This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

need help with trojans

140 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I recently started getting messages from AVG that virus was detected and while I was trying to find info on the virus it just started popping up more and more with several different trojans. I tried to scan with Avg cannot launch the test center it says "@MainFrm_NotStartUIB" I believe my teenager has downloaded something from shareware without me knowing it. What should I do to remove these and get my virus protection working right again? I also tried to run spybot and adaware both programs will not completely finish scan before freezing. IE browser is going crazy by just closing by itself. would be thankful for any help that you might be. Julie
Sorry to add this but having trouble keeping IE from shutting down every couple of minutes

Logfile of HijackThis v1.98.2
Scan saved at 11:01:37 PM, on 7/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\{B08E8A4B-05FC-1033-1216-021113020001}\Update.exe
C:\Program Files\CallWave\IAM.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.win
F1 - win.ini: run=C:\WINDOWS\system32\mouse_configurator.win
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.4.3.28/aces…s-ob-assets.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.3.0.53/blac…k-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.4.2.30/harv…t-ob-assets.cab
O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.4.2.30/pool…l-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.2.30/mahj…g-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.5.1.24/mlsl…slots-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.4.2.30/hots…k-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.3.1.26/spid…r-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.4.3.28/peak…s-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.4.4.34/word…2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.4.3.28/whac…n-ob-assets.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122319668671
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://198.207.241.9/webline/applets/msie40x.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v46/wof/wof.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98B1C8ED-1091-4B97-8F08-1C006A6248E1}: NameServer = 208.54.220.20 64.91.3.46
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
Logfile of HijackThis v1.99.1
Scan saved at 6:58:12 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\{B08E8A4B-05FC-1033-1216-021113020001}\Update.exe
C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\CallWave\IAM.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\1P0Q4B3C\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.win
F1 - win.ini: run=C:\WINDOWS\system32\mouse_configurator.win
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.4.3.28/aces…s-ob-assets.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.3.0.53/blac…k-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.4.2.30/harv…t-ob-assets.cab
O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.4.2.30/pool…l-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.2.30/mahj…g-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.5.1.24/mlsl…slots-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.4.2.30/hots…k-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.3.1.26/spid…r-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.4.3.28/peak…s-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.4.4.34/word…2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.4.3.28/whac…n-ob-assets.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122319668671
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://198.207.241.9/webline/applets/msie40x.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v46/wof/wof.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98B1C8ED-1091-4B97-8F08-1C006A6248E1}: NameServer = 208.54.220.20 64.91.3.46
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Please disable Teatimer, it can interfere with the cleaning process:

Right-click on the Teatimer icon in the system tray, and "EXIT"

Then do this:

How to Disable Teatimer

After we have cleaned your system, please be sure to reverse this process, and re-enable Teatimer.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.win

F1 - win.ini: run=C:\WINDOWS\system32\mouse_configurator.win

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\program files\common files\{b08e8a4b-05fc-1033-1216-021113020001}\update.exe <— file

C:\WINDOWS\system32\winmgd.win <— file

C:\WINDOWS\system32\mouse_configurator.win <— file

C:\WINDOWS\system32\Regsrv.exe <— file

C:\WINDOWS\system32\Sendi.exe <— file

C:\WINDOWS\system32\AvrilLavigne.jpg <— file

C:\WINDOWS\system32\iwn.dat <— file

C:\WINDOWS\system32\iw.dat. <— file

C:\WINDOWS\system32\ixn.dat <— file

C:\WINDOWS\system32\ix.dat <— file

C:\WINDOWS\system32\File.vbs <— file

C:\WINDOWS\system32\Gedzac.vbs <— file

C:\WINDOWS\system32\hta.vbs <— file

C:\WINDOWS\system32\Israfel.vbs <— file

C:\WINDOWS\system32\pubprn.vbs <— file

C:\WINDOWS\system32\Kernel32.win <— file

C:\WINDOWS\system32\Backup.vbs <— file

C:\WINDOWS\system32\Template.htm <— file

C:\WINDOWS\system32\Filezip.zip <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
ok here it is :blink:


Logfile of HijackThis v1.99.1
Scan saved at 9:17:23 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\CallWave\IAM.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus7.hpwis.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.4.3.28/aces…s-ob-assets.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.3.0.53/blac…k-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.4.2.30/harv…t-ob-assets.cab
O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.4.2.30/pool…l-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.2.30/mahj…g-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.5.1.24/mlsl…slots-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.4.2.30/hots…k-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.3.1.26/spid…r-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.4.3.28/peak…s-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.4.4.34/word…2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.4.3.28/whac…n-ob-assets.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122319668671
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://198.207.241.9/webline/applets/msie40x.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v46/wof/wof.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Looks good. :thumbup:

We need to check two things.

Can you use regedit?
:unsure:

Go to:

Start –> Run

In the box type in regedit then hit (or click OK)

Does that work?

:unsure:

DON'T CHANGE ANYTHING WITH REGEDIT!!!

I just want to know if it will work….

And, can you use the task manager.

Press at the same time…

Does the task manager appear?
:unsure:
yes the task manager works but the regedit does not. it appears like a msdos window and then a box pops up that says it has performed an illegal instruction allowing me to choose ignore or close.
Copy and paste the contents of the quote box below into notepad.

Save it as file name: "fixme.reg" (not including the quotes).

Save as file type: *All files* and save it on to the root folder ("C:\").

REGEDIT4

[HKEY_CLASSES_ROOT\regfile\shell\open\command]
@="regedit.exe \"%1\""

[-HKEY_CLASSES_ROOT\keyfile]

[HKEY_CURRENT_USER\Software\Microsoft\Windows Scripting Host\Settings]
"Timeout"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Scripting Host\Settings]
"Timeout"=-

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=-

[HKEY_CURRENT_USER\Software\Microsoft\WindowsNT\CurrentVersion\Policies\System]
"DisableRegistryTools"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=-


Now, please go to:

Start –> Run

In the box type in c:\fixme.reg then hit (or click OK)

OK any prompts.

Reboot and try regedit once more.
:)
okay did what you said but when i run c:\fixme.reg it ask me to choose a program to open it with. maybe i did something wrong? thanks so much for your time. :oops:
Let's give this a try.

Go to:

Start –> Run

In the box type in regedt32.exe then hit (or click OK)

Click: File –> Import, navigate to c:\fixme.reg, and click Open.

Reboot.

That work for you?
:unsure:
Okay turned on computer today and so far I have moved 100 files to vault and they steadily keep popping up. Think those trojans had a party while I slept and multiplied. However I did go ahead and run the fixme.reg like you said and rebooted. I am posting another log and will wait for your reply to do anything else. I still cannot open regedit and task manager opens fine still. If you had an emicon of a parent choking her teenager I would add that here, however you don't so I will just thank you once again for your time and your knowledge and thank the Lord once again for the unconditional love I have for my children.
Julie

Logfile of HijackThis v1.99.1
Scan saved at 12:37:20 PM, on 7/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\CallWave\IAM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Owner\Desktop\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus7.hpwis.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.4.3.28/aces…s-ob-assets.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.3.0.53/blac…k-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.4.2.30/harv…t-ob-assets.cab
O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.4.2.30/pool…l-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.2.30/mahj…g-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.5.1.24/mlsl…slots-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.4.2.30/hots…k-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.3.1.26/spid…r-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.4.3.28/peak…s-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.4.4.34/word…2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.4.3.28/whac…n-ob-assets.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122319668671
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://198.207.241.9/webline/applets/msie40x.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v46/wof/wof.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98B1C8ED-1091-4B97-8F08-1C006A6248E1}: NameServer = 208.54.220.20 64.91.3.46
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
What are some of the files moved to the vault? :unsure: The log looks like you're clean of any infection. :scratch:
all of them start like this C:\program files\real\real\realoneplayer\datacache\logins\js\buttons\.js and then after the progran named mostly Realone\ Quicken\ recordnow\ and then it gets into the i386 and so on down the list they are popping up so much that I am just having to pretend not there until the timer runs down and the next one pops up. they end in .htm .js .html some with numbers such as b452\ 04b1\04b2\45_b\ so many to list. all say the virus identified is VBS/Gedza.A
this might be easier, sorry didn't know I could do this. this is the list in the vault "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\js\buttons.js","7/24/2006 12:24:48 PM","buttons.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\21b1.htm","7/24/2006 12:24:54 PM","21b1.htm","278.85 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\21b2.htm","7/24/2006 12:25:00 PM","21b2.htm","270.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\38bbb.htm","7/24/2006 12:25:06 PM","38bbb.htm","270.33 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\38billb.htm","7/24/2006 12:25:11 PM","38billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\39b1.htm","7/24/2006 12:25:15 PM","39b1.htm","276.63 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\js\authsubmit.js","7/24/2006 12:25:20 PM","authsubmit.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\page\Central\pagetype.js","7/24/2006 12:25:24 PM","pagetype.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\QWDELUXE\custom\program\inet\common\pnf\quicken\21b1.htm","7/24/2006 12:25:37 PM","21b1.htm","275.72 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\07b2.htm","7/24/2006 12:28:45 PM","07b2.htm","273.17 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\08.HTM","7/24/2006 12:28:49 PM","08.HTM","272.14 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\01_left.htm","7/24/2006 12:28:52 PM","01_left.htm","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\CTW\connectiondata.js","7/24/2006 12:01:07 PM","connectiondata.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\webresources\dnserror.htm","7/24/2006 12:01:56 PM","dnserror.htm","266 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\Home\pageData.js","7/24/2006 12:02:44 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\reboot.html","7/24/2006 12:03:00 PM","reboot.html","290.14 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\index.html","7/24/2006 12:03:09 PM","index.html","271.47 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\postponed.html","7/24/2006 12:03:17 PM","postponed.html","269.65 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\data\links.js","7/24/2006 12:03:23 PM","links.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\upsell\upselldata.js","7/24/2006 12:03:29 PM","upselldata.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\main.html","7/24/2006 12:03:34 PM","main.html","274.4 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\25billb.htm","7/24/2006 12:03:37 PM","25billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\02.htm","7/24/2006 12:03:45 PM","02.htm","270.33 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\networkFooter.htm","7/24/2006 12:03:50 PM","networkFooter.htm","266 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\networkNetEnd.htm","7/24/2006 12:03:56 PM","networkNetEnd.htm","266.14 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\license.htm","7/24/2006 12:04:02 PM","license.htm","302.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\25.htm","7/24/2006 12:04:06 PM","25.htm","271.78 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\25b1.htm","7/24/2006 12:04:12 PM","25b1.htm","274 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\25b2.htm","7/24/2006 12:04:17 PM","25b2.htm","270.58 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\25_left.htm","7/24/2006 12:04:34 PM","25_left.htm","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\38.htm","7/24/2006 12:04:41 PM","38.htm","271.25 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\39_left.htm","7/24/2006 12:04:46 PM","39_left.htm","266.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\40b1.htm","7/24/2006 12:04:50 PM","40b1.htm","271.26 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\40b2.htm","7/24/2006 12:04:53 PM","40b2.htm","271.66 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\40billb.htm","7/24/2006 12:04:57 PM","40billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\40_left.htm","7/24/2006 12:05:00 PM","40_left.htm","266.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\42.htm","7/24/2006 12:05:03 PM","42.htm","270.56 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\42b1.htm","7/24/2006 12:05:06 PM","42b1.htm","277.41 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\42b2.htm","7/24/2006 12:05:10 PM","42b2.htm","269.97 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\42b3.htm","7/24/2006 12:05:13 PM","42b3.htm","269.77 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\42billb.htm","7/24/2006 12:05:17 PM","42billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\02b1.htm","7/24/2006 12:05:21 PM","02b1.htm","272.29 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\networkHeader.htm","7/24/2006 12:05:26 PM","networkHeader.htm","266.9 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\23b1.htm","7/24/2006 12:05:30 PM","23b1.htm","288.66 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\23b2.htm","7/24/2006 12:05:34 PM","23b2.htm","272.12 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\23billb.htm","7/24/2006 12:05:37 PM","23billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\23_left.htm","7/24/2006 12:05:41 PM","23_left.htm","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\24.htm","7/24/2006 12:05:44 PM","24.htm","274.85 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\24aaa.htm","7/24/2006 12:05:49 PM","24aaa.htm","277.38 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\24b1.htm","7/24/2006 12:05:53 PM","24b1.htm","277.75 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\24b2.htm","7/24/2006 12:05:58 PM","24b2.htm","270 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\24billb.htm","7/24/2006 12:06:03 PM","24billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\04.HTM","7/24/2006 12:06:08 PM","04.HTM","270.93 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\40.htm","7/24/2006 12:06:13 PM","40.htm","270.45 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\39billb.htm","7/24/2006 12:06:15 PM","39billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\xpr\pageData.js","7/24/2006 12:06:22 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\networkNetStart.htm","7/24/2006 12:06:27 PM","networkNetStart.htm","267 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\data\countries.js","7/24/2006 12:06:31 PM","countries.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\09billb.htm","7/24/2006 12:06:36 PM","09billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\19.htm","7/24/2006 12:06:41 PM","19.htm","269.92 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\test.html","7/24/2006 12:06:44 PM","test.html","267.21 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\07aaa.htm","7/24/2006 12:06:48 PM","07aaa.htm","276.4 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\18_left.htm","7/24/2006 12:06:51 PM","18_left.htm","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\24_left.htm","7/24/2006 12:06:57 PM","24_left.htm","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\reg\later2.htm","7/24/2006 12:07:01 PM","later2.htm","276.31 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\46b1.htm","7/24/2006 12:07:05 PM","46b1.htm","274.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\46_left.htm","7/24/2006 12:07:08 PM","46_left.htm","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\38_left.htm","7/24/2006 12:07:13 PM","38_left.htm","266.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\Firstrun\1.htm","7/24/2006 12:35:58 PM","1.htm","266.47 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\01b1.htm","7/24/2006 12:07:21 PM","01b1.htm","271.97 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\07.htm","7/24/2006 12:07:25 PM","07.htm","274 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\45b2.htm","7/24/2006 12:36:09 PM","45b2.htm","271.11 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\45billb.htm","7/24/2006 12:36:13 PM","45billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\03aaa.htm","7/24/2006 12:07:31 PM","03aaa.htm","279.69 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\45_left.htm","7/24/2006 12:36:16 PM","45_left.htm","266.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\46.htm","7/24/2006 12:36:20 PM","46.htm","273 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\48.htm","7/24/2006 12:07:39 PM","48.htm","272.27 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\09b3.htm","7/24/2006 12:07:44 PM","09b3.htm","269.53 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\03b1.htm","7/24/2006 12:07:48 PM","03b1.htm","280 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\Error\pageData.js","7/24/2006 12:36:33 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\uploadsFile.htm","7/24/2006 12:07:51 PM","uploadsFile.htm","266.41 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\05b2.htm","7/24/2006 12:07:53 PM","05b2.htm","270 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\08billb.htm","7/24/2006 12:07:56 PM","08billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\Devices\pageData.js","7/24/2006 12:36:42 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\02b2.htm","7/24/2006 12:08:06 PM","02b2.htm","270.4 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\bswi.htm","7/24/2006 12:08:19 PM","bswi.htm","274.89 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\46billb.htm","7/24/2006 12:08:25 PM","46billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\05aaa.htm","7/24/2006 12:08:29 PM","05aaa.htm","277.36 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\39.htm","7/24/2006 12:08:34 PM","39.htm","275.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\21_left.htm","7/24/2006 12:08:52 PM","21_left.htm","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\19_left.htm","7/24/2006 12:09:00 PM","19_left.htm","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\secdetail.htm","7/24/2006 12:09:04 PM","secdetail.htm","275.11 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\security.htm","7/24/2006 12:09:09 PM","security.htm","268.24 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\38b3.htm","7/24/2006 12:09:14 PM","38b3.htm","270.1 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\39b2.htm","7/24/2006 12:09:19 PM","39b2.htm","272.72 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\07b1.htm","7/24/2006 12:09:24 PM","07b1.htm","279.14 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\loc\en\country_list.js","7/24/2006 12:09:34 PM","country_list.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\06.htm","7/24/2006 12:09:39 PM","06.htm","274.56 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\21.htm","7/24/2006 12:09:52 PM","21.htm","272.91 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\searchRowStart.htm","7/24/2006 12:10:09 PM","searchRowStart.htm","266.77 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\searchTab.htm","7/24/2006 12:10:16 PM","searchTab.htm","266.28 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\uploadsQueueStart.htm","7/24/2006 12:10:27 PM","uploadsQueueStart.htm","266.92 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\RecordNow\Explain\MyCD_BufferUnderrun.html","7/24/2006 12:10:35 PM","MyCD_BufferUnderrun.html","270.86 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\RecordNow\Explain\MyCD_Files.html","7/24/2006 12:10:41 PM","MyCD_Files.html","269.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Devices\cdr_help.html","7/24/2006 12:39:31 PM","cdr_help.html","280.25 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\RecordNow\Explain\MyCD_Space_HDD.html","7/24/2006 12:10:54 PM","MyCD_Space_HDD.html","271.33 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\RecordNow\Explain\MyCD_Testing_Disc.html","7/24/2006 12:11:03 PM","MyCD_Testing_Disc.html","269.64 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\RecordNow\Explain\MyCD_Verify.html","7/24/2006 12:11:11 PM","MyCD_Verify.html","269.38 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\Readme.html","7/24/2006 12:11:16 PM","Readme.html","291.72 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\Firstrun\context1.htm","7/24/2006 12:11:26 PM","context1.htm","266.73 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\qlive.htm","7/24/2006 12:40:11 PM","qlive.htm","271.57 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\searchRowEnd.htm","7/24/2006 12:11:39 PM","searchRowEnd.htm","266 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Shareaza\Remote\searchBottom.htm","7/24/2006 12:11:45 PM","searchBottom.htm","266.11 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\04B1.HTM","7/24/2006 12:11:59 PM","04B1.HTM","272.55 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\04B2.HTM","7/24/2006 12:12:06 PM","04B2.HTM","270.12 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\04billb.htm","7/24/2006 12:12:13 PM","04billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\03_LEFT.HTM","7/24/2006 12:41:19 PM","03_LEFT.HTM","266.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\47billb.htm","7/24/2006 12:41:23 PM","47billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\loc\en\language_list.js","7/24/2006 12:42:20 PM","language_list.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\loc\en\welcome.js","7/24/2006 12:42:25 PM","welcome.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\js\actions.js","7/24/2006 12:42:31 PM","actions.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\js\etrap.js","7/24/2006 12:42:38 PM","etrap.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\loc\en\index.js","7/24/2006 12:42:42 PM","index.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\404.html","7/24/2006 12:42:46 PM","404.html","273.23 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\CTW.html","7/24/2006 12:42:49 PM","CTW.html","268.95 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\visualizations\pageData.js","7/24/2006 12:42:54 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\reg\index.htm","7/24/2006 12:43:12 PM","index.htm","275.67 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\search\pageData.js","7/24/2006 12:43:15 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\15billb.htm","7/24/2006 12:43:19 PM","15billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\15_LEFT.HTM","7/24/2006 12:43:29 PM","15_LEFT.HTM","266.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\17.htm","7/24/2006 12:43:35 PM","17.htm","273.75 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\17b1.htm","7/24/2006 12:43:39 PM","17b1.htm","288.66 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\17b2.htm","7/24/2006 12:43:47 PM","17b2.htm","272.12 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\17billb.htm","7/24/2006 12:43:51 PM","17billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\18.htm","7/24/2006 12:43:54 PM","18.htm","271.28 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\18billb.htm","7/24/2006 12:43:58 PM","18billb.htm","266.2 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\42_left.htm","7/24/2006 12:46:20 PM","42_left.htm","266.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\45.htm","7/24/2006 12:46:25 PM","45.htm","272.59 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\45b1.htm","7/24/2006 12:46:29 PM","45b1.htm","273.71 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\46b2.htm","7/24/2006 12:46:36 PM","46b2.htm","270.43 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\46b3.htm","7/24/2006 12:46:40 PM","46b3.htm","271 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\default\pageData.js","7/24/2006 12:46:45 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\custsupport\techsupport\pageData.js","7/24/2006 12:46:53 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\custsupport\sersupport\pageData.js","7/24/2006 12:46:55 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\custsupport\prodsurvey\pageData.js","7/24/2006 12:48:32 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\Common\data.js","7/24/2006 12:48:39 PM","data.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\Channels\pageData.js","7/24/2006 12:48:42 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\loc\en\Central\pageData.js","7/24/2006 12:48:46 PM","pageData.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\CTW\buttons.js","7/24/2006 12:48:50 PM","buttons.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\QWDELUXE\custom\program\inet\common\pnf\quicken\21.htm","7/24/2006 12:48:58 PM","21.htm","272.27 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\blank.htm","7/24/2006 12:49:02 PM","blank.htm","266 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\47.htm","7/24/2006 12:49:05 PM","47.htm","268.98 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\reg\complete.htm","7/24/2006 12:50:05 PM","complete.htm","276.28 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\js\renderforms.js","7/24/2006 12:50:10 PM","renderforms.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\data\buttons.js","7/24/2006 12:50:15 PM","buttons.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\data\languages.js","7/24/2006 12:50:19 PM","languages.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Login\data\years.js","7/24/2006 12:50:23 PM","years.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\Help\myacct.html","7/24/2006 12:50:30 PM","myacct.html","267 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\page\Devices\pagetype.js","7/24/2006 12:50:35 PM","pagetype.js","266.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\GetMedia\page\custsupport\pagetype.js","7/24/2006 12:50:40 PM","pagetype.js","266.37 KB"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI