValueW, SHRegOpenUSKeyW, SHRegSetUSValueW, PathIsDirectoryW, PathFileExistsW, PathGetDriveNumberW, -, StrChrW, PathFindExtensionW, -, -, PathRemoveFileSpecW, PathStripToRootW, -, -, -, SHOpenRegStream2W, -, -, -, StrDupW, SHDeleteValueW, StrCatBuffW, SHDeleteKeyW, StrCmpIW, -, -, wnsprintfW, -, -, StrCmpNW, -, - > USER32.dll: TileWindows, GetDoubleClickTime, GetSystemMetrics, GetSysColorBrush, AllowSetForegroundWindow, LoadMenuW, GetSubMenu, RemoveMenu, SetParent, GetMessagePos, CheckDlgButton, EnableWindow, GetDlgItemInt, SetDlgItemInt, CopyIcon, AdjustWindowRectEx, DrawFocusRect, DrawEdge, ExitWindowsEx, WindowFromPoint, SetRect, AppendMenuW, LoadAcceleratorsW, LoadBitmapW, SendNotifyMessageW, SetWindowPlacement, CheckMenuItem, EndDialog, SendDlgItemMessageW, MessageBeep, GetActiveWindow, PostQuitMessage, MoveWindow, GetDlgItem, RemovePropW, GetClassNameW, GetDCEx, SetCursorPos, ChildWindowFromPoint, ChangeDisplaySettingsW, RegisterHotKey, UnregisterHotKey, SetCursor, SendMessageTimeoutW, GetWindowPlacement, LoadImageW, SetWindowRgn, IntersectRect, OffsetRect, EnumDisplayMonitors, RedrawWindow, SubtractRect, TranslateAcceleratorW, WaitMessage, InflateRect, CallWindowProcW, GetDlgCtrlID, SetCapture, LockSetForegroundWindow, SystemParametersInfoW, FindWindowW, CreatePopupMenu, GetMenuDefaultItem, DestroyMenu, GetShellWindow, EnumChildWindows, GetWindowLongW, SendMessageW, RegisterWindowMessageW, GetKeyState, CopyRect, MonitorFromRect, MonitorFromPoint, RegisterClassW, SetPropW, GetWindowLongA, SetWindowLongW, FillRect, GetCursorPos, MessageBoxW, LoadStringW, ReleaseDC, GetDC, EnumDisplaySettingsExW, EnumDisplayDevicesW, PostMessageW, DispatchMessageW, TranslateMessage, GetMessageW, PeekMessageW, PtInRect, BeginPaint, EndPaint, SetWindowTextW, GetAsyncKeyState, InvalidateRect, GetWindow, ShowWindowAsync, TrackPopupMenuEx, UpdateWindow, DestroyIcon, IsRectEmpty, SetActiveWindow, GetSysColor, DrawTextW, IsHungAppWindow, SetTimer, GetMenuItemID, TrackPopupMenu, EndTask, SendMessageCallbackW, GetClassLongW, LoadIconW, OpenInputDesktop, CloseDesktop, SetScrollPos, ShowWindow, BringWindowToTop, GetDesktopWindow, CascadeWindows, CharUpperBuffW, SwitchToThisWindow, InternalGetWindowText, GetScrollInfo, GetMenuItemCount, CreateWindowExW, DialogBoxParamW, MsgWaitForMultipleObjects, CharNextA, RegisterClipboardFormatW, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, PrintWindow, SetClassLongW, GetPropW, GetNextDlgGroupItem, GetNextDlgTabItem, ChildWindowFromPointEx, IsChild, NotifyWinEvent, TrackMouseEvent, GetCapture, GetAncestor, CharUpperW, SetWindowLongA, DrawCaption, ModifyMenuW, InsertMenuW, IsWindowEnabled, GetMenuState, LoadCursorW, GetParent, IsDlgButtonChecked, DestroyWindow, EnumWindows, IsWindowVisible, GetClientRect, UnionRect, EqualRect, GetWindowThreadProcessId, GetForegroundWindow, KillTimer, GetClassInfoExW, DefWindowProcW, RegisterClassExW, GetIconInfo, SetScrollInfo, GetLastActivePopup, SetForegroundWindow, IsWindow, GetSystemMenu, IsIconic, IsZoomed, EnableMenuItem, SetMenuDefaultItem, MonitorFromWindow, GetMonitorInfoW, GetWindowInfo, GetFocus, SetFocus, MapWindowPoints, ScreenToClient, ClientToScreen, GetWindowRect, SetWindowPos, DeleteMenu, GetMenuItemInfoW, SetMenuItemInfoW, CharNextW > UxTheme.dll: GetThemeBackgroundContentRect, GetThemeBool, GetThemePartSize, DrawThemeParentBackground, OpenThemeData, DrawThemeBackground, GetThemeTextExtent, DrawThemeText, CloseThemeData, SetWindowTheme, GetThemeBackgroundRegion, -, GetThemeMargins, GetThemeColor, GetThemeFont, GetThemeRect, IsAppThemed ( 0 exports ) RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win32 Executable Generic (42.3%) Win32 Dynamic Link Library (generic) (37.6%) Generic Win/DOS Executable (9.9%) DOS Executable Generic (9.9%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher….: Microsoft Corporation copyright….: © Microsoft Corporation. __ _________ ____ _______ ___________. product……: ___________ _______ Microsoft_ Windows_ description..: __________ ___ Windows original name: EXPLORER.EXE internal name: explorer file version.: 6.00.2900.5512 (xpsp.080413-2105) comments…..: n/a signers……: - signing date.: - verified…..: Unsigned ————————————– File spoolsv.exe received on 2010.07.27 08:16:22 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/42 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 43 and 62 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2010.07.27.00 2010.07.26 - AntiVir 8.2.4.26 2010.07.26 - Antiy-AVL 2.0.3.7 2010.07.26 - Authentium 5.2.0.5 2010.07.27 - Avast 4.8.1351.0 2010.07.26 - Avast5 5.0.332.0 2010.07.26 - AVG 9.0.0.851 2010.07.26 - BitDefender 7.2 2010.07.27 - CAT-QuickHeal 11.00 2010.07.27 - ClamAV 0.96.0.3-git 2010.07.27 - Comodo 5553 2010.07.27 - DrWeb 5.0.2.03300 2010.07.27 - Emsisoft 5.0.0.34 2010.07.27 - eSafe 7.0.17.0 2010.07.26 - eTrust-Vet 36.1.7738 2010.07.26 - F-Prot 4.6.1.107 2010.07.27 - F-Secure 9.0.15370.0 2010.07.27 - Fortinet 4.1.143.0 2010.07.24 - GData 21 2010.07.27 - Ikarus T3.1.1.84.0 2010.07.27 - Jiangmin 13.0.900 2010.07.26 - Kaspersky 7.0.0.125 2010.07.27 - McAfee 5.400.0.1158 2010.07.27 - McAfee-GW-Edition 2010.1 2010.07.27 - Microsoft 1.6004 2010.07.27 - NOD32 5315 2010.07.26 - Norman 6.05.11 2010.07.27 - nProtect 2010-07-27.01 2010.07.27 - Panda 10.0.2.7 2010.07.26 - PCTools 7.0.3.5 2010.07.27 - Prevx 3.0 2010.07.27 - Rising 22.58.01.03 2010.07.27 - Sophos 4.55.0 2010.07.27 - Sunbelt 6646 2010.07.27 - SUPERAntiSpyware 4.40.0.1006 2010.07.27 - Symantec 20101.1.1.7 2010.07.27 - TheHacker 6.5.2.1.326 2010.07.27 - TrendMicro 9.120.0.1004 2010.07.27 - TrendMicro-HouseCall 9.120.0.1004 2010.07.27 - VBA32 3.12.12.6 2010.07.27 - ViRobot 2010.7.28.3961 2010.07.27 - VirusBuster 5.0.27.0 2010.07.26 - Additional information File size: 57856 bytes MD5…: 2a5da64e77498e92ec20dc36a747dc98 SHA1..: ba41ceb62884571c7e2701ffd5a2f9b41afa0139 SHA256: 4237829f8500a0d0489b3054a9df3918b5c3acde70844dfabb32a67e87c2c93b ssdeep: 768:BE4EVpgSavGlAMm1yMvsCeq+H8O+j8f1b1mDV3D+JMG/dXplJigo:kgSHlAM mxUC/OUVIrOgo PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x461b timedatestamp…..: 0x48025ce1 (Sun Apr 13 19:20:01 2008) machinetype…….: 0x14c (I386) ( 3 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0xba70 0xbc00 5.96 55937a5c7b20d8057495ea0cef00275c .data 0xd000 0x13b4 0x1400 2.24 887444c39cada5bd753c428783e0009b .rsrc 0xf000 0xc68 0xe00 6.18 8b7aa680680d5c40e90647de12607611 ( 6 imports ) > ADVAPI32.dll: SetServiceStatus, RegQueryValueExW, AllocateAndInitializeSid, FreeSid, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, GetLengthSid, InitializeAcl, AddAccessAllowedAce, AddAccessDeniedAce, GetAce, SetSecurityDescriptorDacl, GetSecurityDescriptorLength, MakeSelfRelativeSD, RegDisablePredefinedCache, RegOpenKeyExW, RegCloseKey, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW > GDI32.dll: bMakePathNameW, GdiInitSpool, GdiGetSpoolMessage > KERNEL32.dll: GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, GetCurrentProcessId, SetUnhandledExceptionFilter, GetModuleHandleA, GetCurrentThreadId, GetTickCount, UnhandledExceptionFilter, QueryPerformanceCounter, FreeLibrary, InterlockedExchange, GetModuleHandleW, GetLastError, ExitThread, CloseHandle, WaitForSingleObject, CreateEventW, CreateThread, ExitProcess, Sleep, OpenEventW, LoadLibraryA, InitializeCriticalSection, LocalFree, LocalAlloc, SetEvent, LeaveCriticalSection, EnterCriticalSection, SetLastError, OpenProcess, InterlockedIncrement, RaiseException, InterlockedDecrement, GetProcAddress, GetSystemDirectoryW > msvcrt.dll: __initenv, _exit, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _controlfp, _XcptFilter, wcsrchr, wcslen, _c_exit, _stricmp, _wcsnicmp, _except_handler3 > ntdll.dll: RtlValidRelativeSecurityDescriptor > RPCRT4.dll: RpcServerRegisterIf2, I_RpcBindingIsClientLocal, I_RpcSessionStrictContextHandle, RpcRaiseException, RpcImpersonateClient, RpcRevertToSelf, NdrServerCall2, RpcServerUseProtseqEpA, I_RpcSsDontSerializeContext, RpcMgmtSetServerStackSize, RpcServerListen ( 12 exports ) YDriverUnloadComplete, YEndDocPrinter, YFlushPrinter, YGetPrinter, YGetPrinterDriver2, YGetPrinterDriverDirectory, YReadPrinter, YSeekPrinter, YSetJob, YSetPort, YSplReadPrinter, YWritePrinter RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win64 Executable Generic (59.6%) Win32 Executable MS Visual C++ (generic) (26.2%) Win32 Executable Generic (5.9%) Win32 Dynamic Link Library (generic) (5.2%) Generic Win/DOS Executable (1.3%) sigcheck: publisher….: Microsoft Corporation copyright….: © Microsoft Corporation. All rights reserved. product……: Microsoft_ Windows_ Operating System description..: Spooler SubSystem App original name: spoolsv.exe internal name: spoolsv.exe file version.: 5.1.2600.5512 (xpsp.080413-0852) comments…..: n/a signers……: - signing date.: - verified…..: Unsigned ————————-
File ctfmon.exe received on 2010.07.27 08:21:48 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/42 (0%) Loading server information… Your file is queued in position: 3. Estimated start time is between 61 and 87 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2010.07.27.00 2010.07.26 - AntiVir 8.2.4.26 2010.07.26 - Antiy-AVL 2.0.3.7 2010.07.26 - Authentium 5.2.0.5 2010.07.27 - Avast 4.8.1351.0 2010.07.26 - Avast5 5.0.332.0 2010.07.26 - AVG 9.0.0.851 2010.07.26 - BitDefender 7.2 2010.07.27 - CAT-QuickHeal 11.00 2010.07.27 - ClamAV 0.96.0.3-git 2010.07.27 - Comodo 5553 2010.07.27 - DrWeb 5.0.2.03300 2010.07.27 - Emsisoft 5.0.0.34 2010.07.27 - eSafe 7.0.17.0 2010.07.26 - eTrust-Vet 36.1.7738 2010.07.26 - F-Prot 4.6.1.107 2010.07.27 - F-Secure 9.0.15370.0 2010.07.27 - Fortinet 4.1.143.0 2010.07.24 - GData 21 2010.07.27 - Ikarus T3.1.1.84.0 2010.07.27 - Jiangmin 13.0.900 2010.07.26 - Kaspersky 7.0.0.125 2010.07.27 - McAfee 5.400.0.1158 2010.07.27 - McAfee-GW-Edition 2010.1 2010.07.27 - Microsoft 1.6004 2010.07.27 - NOD32 5315 2010.07.26 - Norman 6.05.11 2010.07.27 - nProtect 2010-07-27.01 2010.07.27 - Panda 10.0.2.7 2010.07.26 - PCTools 7.0.3.5 2010.07.27 - Prevx 3.0 2010.07.27 - Rising 22.58.01.03 2010.07.27 - Sophos 4.55.0 2010.07.27 - Sunbelt 6646 2010.07.27 - SUPERAntiSpyware 4.40.0.1006 2010.07.27 - Symantec 20101.1.1.7 2010.07.27 - TheHacker 6.5.2.1.326 2010.07.27 - TrendMicro 9.120.0.1004 2010.07.27 - TrendMicro-HouseCall 9.120.0.1004 2010.07.27 - VBA32 3.12.12.6 2010.07.27 - ViRobot 2010.7.28.3961 2010.07.27 - VirusBuster 5.0.27.0 2010.07.26 - Additional information File size: 15360 bytes MD5…: 50b3edf71885d610401f5dc03b1c03d8 SHA1..: 6cbb73608e62cbef547c30fac663a4a0417e92cc SHA256: 12e5e8ffd84d33d02d4756233de59576ba966efc6a840fa663c6d757160d1556 ssdeep: 192:WMzGoc4F/MNhlYWpjZ+o7NpO7MIl8SVPTI7mW7rOi7oLG9lMnjmxAITljrUF E3W3:n21Eo7NY8MPTIaW7/lumxlJlWDlgW PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x2e35 timedatestamp…..: 0x48025356 (Sun Apr 13 18:39:18 2008) machinetype…….: 0x14c (I386) ( 3 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x2ab8 0x2c00 6.75 8b10731da52299a05a74e30d91089a2d .data 0x4000 0x210 0x200 1.07 bd8c5cd346a9f53dc0dbc69260ab2240 .rsrc 0x5000 0x870 0xa00 3.85 421ca88053c2138f828a915f2a95d754 ( 6 imports ) > msvcrt.dll: _controlfp, _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _cexit, _XcptFilter, _exit, _c_exit > ADVAPI32.dll: RegDeleteValueA, RegOpenKeyExA, RegCloseKey, RegSetValueExA, RegCreateKeyA, RegCreateKeyExA > KERNEL32.dll: lstrcpynA, lstrlenA, GetSystemDirectoryA, GetSystemWindowsDirectoryA, GetVersionExA, GetACP, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LocalFree, CloseHandle, ResetEvent, OpenEventA, CreateProcessA, lstrcatA, GetSystemInfo, lstrcmpiA, FreeLibrary, LoadLibraryA, CreateEventA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, LocalAlloc, GetProcAddress > USER32.dll: EnumWindows, GetClassNameA, FindWindowA, PostMessageA, SetTimer, KillTimer, MsgWaitForMultipleObjects, PeekMessageA, TranslateMessage, DispatchMessageA, GetMessageA, SetWindowPos, LoadCursorA, RegisterClassExA, DefWindowProcA, PostQuitMessage, CreateWindowExA, GetSystemMetrics > MSCTF.dll: TF_InitSystem, TF_GetGlobalCompartment, TF_InvalidAssemblyListCacheIfExist, TF_InvalidAssemblyListCache, TF_PostAllThreadMsg, TF_CreateCicLoadMutex, TF_UninitSystem > MSUTB.dll: ClosePopupTipbar, GetPopupTipbar ( 0 exports ) RDS…: NSRL Reference Data Set - pdfid.: - sigcheck: publisher….: Microsoft Corporation copyright….: © Microsoft Corporation. All rights reserved. product……: Microsoft_ Windows_ Operating System description..: CTF Loader original name: CTFMON.EXE internal name: CTFMON file version.: 5.1.2600.5512 (xpsp.080413-2105) comments…..: n/a signers……: - signing date.: - verified…..: Unsigned trid..: Win32 Executable Generic (42.3%) Win32 Dynamic Link Library (generic) (37.6%) Generic Win/DOS Executable (9.9%) DOS Executable Generic (9.9%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) ———————————————————————————— File userinit.exe received on 2010.07.27 08:25:32 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/42 (0%) Loading server information… Your file is queued in position: 4. Estimated start time is between 70 and 100 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result AhnLab-V3 2010.07.27.00 2010.07.26 - AntiVir 8.2.4.26 2010.07.26 - Antiy-AVL 2.0.3.7 2010.07.26 - Authentium 5.2.0.5 2010.07.27 - Avast 4.8.1351.0 2010.07.26 - Avast5 5.0.332.0 2010.07.26 - AVG 9.0.0.851 2010.07.26 - BitDefender 7.2 2010.07.27 - CAT-QuickHeal 11.00 2010.07.27 - ClamAV 0.96.0.3-git 2010.07.27 - Comodo 5553 2010.07.27 - DrWeb 5.0.2.03300 2010.07.27 - Emsisoft 5.0.0.34 2010.07.27 - eSafe 7.0.17.0 2010.07.26 - eTrust-Vet 36.1.7738 2010.07.26 - F-Prot 4.6.1.107 2010.07.27 - F-Secure 9.0.15370.0 2010.07.27 - Fortinet 4.1.143.0 2010.07.24 - GData 21 2010.07.27 - Ikarus T3.1.1.84.0 2010.07.27 - Jiangmin 13.0.900 2010.07.26 - Kaspersky 7.0.0.125 2010.07.27 - McAfee 5.400.0.1158 2010.07.27 - McAfee-GW-Edition 2010.1 2010.07.27 - Microsoft 1.6004 2010.07.27 - NOD32 5315 2010.07.26 - Norman 6.05.11 2010.07.27 - nProtect 2010-07-27.01 2010.07.27 - Panda 10.0.2.7 2010.07.26 - PCTools 7.0.3.5 2010.07.27 - Prevx 3.0 2010.07.27 - Rising 22.58.01.03 2010.07.27 - Sophos 4.55.0 2010.07.27 - Sunbelt 6646 2010.07.27 - SUPERAntiSpyware 4.40.0.1006 2010.07.27 - Symantec 20101.1.1.7 2010.07.27 - TheHacker 6.5.2.1.326 2010.07.27 - TrendMicro 9.120.0.1004 2010.07.27 - TrendMicro-HouseCall 9.120.0.1004 2010.07.27 - VBA32 3.12.12.6 2010.07.27 - ViRobot 2010.7.28.3961 2010.07.27 - VirusBuster 5.0.27.0 2010.07.26 - Additional information File size: 26624 bytes MD5…: fd570c21ec04e768de7577cad6081c76 SHA1..: 50ddafa10ddf375ed974c703606aaa6c044c78a5 SHA256: 80597c48515335458612dd24034562a0ce6cb0b388b56aa41d7750f238cac209 ssdeep: 768:uiHJi8jDLIDSAaQFxfftjaLacmkLGKBmj:uYJbDMDSA7FxffJaLaSLG6mj PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x54ad timedatestamp…..: 0x480251a8 (Sun Apr 13 18:32:08 2008) machinetype…….: 0x14c (I386) ( 3 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x520e 0x5400 5.95 08f818d9cc956ee97bd5837a7b3278a9 .data 0x7000 0x14c 0x200 1.86 0bb948f267e82975313a03d8c0e8a1cf .rsrc 0x8000 0xd4c 0xe00 4.47 2ead424cee80adf0600377b02bab29a2 ( 9 imports ) > USER32.dll: CreateWindowExW, DestroyWindow, RegisterClassExW, DefWindowProcW, LoadRemoteFonts, wsprintfW, GetSystemMetrics, GetKeyboardLayout, SystemParametersInfoW, GetDesktopWindow, LoadStringW, MessageBoxW, ExitWindowsEx, CharNextW > ADVAPI32.dll: RegOpenKeyExA, ReportEventW, RegisterEventSourceW, DeregisterEventSource, OpenProcessToken, RegCreateKeyExW, RegSetValueExW, GetUserNameW, RegQueryValueExW, RegOpenKeyExW, RegQueryInfoKeyW, RegCloseKey, RegQueryValueExA > CRYPT32.dll: CryptProtectData > WINSPOOL.DRV: SpoolerInit > ntdll.dll: RtlLengthSid, RtlCopySid, _itow, RtlFreeUnicodeString, DbgPrint, wcslen, wcscpy, wcscat, wcscmp, RtlInitUnicodeString, NtOpenKey, NtClose, _wcsicmp, memmove, RtlConvertSidToUnicodeString, NtQueryInformationToken > NETAPI32.dll: DsGetDcNameW, NetApiBufferFree > WLDAP32.dll: -, -, -, -, -, - > msvcrt.dll: __setusermatherr, _initterm, __getmainargs, _acmdln, _adjust_fdiv, _XcptFilter, _exit, _c_exit, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, _cexit, exit > KERNEL32.dll: CompareFileTime, LoadLibraryW, GetProcAddress, FreeLibrary, lstrcpyW, CreateProcessW, lstrlenW, GetVersionExW, LocalFree, LocalAlloc, GetEnvironmentVariableW, CloseHandle, lstrcatW, WaitForSingleObject, DelayLoadFailureHook, GetStartupInfoA, GetModuleHandleA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, LoadLibraryA, InterlockedCompareExchange, LocalReAlloc, GetSystemTime, lstrcmpW, GetCurrentThread, SetThreadPriority, ExpandEnvironmentStringsW, SearchPathW, GetLastError, CreateThread, GetFileAttributesExW, GetSystemDirectoryW, SetCurrentDirectoryW, FormatMessageW, lstrcmpiW, GetCurrentProcess, GetUserDefaultLangID, GetCurrentProcessId, SetEvent, OpenEventW, Sleep, SetEnvironmentVariableW ( 0 exports ) RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) sigcheck: publisher….: Microsoft Corporation copyright….: © Microsoft Corporation. __ _________ ____ _______ ___________. product……: ___________ _______ Microsoft_ Windows_ description..: ________ ________ Userinit original name: USERINIT.EXE internal name: userinit file version.: 5.1.2600.5512 (xpsp.080413-2113) comments…..: n/a signers……: - signing date.: - verified…..: Unsigned —————————————————————————————– regedit.exe is not found
Hello alexger

Thank you for the scans.

The regedit.exe program is most likely "missing" due to the infection (my guess would be that it has become infected and therefore unreadable).


As this virus is still active on your system there is no acurate way of determining how much damage has been caused. You appear to be unable to boot into normal mode at present and would have to (at the very least) uninstall all of the infected programs detected by the Kaspersky Online Scan.

Even after doing this there is no real way to guarantee that your system would be problem free. Polymorphic file infectors are extremely bad news, and serve only to destroy the system which they infect.

After conferring with several colleagues we feel that the best approach to reslove your problem would be to perform a complete system reformat and reinstallation of Windows. I realise that this is not what you want to hear, but it is the only reliable way to ensure that all traces of the virus are eliminated.


If you wish, you may try running the following tool. It may remove the infecting agent, but like I said, the damage that has been caused to your system will be almost impossible to repair with any real certainty. Even after running it, you would almost certainly be faced with additional problems - any machine that has fell victim to a polymorphic file infector can no longer be considered safe.



  • Please perform the following scan

    Print this topic or save to notepad, it will make it easier for you to follow the instructions and complete all of the necessary steps as we will need to close all windows that are open later in the fix.


    • Please download Dr.Web CureIt by clicking here and save the file (called drweb-cureit.exe) to your desktop.

  • Next, please reboot your computer in Safe Mode by doing the following:


    • Restart your computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
    • Use the arrow keys to select the Safe mode menu item.
    • Press Enter.

  • Scan with DrWeb-CureIt as follows:


    • Double-click on the drweb-cureit.exe ico to start the program. An "Express Scan of your PC" notice will appear.
    • Under "Start the Express Scan Now" Click "OK" to start. This is a short scan that will scan the files currently running in memory. If anything is found, click "Yes" when the program asks you if you want to cure it.
    • Note: A window may appear during this phase suggesting you purchase the program - click the X at the top right corner of this window to close it.


    • Once the short scan has finished, Click Options > Change settings.
    • Click on the "Scan tab" and UNcheck "Heuristic analysis".
    • Back at the main window, click "Select drives" and click on the C-drive icon (a red dot will appear over the C-drive icon once it has been selected).
    • Click the "Start/Stop Scanning" button (green arrow on the right) to start the scan.
    • During this scan - if Dr.Web finds an infection a window will pop up requesting your attention. Select the "Cure" button.
    • Note:If the file cannot be cured, Dr.Web will automatically delete the file.


    • When finished, a message will be displayed that will tell you if any viruses were found.
    • Click "Yes to all" if it asks if you want to cure/move the infected file(s).
    • If the infected objects cannot be cured, locate the icon next to the files found. Click once, then click the next icon right below and select "Move incurable".
      (This will move the infected item to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured).
    • Next, in the Dr.Web CureIt menu on top, click "File" and select "Save report list".
    • Save the DrWeb.csv report to your desktop.
    • Exit Dr.Web Cureit when done.


    • Important! Please reboot your computer back into normal mode.
    • After reboot, post the contents of the log from Dr.Web.cvs and a new HJT log in your next reply (you can use Notepad to open the DrWeb.cvs report).

    If you choose to run the tool please post the log created. However as I mentioned above, we feel that the best course of action in this instance would be to reformat.

    Sorry to be the bearer of bad news.

    Best wishes
    JonTom
Hello JonTom,

Thank you for your reply.

I have given some serious thought to reformatting. I needed to save some files though so I tried the tools first.
Please take a look and let me know what you think.

Thank you again for your help.
:)


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:51:02 μμ, on 29/7/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Roxio\BackOnTrack\Instant Restore\BOTService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\wdm\STacSV.exe
C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
C:\WINDOWS\svcadmin.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Program Files\HP\HPBTWD.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\syncables\syncables desktop\Syncables.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\syncables\syncables desktop\jre\bin\javaw.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\syncables\syncables desktop\MigoMapi.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast5\setup\avast.setup
C:\Documents and Settings\Alex\Επιφάνεια εργασίας\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Συνδέσεις
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: facemoods Helper - {64182481-4F71-486b-A045-B233BD0DA8FC} - C:\Program Files\facemoods.com\facemoods\1.3.62.1\facemoods.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Βοηθός εισόδου του Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0559.0\msneshellx.dll (file missing)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0559.0\msneshellx.dll (file missing)
O3 - Toolbar: Nuclear Games Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O3 - Toolbar: facemoods Toolbar - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - C:\Program Files\facemoods.com\facemoods\1.3.62.1\facemoodsTlbr.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
O4 - HKLM\..\Run: [HP BTW Detect Program] C:\Program Files\HP\HPBTWD.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Syncables] C:\Program Files\syncables\syncables desktop\Syncables.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Alex\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [Steam] C:\Program Files\Steam\Steam.exe -silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LaunchU3.exe.lnk = ?
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OneNote Table Of Contents.onetoc2
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O8 - Extra context menu item: Αποστολή σε Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Αποστολή στη συσκευή &Bluetooth… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} (Moonlight MPEG-4 Video Decoder) - http://view.conn-x.gr/surveillance/software/mpeg4_dec.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
O16 - DPF: {67B1A88A-B5D2-48B1-BF93-EB74D6FCB077} (AxisRTPSrcFilterEmb) - http://view.conn-x.gr/surveillance/software/AMC.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Προφορτωτής Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Δαίμονας cache κατηγοριών στοιχείων - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Roxio SAIB Service (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269) - Unknown owner - C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
O23 - Service: Anyplace Control Security - Unknown owner - C:\WINDOWS\svcadmin.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: BOTService - Sonic Solutions - C:\Program Files\Roxio\BackOnTrack\Instant Restore\BOTService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\wdm\STacSV.exe

–
End of file - 13980 bytes
—————————————


dvb4A.tmp;C:\DOCUME~1\Alex\LOCALS~1\Temp;Win32.Parite.2;Διαγράφθηκε.;
othread2.dll;C:\;Program.RemoteAdmin.152;Incurable.Deleted.;
othread2.dll;C:\;Program.RemoteAdmin.152;Invalid path to file ;
setup.exe;C:\Documents and Settings\Alex\Local Settings\Application Data\Google\Chrome\Application\5.0.375.99\Installer;Win32.Parite.2;Cured.;
GoogleUpdate.exe;C:\Documents and Settings\Alex\Local Settings\Application Data\Google\Update\1.2.183.29;Win32.Parite.2;Cured.;
jaureg.exe;C:\Program Files\Common Files\Java\Java Update;Win32.Parite.2;Cured.;
java-rmi.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
javacpl.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
jbroker.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
jp2launcher.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
keytool.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
kinit.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
klist.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
ktab.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
orbd.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
pack200.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
policytool.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
rmid.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
rmiregistry.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
servertool.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
ssvagent.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
tnameserv.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
unpack200.exe;C:\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
crashreporter.exe;C:\Program Files\Mozilla Firefox;Win32.Parite.2;Cured.;
updater.exe;C:\Program Files\Mozilla Firefox;Win32.Parite.2;Cured.;
helper.exe;C:\Program Files\Mozilla Firefox\uninstall;Win32.Parite.2;Cured.;
ooxmi.dll;C:\Program Files\OpenOffice.org 3\Basis\program;Trojan.AdSubscribe.origin;Incurable.Moved.;
soffice.exe;C:\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
drstguimanager.dll;C:\Program Files\SpeedTouch\Dr SpeedTouch;Trojan.DownLoader.origin;Incurable.Moved.;
othread2.dll;C:\RECYCLER\S-1-5-21-1329424299-2075852907-1434492207-1006\Dc12\Myvnc;Program.RemoteAdmin.152;;
othread2.dll;C:\RECYCLER\S-1-5-21-1329424299-2075852907-1434492207-1006\Dc23\Myvnc;Program.RemoteAdmin.152;;
winvnc.exe;C:\RECYCLER\S-1-5-21-1329424299-2075852907-1434492207-1006\Dc23\Myvnc;Program.RemoteAdmin;;
hl.exe;C:\System Rollback Data\Restore\Current\06296\110\Target\Program Files\Counter-Strike 1.6;Win32.Parite.2;Cured.;
hlds.exe;C:\System Rollback Data\Restore\Current\06296\110\Target\Program Files\Counter-Strike 1.6;Win32.Parite.2;Cured.;
hltv.exe;C:\System Rollback Data\Restore\Current\06296\110\Target\Program Files\Counter-Strike 1.6;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\110\Target\Program Files\Counter-Strike 1.6;Win32.Parite.2;Cured.;
7z.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\7-Zip;Win32.Parite.2;Cured.;
7zFM.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\7-Zip;Win32.Parite.2;Cured.;
7zG.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\7-Zip;Win32.Parite.2;Cured.;
Uninstall.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\7-Zip;Win32.Parite.2;Cured.;
jaureg.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\common files\Java\Java Update;Win32.Parite.2;Cured.;
msinfo32.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\common files\microsoft shared\MSInfo;Win32.Parite.2;Cured.;
sapisvr.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\common files\microsoft shared\Speech;Win32.Parite.2;Cured.;
hl.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Counter-Strike 1.6;Win32.Parite.2;Cured.;
hlds.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Counter-Strike 1.6;Win32.Parite.2;Cured.;
hltv.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Counter-Strike 1.6;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Counter-Strike 1.6;Win32.Parite.2;Cured.;
iedw.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer;Win32.Parite.2;Cured.;
icwconn1.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard;Win32.Parite.2;Cured.;
icwconn2.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard;Win32.Parite.2;Cured.;
icwrmind.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard;Win32.Parite.2;Cured.;
icwtutor.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard;Win32.Parite.2;Cured.;
inetwiz.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard;Win32.Parite.2;Cured.;
isignup.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\internet explorer\connection wizard;Win32.Parite.2;Cured.;
java-rmi.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
javacpl.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
javaw.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
javaws.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
jbroker.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
jp2launcher.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
jqsnotify.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
keytool.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
kinit.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
klist.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
ktab.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
orbd.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
pack200.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
policytool.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
rmid.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
rmiregistry.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
servertool.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
ssvagent.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
tnameserv.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
unpack200.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
crashreporter.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Mozilla Firefox;Win32.Parite.2;Cured.;
updater.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Mozilla Firefox;Win32.Parite.2;Cured.;
helper.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\Mozilla Firefox\uninstall;Win32.Parite.2;Cured.;
bckgzm.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows;Win32.Parite.2;Cured.;
chkrzm.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows;Win32.Parite.2;Cured.;
hrtzzm.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows;Win32.Parite.2;Cured.;
rvsezm.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows;Win32.Parite.2;Cured.;
shvlzm.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows;Win32.Parite.2;Cured.;
zclientm.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\msn gaming zone\Windows;Win32.Parite.2;Cured.;
conf.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\netmeeting;Win32.Parite.2;Cured.;
wb32.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\netmeeting;Win32.Parite.2;Cured.;
soffice.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
msimn.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express;Win32.Parite.2;Cured.;
oemig50.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express;Win32.Parite.2;Cured.;
setup50.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express;Win32.Parite.2;Cured.;
wab.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express;Win32.Parite.2;Cured.;
wabmig.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\outlook express;Win32.Parite.2;Cured.;
migrate.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows media player;Win32.Parite.2;Cured.;
setup_wm.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows media player;Win32.Parite.2;Cured.;
wmplayer.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows media player;Win32.Parite.2;Cured.;
dialer.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows nt;Win32.Parite.2;Cured.;
pinball.exe;C:\System Rollback Data\Restore\Current\06296\115\Target\Program Files\windows nt\Pinball;Win32.Parite.2;Cured.;
OLD4B.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Common Files\Microsoft Shared\MSInfo;Win32.Parite.2;Cured.;
OLD4D.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Common Files\Microsoft Shared\Speech;Win32.Parite.2;Cured.;
OLD4F.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer;Win32.Parite.2;Cured.;
OLD51.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD53.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD55.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD57.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD59.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD5B.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD5D.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows;Win32.Parite.2;Cured.;
OLD5F.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows;Win32.Parite.2;Cured.;
OLD61.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows;Win32.Parite.2;Cured.;
OLD63.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows;Win32.Parite.2;Cured.;
OLD65.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows;Win32.Parite.2;Cured.;
OLD67.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\MSN Gaming Zone\Windows;Win32.Parite.2;Cured.;
OLD69.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\NetMeeting;Win32.Parite.2;Cured.;
OLD6B.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\NetMeeting;Win32.Parite.2;Cured.;
OLD6D.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD6F.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD71.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD73.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD75.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD77.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows Media Player;Win32.Parite.2;Cured.;
OLD79.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows Media Player;Win32.Parite.2;Cured.;
OLD7B.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows Media Player;Win32.Parite.2;Cured.;
OLD7D.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows NT;Win32.Parite.2;Cured.;
OLD7F.tmp;C:\System Rollback Data\Restore\Current\06296\116\Target\Program Files\Windows NT\Pinball;Win32.Parite.2;Cured.;
7z.exe;C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\7-Zip;Win32.Parite.2;Cured.;
7zG.exe;C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\7-Zip;Win32.Parite.2;Cured.;
Uninstall.exe;C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\7-Zip;Win32.Parite.2;Cured.;
hl.exe;C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\Counter-Strike 1.6;Win32.Parite.2;Cured.;
hlds.exe;C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\Counter-Strike 1.6;Win32.Parite.2;Cured.;
hltv.exe;C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\Counter-Strike 1.6;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\117\Target\PROGRAM FILES\Counter-Strike 1.6;Win32.Parite.2;Cured.;
javaws.exe;C:\System Rollback Data\Restore\Current\06296\132\Target\PROGRAM FILES\Java\jre6\bin;Win32.Parite.2;Cured.;
jaureg.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Common Files\Java\Java Update;Win32.Parite.2;Cured.;
java-rmi.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
javacpl.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
jbroker.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
jp2launcher.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
keytool.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
kinit.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
klist.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
ktab.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
orbd.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
pack200.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
policytool.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
rmid.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
rmiregistry.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
servertool.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
ssvagent.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
tnameserv.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
unpack200.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Java\jre6\bin;Win32.Parite.2;Cured.;
crashreporter.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Mozilla Firefox;Win32.Parite.2;Cured.;
updater.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Mozilla Firefox;Win32.Parite.2;Cured.;
helper.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\Mozilla Firefox\uninstall;Win32.Parite.2;Cured.;
ooxmi.dll;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\OpenOffice.org 3\Basis\program;Trojan.AdSubscribe.origin;Incurable.Moved.;
soffice.exe;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
drstguimanager.dll;C:\System Rollback Data\Restore\Current\06296\185\Target\Program Files\SpeedTouch\Dr SpeedTouch;Trojan.DownLoader.origin;Incurable.Moved.;
apdproxy.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps;Win32.Parite.2;Cured.;
Adobe Gamma Loader.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe\Calibration;Win32.Parite.2;Cured.;
AdobeUpdater.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe\Updater;Win32.Parite.2;Cured.;
AdobeUpdaterInstallMgr.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe\Updater6;Win32.Parite.2;Cured.;
Adobe_Updater.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe\Updater6;Win32.Parite.2;Cured.;
Adobelmsvc.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Adobe Systems Shared\Service;Win32.Parite.2;Cured.;
IDriver.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\10\Intel 32;Win32.Parite.2;Cured.;
IDriver2.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\10\Intel 32;Win32.Parite.2;Cured.;
IDriver.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\1050\Intel 32;Win32.Parite.2;Cured.;
IDriver2.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\1050\Intel 32;Win32.Parite.2;Cured.;
IDriverT.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\1050\Intel 32;Win32.Parite.2;Cured.;
IDriver.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\9\Intel 32;Win32.Parite.2;Cured.;
IDriver2.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Driver\9\Intel 32;Win32.Parite.2;Cured.;
IKernel.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\Engine\6\Intel 32;Win32.Parite.2;Cured.;
agent.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\UpdateService;Win32.Parite.2;Cured.;
ISDM.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\UpdateService;Win32.Parite.2;Cured.;
issch.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\InstallShield\UpdateService;Win32.Parite.2;Cured.;
jaucheck.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Java\Java Update;Win32.Parite.2;Cured.;
jucheck.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Java\Java Update;Win32.Parite.2;Cured.;
DW20.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\DW;Win32.Parite.2;Cured.;
DWTRIG20.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\DW;Win32.Parite.2;Cured.;
EQNEDT32.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Equation;Win32.Parite.2;Cured.;
OINFOP12.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\MSInfo;Win32.Parite.2;Cured.;
MSE7.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12;Win32.Parite.2;Cured.;
ODSERV.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12;Win32.Parite.2;Cured.;
OFFDIAG.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12;Win32.Parite.2;Cured.;
OFFLB.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12;Win32.Parite.2;Cured.;
ODEPLOY.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Contr;Win32.Parite.2;Cured.;
SETUP.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Contr;Win32.Parite.2;Cured.;
SmartTagInstall.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Smart Tag;Win32.Parite.2;Cured.;
OSE.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Source Engine;Win32.Parite.2;Cured.;
WLLoginProxy.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Windows Live;Win32.Parite.2;Cured.;
dw15.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Works Shared;Win32.Parite.2;Cured.;
WkCalRem.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Works Shared;Win32.Parite.2;Cured.;
WksCal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Microsoft Shared\Works Shared;Win32.Parite.2;Cured.;
r1puninst.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Real\Update_OB;Win32.Parite.2;Cured.;
RealOneMessageCenter.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Real\Update_OB;Win32.Parite.2;Cured.;
upgrdhlp.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Common Files\Real\Update_OB;Win32.Parite.2;Cured.;
DFArc.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood;Win32.Parite.2;Cured.;
dink.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood;Win32.Parite.2;Cured.;
dinkedit.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood;Win32.Parite.2;Cured.;
Uninstall.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood;Win32.Parite.2;Cured.;
compile.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood\develop;Win32.Parite.2;Cured.;
ffcreate.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Dink Smallwood\develop;Win32.Parite.2;Cured.;
Expand.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Empire Interactive\Starsky&Hutch;Win32.Parite.2;Cured.;
AUTOBACK.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\ERUNT;Win32.Parite.2;Cured.;
ERUNT.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\ERUNT;Win32.Parite.2;Cured.;
NTREGOPT.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\ERUNT;Win32.Parite.2;Cured.;
unins000.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\ERUNT;Win32.Parite.2;Cured.;
uninstall.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\facemoods.com\facemoods\1.3.62.1;Win32.Parite.2;Cured.;
unins000.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\GameTop.com\Shark Attack;Win32.Parite.2;Cured.;
BrdItVer.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\BrandIt;Win32.Parite.2;Cured.;
HPQWAVer.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\HP Wireless Assistant;Win32.Parite.2;Cured.;
HPQWA_UI.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\HP Wireless Assistant;Win32.Parite.2;Cured.;
Wireless.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\HP Wireless Assistant;Win32.Parite.2;Cured.;
HPSdpApp.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\SDP;Win32.Parite.2;Cured.;
HPUpdater.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\SDP;Win32.Parite.2;Cured.;
HPWaitWindow.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\SDP;Win32.Parite.2;Cured.;
HPWriter.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\SDP;Win32.Parite.2;Cured.;
WizInstaller.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\Shared;Win32.Parite.2;Cured.;
WizLink.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Hewlett-Packard\Shared;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT;Win32.Parite.2;Cured.;
kb888111srvrtm.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\srvrtm\us;Win32.Parite.2;Cured.;
KB901105.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\srvsp1\us;Win32.Parite.2;Cured.;
KB901105.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\win2k3\jpn;Win32.Parite.2;Cured.;
kb901105.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\win2k3\us;Win32.Parite.2;Cured.;
kb888111w2ksp4.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\win2ksp4\us;Win32.Parite.2;Cured.;
kb835221.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\win2k_xp\us;Win32.Parite.2;Cured.;
kb888111xpsp1.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\xpsp1\us;Win32.Parite.2;Cured.;
kb888111xpsp2.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\HDAQFE\xpsp2\us;Win32.Parite.2;Cured.;
AESTFltr.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\WDM;Win32.Parite.2;Cured.;
suhlp.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\IDT\WDM;Win32.Parite.2;Cured.;
Setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{01FB4998-33C4-443;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{08B3869E-D282-424;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{12933722-E473-484;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{3108C217-BE83-42E;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{3FE31026-246F-4BA;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{5DB1DF0C-AABC-436;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{69DAC00A-7665-4E9;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{96AE7E41-E34E-47D;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{A93C4E94-1005-489;Win32.Parite.2;Cured.;
Setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{CE6D39E2-D4CB-4C4;Win32.Parite.2;Cured.;
Setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{CF149A60-8F5A-463;Win32.Parite.2;Cured.;
Setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{E0AD4033-D89B-11D;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\InstallShield Installation Information\{E3A5A8AB-58F6-45F;Win32.Parite.2;Cured.;
ExtExport.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Internet Explorer;Win32.Parite.2;Cured.;
mbamgui.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Malwarebytes' Anti-Malware;Win32.Parite.2;Cured.;
mbamservice.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Malwarebytes' Anti-Malware;Win32.Parite.2;Cured.;
unins000.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Malwarebytes' Anti-Malware;Win32.Parite.2;Cured.;
CGuard.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft\Search Enhancement Pack\Choice Guard;Win32.Parite.2;Cured.;
CLVIEW.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
CNFNOT32.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
DRAT.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
DSSM.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
EDITOR.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
EXCEL.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
excelcnv.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
GRAPH.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
GROOVE.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
GrooveAuditService.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
GrooveClean.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
GrooveMigrator.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
GrooveStdURLLauncher.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
INFOPATH.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
MSACCESS.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
MSOHTMED.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
MSPUB.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
MSQRY32.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
MSTORDB.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
MSTORE.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
ONENOTE.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
ORGWIZ.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
POWERPNT.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
PPTVIEW.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
PROJIMPT.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
REGFORM.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
SCANOST.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
SCANPST.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
SELFCERT.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
SETLANG.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
TLIMPT.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
VPREVIEW.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
Wordconv.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12;Win32.Parite.2;Cured.;
ONELEV.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\Office12\1033;Win32.Parite.2;Cured.;
PPTVIEW.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Office\PowerPoint Viewer;Win32.Parite.2;Cured.;
sllauncher.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Silverlight;Win32.Parite.2;Cured.;
agcp.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Silverlight\4.0.50524.0;Win32.Parite.2;Cured.;
coregen.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Silverlight\4.0.50524.0;Win32.Parite.2;Cured.;
Silverlight.Configuration.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Silverlight\4.0.50524.0;Win32.Parite.2;Cured.;
MSWorks.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
WkDStore.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
wkgdcach.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
wklnckml.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
wkplmstp.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
wksab.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
wksdb.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
WksSb.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
wksss.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
wkwcestp.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Microsoft Works;Win32.Parite.2;Cured.;
MsiZapA.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\MSECACHE\WICU3;Win32.Parite.2;Cured.;
MsiZapU.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\MSECACHE\WICU3;Win32.Parite.2;Cured.;
MsiZap.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\MSECACHE\WICU3\Ansi;Win32.Parite.2;Cured.;
MsiZap.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\MSECACHE\WICU3\Unicode;Win32.Parite.2;Cured.;
uninstal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Nice-Games\Tank-o-box;Win32.Parite.2;Cured.;
Tank-o-box.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Nice-Games\Tank-o-box\game;Win32.Parite.2;Cured.;
nicej2k.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Nice-Games\Tank-o-box\game\scripts;Win32.Parite.2;Cured.;
oggdec.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Nice-Games\Tank-o-box\game\scripts;Win32.Parite.2;Cured.;
oalinst.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenAL;Win32.Parite.2;Cured.;
gengal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program;Win32.Parite.2;Cured.;
nsplugin.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program;Win32.Parite.2;Cured.;
odbcconfig.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program;Win32.Parite.2;Cured.;
senddoc.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program;Win32.Parite.2;Cured.;
setofficelang.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program;Win32.Parite.2;Cured.;
wininst.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\Basis\program\python-core-2.3.4\lib\dist;Win32.Parite.2;Cured.;
crashrep.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
python.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
quickstart.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
sbase.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
sdraw.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
simpress.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
smath.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
sweb.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
unoinfo.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
unopkg.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\OpenOffice.org 3\program;Win32.Parite.2;Cured.;
LaunchCooliris.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\PicLensIE;Win32.Parite.2;Cured.;
fixrjb.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer;Win32.Parite.2;Cured.;
realjbox.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer;Win32.Parite.2;Cured.;
realplay.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer;Win32.Parite.2;Cured.;
RecordingManager.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer;Win32.Parite.2;Cured.;
rphelperapp.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer;Win32.Parite.2;Cured.;
convert.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\converter;Win32.Parite.2;Cured.;
RealConverter.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\converter;Win32.Parite.2;Cured.;
r1puninst.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\converter\Update;Win32.Parite.2;Cured.;
setup.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Real\RealPlayer\Setup;Win32.Parite.2;Cured.;
revcon.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Realtek\USB2.0 Card Reader Software;Win32.Parite.2;Cured.;
SaibSVR.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Roxio\BackOnTrack\Disaster Recovery;Win32.Parite.2;Cured.;
SaibIa32Install.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Roxio\BackOnTrack\Disaster Recovery\Drivers;Win32.Parite.2;Cured.;
Backup_Central10.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Roxio\BackOnTrack\Main;Win32.Parite.2;Cured.;
SkypeIEPluginBroker.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Skype\Toolbars\Internet Explorer;Win32.Parite.2;Cured.;
SkypeNames2.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Skype\Toolbars\Shared;Win32.Parite.2;Cured.;
Contra Game - The Guns Nomads.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Contra Game - The Guns Nomads;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Contra Game - The Guns Nomads;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Mario Forever Galaxy;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Mario Forever Lost Map;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Mario Online;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Old Super Mario Bros;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Steam Punk Rally;Win32.Parite.2;Cured.;
Uninstal.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\softendo.com\Super Mario;Win32.Parite.2;Cured.;
logo32.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Softronics\Microsoft Windows Logo;Win32.Parite.2;Cured.;
helper.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Sophos\Sophos Anti-Rootkit;Win32.Parite.2;Cured.;
sarcli.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Sophos\Sophos Anti-Rootkit;Win32.Parite.2;Cured.;
sargui.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Sophos\Sophos Anti-Rootkit;Win32.Parite.2;Cured.;
php.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SpeedTouch\Dr SpeedTouch;Win32.Parite.2;Cured.;
sbautoupdate.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SpywareBlaster;Win32.Parite.2;Cured.;
spywareblaster.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SpywareBlaster;Win32.Parite.2;Cured.;
unins000.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SpywareBlaster;Win32.Parite.2;Cured.;
Steam.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Steam;Win32.Parite.2;Cured.;
UNWISE.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Steam;Win32.Parite.2;Cured.;
WriteMiniDump.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Steam;Win32.Parite.2;Cured.;
unins000.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Super Mario All-Stars;Win32.Parite.2;Cured.;
BootSafe.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware;Win32.Parite.2;Cured.;
RUNSAS.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware;Win32.Parite.2;Cured.;
SASCORE.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware;Win32.Parite.2;Cured.;
SASINST.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware;Win32.Parite.2;Cured.;
SASUNINST.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware;Win32.Parite.2;Cured.;
SSUPDATE.EXE;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\SUPERAntiSpyware;Win32.Parite.2;Cured.;
InstNT.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP;Win32.Parite.2;Cured.;
SynMood.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP;Win32.Parite.2;Cured.;
SynTPHelper.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP;Win32.Parite.2;Cured.;
SynZMetr.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP;Win32.Parite.2;Cured.;
Tutorial.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Synaptics\SynTP;Win32.Parite.2;Cured.;
MigoMobileHost.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop;Win32.Parite.2;Cured.;
syncablesUSB.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop;Win32.Parite.2;Cured.;
java-rmi.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
java.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
javacpl.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
javaws.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
jucheck.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
jusched.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
keytool.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
kinit.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
klist.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
ktab.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
orbd.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
pack200.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
policytool.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
rmid.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
rmiregistry.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
servertool.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
tnameserv.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
unpack200.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\jre\bin;Win32.Parite.2;Cured.;
syncablesdesktop.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\syncables\syncables desktop\syncablesdesktop_Copy;Win32.Parite.2;Cured.;
uninst.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Unlocker;Win32.Parite.2;Cured.;
Unlocker.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Unlocker;Win32.Parite.2;Cured.;
btsendto_explorer.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software;Win32.Parite.2;Cured.;
BTStackServer.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software;Win32.Parite.2;Cured.;
BtwHfConfig.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software;Win32.Parite.2;Cured.;
BtwHtmlPrint.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software;Win32.Parite.2;Cured.;
gzip.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software;Win32.Parite.2;Cured.;
DPInst.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\WIDCOMM\Bluetooth Software\bin;Win32.Parite.2;Cured.;
unins000.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Garbage Collector;Win32.Parite.2;Cured.;
WindowsGarbageCollector.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Garbage Collector;Win32.Parite.2;Cured.;
MsiZap.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Installer Clean Up;Win32.Parite.2;Cured.;
fsssvc.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Family Safety;Win32.Parite.2;Cured.;
fsui.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Family Safety;Win32.Parite.2;Cured.;
wlarp.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Installer;Win32.Parite.2;Cured.;
wloobe.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Installer;Win32.Parite.2;Cured.;
msvs.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live\Messenger;Win32.Parite.2;Cured.;
wlscUploader.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Live Safety Center;Win32.Parite.2;Cured.;
wmccds.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Media Connect 2;Win32.Parite.2;Cured.;
WMCCFG.exe;C:\System Rollback Data\Restore\Current\06296\91\Target\Program Files\Windows Media Connect 2;Win32.Parite.2;Cured.;
aspnet_regiis.exe;C:\System Rollback Data\Restore\Current\06296\92\Target\WINDOWS\Microsoft.NET\Framework\v2.0.50727;Win32.Parite.2;Cured.;
OLD1A.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Common Files\Microsoft Shared\MSInfo;Win32.Parite.2;Cured.;
OLD1E.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Internet Explorer;Win32.Parite.2;Cured.;
OLD38.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\NetMeeting;Win32.Parite.2;Cured.;
OLD3A.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\NetMeeting;Win32.Parite.2;Cured.;
OLD3C.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD3E.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD40.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD42.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD44.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Outlook Express;Win32.Parite.2;Cured.;
OLD46.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Windows Media Player;Win32.Parite.2;Cured.;
OLD48.tmp;C:\System Rollback Data\Restore\Current\06296\94\Target\Program Files\Windows Media Player;Win32.Parite.2;Cured.;
OLD1C.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\Speech;Win32.Parite.2;Cured.;
OLD20.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD22.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD24.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD26.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD28.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD2A.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\Internet Explorer\Connection Wizard;Win32.Parite.2;Cured.;
OLD2C.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows;Win32.Parite.2;Cured.;
OLD2E.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows;Win32.Parite.2;Cured.;
OLD30.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows;Win32.Parite.2;Cured.;
OLD32.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows;Win32.Parite.2;Cured.;
OLD34.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows;Win32.Parite.2;Cured.;
OLD36.tmp;C:\System Rollback Data\Restore\Current\06296\96\Target\PROGRAM FILES\MSN GAMING ZONE\Windows;Win32.Parite.2;Cured.;
A0000263.dll;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Program.RemoteAdmin.152;;
A0000264.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000265.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000266.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000267.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000268.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000269.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000270.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000271.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000272.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000273.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000274.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000275.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000276.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000277.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000278.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000279.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000280.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000281.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000282.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000283.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000284.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000285.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000286.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000287.dll;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Trojan.AdSubscribe.origin;Incurable.Moved.;
A0000288.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000289.dll;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Trojan.DownLoader.origin;Incurable.Moved.;
A0000290.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000291.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000292.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000293.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000294.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000295.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000296.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000297.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000298.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000299.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000300.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000301.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000302.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000303.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000304.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000305.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000306.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000307.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000308.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000309.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000310.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000311.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000312.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000313.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000314.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000315.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000316.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000317.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000318.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000319.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000320.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000321.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000322.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000323.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000324.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000325.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000326.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000327.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000328.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000329.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000330.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000331.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000332.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000333.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000334.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000335.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000336.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000337.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000338.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000339.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000340.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000341.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000342.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000343.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000344.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000345.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000346.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000347.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000348.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000349.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000350.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000351.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000352.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000353.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000354.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000355.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000356.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000357.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000358.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000359.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000360.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000361.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000362.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000363.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000364.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000365.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000366.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000367.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000368.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000369.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000370.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000371.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000372.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000373.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000374.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000375.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000376.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000377.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000378.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000379.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000380.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000381.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000382.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000383.dll;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Trojan.AdSubscribe.origin;Incurable.Moved.;
A0000384.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000385.dll;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Trojan.DownLoader.origin;Incurable.Moved.;
A0000386.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000387.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000388.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000389.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000390.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000391.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000392.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000393.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000394.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000395.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000396.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000397.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000398.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000399.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000400.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000401.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000402.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000403.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000404.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000405.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000406.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000407.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000408.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000409.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000410.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000411.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000412.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000413.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000414.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000415.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000416.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000417.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000418.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000419.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000420.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000421.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000422.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000423.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000424.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000425.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000426.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000427.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000428.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000429.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000430.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000431.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000432.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000433.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000434.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000435.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000436.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000437.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000438.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000439.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000440.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000441.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000442.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000443.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000444.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000445.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000446.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000447.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000448.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000449.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000450.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000451.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000452.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000453.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000454.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000455.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000456.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000457.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000458.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000459.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000460.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000461.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000462.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000463.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000464.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000465.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000466.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000467.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000468.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000469.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000470.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000471.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000472.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000473.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000474.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000475.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000476.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000477.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000478.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000479.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000480.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000481.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000482.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000483.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000484.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000485.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000486.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000487.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000488.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000489.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000490.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000491.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000492.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000493.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000494.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000495.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000496.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000497.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000498.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000499.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000500.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000501.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000502.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000503.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000504.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000505.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000506.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000507.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000508.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000509.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000510.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000511.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000512.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000513.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000514.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000515.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000516.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000517.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000518.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000519.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000520.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000521.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000522.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000523.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000524.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000525.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000526.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000527.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000528.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000529.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000530.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000531.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000532.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000533.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000534.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000535.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000536.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000537.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000538.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000539.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000540.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000541.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000542.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000543.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000544.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000545.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000546.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000547.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000548.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000549.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000550.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000551.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000552.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000553.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000554.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000555.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000556.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000557.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000558.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000559.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000560.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000561.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000562.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000563.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000564.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000565.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000566.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000567.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000568.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000569.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000570.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000571.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000572.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000573.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000574.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000575.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000576.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000577.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000578.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000579.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000580.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000581.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000582.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000583.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000584.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000585.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000586.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000587.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000588.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000589.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000590.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000591.EXE;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000592.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000593.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000594.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000595.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000596.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000597.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000598.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000599.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000600.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000601.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000602.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000603.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000604.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000605.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000606.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000607.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000608.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000609.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000610.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000611.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000612.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000613.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000614.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000615.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000616.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000617.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000618.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000619.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000620.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000621.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000622.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000623.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000624.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000625.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000626.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000627.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000628.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000629.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000630.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000631.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000632.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000633.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000634.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000635.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000636.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
A0000637.exe;C:\System Volume Information\_restore{46343072-1F44-49A0-8296-9E5D082C92CE}\RP1;Win32.Parite.2;Cured.;
DW20.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425;Win32.Parite.2;Cured.;
ODSERV.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425;Win32.Parite.2;Cured.;
OFFDIAG.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425;Win32.Parite.2;Cured.;
OFFLB.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6425;Win32.Parite.2;Cured.;
DW20.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.6425;Win32.Parite.2;Cured.;
ODSERV.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.6425;Win32.Parite.2;Cured.;
OFFDIAG.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.6425;Win32.Parite.2;Cured.;
OFFLB.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002109150000000000000000F01FEC\12.0.6425;Win32.Parite.2;Cured.;
CNFNOT32.EXE_0004;C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518;Win32.Parite.2;Cured.;
ODSERV.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518;Win32.Parite.2;Cured.;
OFFDIAG.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518;Win32.Parite.2;Cured.;
OFFLB.EXE_0001;C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518;Win32.Parite.2;Cured.;
SCANPST.EXE_0002;C:\WINDOWS\Installer\$PatchCache$\Managed\00002119210000000000000000F01FEC\12.0.4518;Win32.Parite.2;Cured.;
BackupCentral.exe;C:\WINDOWS\Installer\{0517F875-BBB2-4812-A63E-733B33CEF215};Win32.Parite.2;Cured.;
BackupCentral.exe;C:\WINDOWS\Installer\{5A06423A-210C-49FB-950E-CB0EB8C5CEC7};Win32.Parite.2;Cured.;
BackupCentral.exe;C:\WINDOWS\Installer\{87A83C6F-F53C-448A-B078-FF00E3EAEB29};Win32.Parite.2;Cured.;
Hello alexger

Thank you for the logs.

I have given some serious thought to reformatting.

This would be the best thing to do. It will probably save you time in the long run.


I needed to save some files though so I tried the tools first.

This is the main problem you now have. If you save files and transfer them onto your reformatted system, it will only take a single infected file to put you right back to square one. An infected file will re-infect your newly reformatted machine and you'll end up in exactly the same situation. Personally, I would'nt take the risk.


Whilst I have never used it myself, here is another tool that you can try:

http://free.avg.com/gb-en/win32-parite

Follow it up with a Kaspersky Online Scan to check for any leftovers.

You could also try scanning the individual files you want to save using VirusTotal, but there are no guarantees.

Please be aware that I believe a clean break to be the best option.

Good Luck

JonTom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI