This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pop Ups

89 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, about a week ago i started getting lots pop ups, mostly involving computer security (Spyware detection alert, winalert 2007,etc) I even get these pop ups when i don't have an internet browser open. i also have this red circle with an exclaimation point in it on my task bar that appears when i start up my computer, it gives me messages about security. These messages look like real windows messages but some of the wording seems suspicous to me. Any way i ran hijackthis and this is my log. Any response is appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 12:09:30 AM, on 22/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SPEEDB~1\VideoAccelerator.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\BenQ\QMusic2\QMAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\avp.exe
C:\WINDOWS\smanager.7.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\FNTS~1\rundll32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hijackthis\Analyze.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\yxhgyepa.dll (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {7480EC7D-221F-4873-A82F-8A80C3317D1D} - C:\WINDOWS\system32\cbxuvuu.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9E598C2F-5B4A-4404-90B6-F03F2F43295e} - C:\WINDOWS\system32\adqgimyg.dll
O2 - BHO: (no name) - {A884815B-4071-40D7-A73B-49C8E9EBC488} - C:\WINDOWS\system32\byxvu.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {BE7A1B45-81AA-D024-D90B-F8ADABBD72E1} - C:\WINDOWS\system32\iswkuncv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QMusic2] "C:\Program Files\BenQ\QMusic2\QMAgent.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu1000272.exe 61A847B5BBF72813329B385475FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [avp] C:\WINDOWS\system32\avp.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvten.dll,startup
O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\system32\immkfjbt.dll",realset
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\K-litePro\K-litePro.exe" -tray
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Aaou] "C:\PROGRA~1\FNTS~1\rundll32.exe" -vt yazb
O4 - HKCU\..\Run: [Vdpbb] C:\WINDOWS\system32\?icrosoft\w?auboot.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS2.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_adult/We…e/bridge-c9.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: byxvu - C:\WINDOWS\system32\byxvu.dll
O20 - Winlogon Notify: cbxuvuu - C:\WINDOWS\SYSTEM32\cbxuvuu.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winiur32 - C:\WINDOWS\SYSTEM32\winiur32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hello and welcome to TomCoyote!

My name is silver and I'll be helping you clean your machine.

First, you should know that your computer has been infected by a backdoor trojan. This program has the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • A log file will be created at C:\vundofix.txt, please post the contents of this in your next response.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Now open HijackThis, select Open the Misc Tools section
Press the Open Uninstall Manager… button, then press Save list…
Save the Uninstall log to your deskop and include a copy in your next response.
Now press Back and Scan and then Save log to create and save a new HijackThis log.

Once complete, please post the Vundofix log, the uninstall list and a new HijackThis log.
Thanks for the reply, i followed your instructions here are the logs you asked for.

VUNDOFIX LOG:

VundoFix V6.4.1

Checking Java version…

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.4.2.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 8:35:19 AM 23/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\byxvu.dll
C:\WINDOWS\system32\cbxuvuu.dll
C:\WINDOWS\system32\ddcdbyv.dll
C:\WINDOWS\system32\gebxuut.dll
C:\WINDOWS\system32\gebxvut.dll
C:\WINDOWS\system32\immkfjbt.dll
C:\WINDOWS\system32\khfeefd.dll
C:\WINDOWS\system32\laoidhht.dll
C:\WINDOWS\system32\tbjfkmmi.ini
C:\WINDOWS\system32\uvxyb.bak1
C:\WINDOWS\system32\uvxyb.bak2
C:\WINDOWS\system32\uvxyb.ini
C:\WINDOWS\system32\yxhgyepa.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\byxvu.dll
C:\WINDOWS\system32\byxvu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbxuvuu.dll
C:\WINDOWS\system32\cbxuvuu.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\ddcdbyv.dll
C:\WINDOWS\system32\ddcdbyv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebxuut.dll
C:\WINDOWS\system32\gebxuut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebxvut.dll
C:\WINDOWS\system32\gebxvut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\immkfjbt.dll
C:\WINDOWS\system32\immkfjbt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\khfeefd.dll
C:\WINDOWS\system32\khfeefd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\laoidhht.dll
C:\WINDOWS\system32\laoidhht.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tbjfkmmi.ini
C:\WINDOWS\system32\tbjfkmmi.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvxyb.bak1
C:\WINDOWS\system32\uvxyb.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvxyb.bak2
C:\WINDOWS\system32\uvxyb.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvxyb.ini
C:\WINDOWS\system32\uvxyb.ini Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\cbxuvuu.dll
C:\WINDOWS\system32\cbxuvuu.dll Has been deleted!

Performing Repairs to the registry.
Done!




UNISTALL LIST:

a² free 1.1
ABBYY FineReader 5.0 Sprint
AC3Filter (remove only)
Ad-Aware SE Personal
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 9 ActiveX
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 7.0.8
Adobe Shockwave Player
AMPSOFT ZIPUP
Apple Software Update
ATI Display Driver
CC_ccStart
ccCommon
CD Burning 4
Championship Bass
Coffee Break PacMan
Coffee Break Worm
Conexant 56K ACLink Modem
Conexant AC-Link Audio
DivX Codec
EA Network Play System
Easy CD & DVD Creator 6
FaxTools
Guitar Pro 5.0
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Indeo® software
InterVideo WinDVD Creator 2
iTunes
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment, SE v1.4.2_05
Java 2 Runtime Environment, SE v1.4.2_06
Lexmark 810 Series
Lexmark Precision Photo
Lexmark X1100 Series
LimeWire 4.12.6
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSN Music Assistant
MSN Search Toolbar
MSRedist
MSXML 4.0 SP2 (KB927978)
NICI (Shared) U.S./Worldwide (128 bit) (2.6.4-7)
Norton AntiVirus 2004
Norton AntiVirus 2004 (Symantec Corporation)
Norton AntiVirus Parent MSI
Norton Spyware Scan provided by Yahoo!
Norton WMI Update
Outerinfo
PartyPoker
QMusic 2.5
QuickTime
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
SP2 Connection Patcher
SpeedBit Video Accelerator
Spybot - Search & Destroy 1.4
Symantec Script Blocking Installer
SymNet
Synaptics Pointing Device Driver
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Viewpoint Manager (Remove Only)
Winamp (remove only)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Yahoo! Address AutoComplete
Yahoo! Anti-Spy
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Messenger Explorer Bar
Yahoo! Toolbar for Internet Explorer






HIJACKTHIS LOG:

Logfile of HijackThis v1.99.1
Scan saved at 9:07:01 AM, on 23/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SPEEDB~1\VideoAccelerator.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\BenQ\QMusic2\QMAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\avp.exe
C:\WINDOWS\smanager.7.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\FNTS~1\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\Analyze.exe.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0B5B81C4-5D94-4039-91C4-5047389CD52C} - C:\WINDOWS\system32\byxvu.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9E598C2F-5B4A-4404-90B6-F03F2F43295e} - C:\WINDOWS\system32\adqgimyg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QMusic2] "C:\Program Files\BenQ\QMusic2\QMAgent.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu1000272.exe 61A847B5BBF72813329B385475FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [avp] C:\WINDOWS\system32\avp.exe
O4 - HKLM\..\Run: [SManager] smanager.7.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvten.dll,startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\K-litePro\K-litePro.exe" -tray
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Aaou] "C:\PROGRA~1\FNTS~1\rundll32.exe" -vt yazb
O4 - HKCU\..\Run: [Vdpbb] C:\WINDOWS\system32\?icrosoft\w?auboot.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS2.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_adult/We…e/bridge-c9.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winiur32 - C:\WINDOWS\SYSTEM32\winiur32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi ranled,

If you have any problems using these tools please stop and let me know what happened, don't continue on with the next one.

Next we need to use Vundofix once more:
  • Double-click VundoFix.exe to run it again.
  • Click the Scan for Vundo button.
  • Once it's done scanning, right-click the white box in the middle and select Add more files?
  • Copy the following paths into the boxes:

    C:\WINDOWS\system32\adqgimyg.dll
    C:\WINDOWS\SYSTEM32\winiur32.dll

  • Then press Add Files, Close Window and then Remove Vundo
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
Next download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
Now download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

IMPORTANT: Do NOT run any other options until you are asked to do so!

If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C: ), and launch from there.

Once complete, please post the new Vundofix log, the SDFix log the SmitfraudFix log and a new HijackThis log.
Alright i ran everything, but for the smitfraudfix it said something about joedanger, no idea what that meant but i ran it anyway. Once i ran smitfraudfix my norton virus scan gave me several warnings about high risk malicious software, i'm a little curious about what that as all about. Here are the logs.

VUNDOFIX log:

VundoFix V6.4.1

Checking Java version…

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.4.2.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 8:35:19 AM 23/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\byxvu.dll
C:\WINDOWS\system32\cbxuvuu.dll
C:\WINDOWS\system32\ddcdbyv.dll
C:\WINDOWS\system32\gebxuut.dll
C:\WINDOWS\system32\gebxvut.dll
C:\WINDOWS\system32\immkfjbt.dll
C:\WINDOWS\system32\khfeefd.dll
C:\WINDOWS\system32\laoidhht.dll
C:\WINDOWS\system32\tbjfkmmi.ini
C:\WINDOWS\system32\uvxyb.bak1
C:\WINDOWS\system32\uvxyb.bak2
C:\WINDOWS\system32\uvxyb.ini
C:\WINDOWS\system32\yxhgyepa.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\byxvu.dll
C:\WINDOWS\system32\byxvu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbxuvuu.dll
C:\WINDOWS\system32\cbxuvuu.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\ddcdbyv.dll
C:\WINDOWS\system32\ddcdbyv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebxuut.dll
C:\WINDOWS\system32\gebxuut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebxvut.dll
C:\WINDOWS\system32\gebxvut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\immkfjbt.dll
C:\WINDOWS\system32\immkfjbt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\khfeefd.dll
C:\WINDOWS\system32\khfeefd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\laoidhht.dll
C:\WINDOWS\system32\laoidhht.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tbjfkmmi.ini
C:\WINDOWS\system32\tbjfkmmi.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvxyb.bak1
C:\WINDOWS\system32\uvxyb.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvxyb.bak2
C:\WINDOWS\system32\uvxyb.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvxyb.ini
C:\WINDOWS\system32\uvxyb.ini Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\cbxuvuu.dll
C:\WINDOWS\system32\cbxuvuu.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.4.1

Checking Java version…

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.4.2.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.2
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 9:39:27 PM 23/05/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Attempting to delete C:\WINDOWS\system32\adqgimyg.dll
C:\WINDOWS\system32\adqgimyg.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\winiur32.dll
C:\WINDOWS\SYSTEM32\winiur32.dll Has been deleted!

Performing Repairs to the registry.
Done!



SDFIX LOG:


SDFix: Version 1.84

Run by [removed]
Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:






Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\Temp\win1A.tmp.exe - Deleted
C:\WINDOWS\Temp\win6B.tmp.exe - Deleted
C:\WINDOWS\Temp\winC2.tmp.exe - Deleted
C:\WINDOWS\Temp\win1A.tmp.exe - Deleted
C:\WINDOWS\Temp\win6B.tmp.exe - Deleted
C:\WINDOWS\Temp\winC2.tmp.exe - Deleted
C:\DOCUME~1\RANDYL~1\LOCALS~1\Temp\win44.tmp.exe - Deleted
C:\DOCUME~1\RANDYL~1\LOCALS~1\Temp\win49.tmp.exe - Deleted
C:\WINDOWS\smanager.7.exe - Deleted
C:\WINDOWS\system32\avp.exe - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted



Removing Temp Files…

ADS Check:

Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.

Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Enabled:RTC App Sharing"
"C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:Windows® NetMeeting®"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\WinMX\\WinMX.exe"="C:\\Program Files\\WinMX\\WinMX.exe:*:Enabled:WinMX"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\K-litePro\\k-litepro.exe"="C:\\Program Files\\K-litePro\\k-litepro.exe:*:Disabled:K-litePro Ultimate File Sharing"
"C:\\Program Files\\Atari-Infogrames\\RiskII\\RiskII.exe"="C:\\Program Files\\Atari-Infogrames\\RiskII\\RiskII.exe:*:Disabled:Risk II"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Documents and Settings\\Randy Leduc\\Local Settings\\Temp\\SAINST\\VideoAccelerator.exe"="C:\\Documents and Settings\\Randy Leduc\\Local Settings\\Temp\\SAINST\\VideoAccelerator.exe:*:Enabled:VideoAccelerator"
"C:\\Program Files\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe"="C:\\Program Files\\SpeedBit Video Accelerator\\VideoAcceleratorEngine.exe:*:Enabled:VideoAcceleratorEngine"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\DOCUME~1\\RANDYL~1\\LOCALS~1\\Temp\\win36.tmp.exe"="C:\\DOCUME~1\\RANDYL~1\\LOCALS~1\\Temp\\win36.tmp.exe:*:Enabled:win36.tmp"
"C:\\WINDOWS\\TEMP\\win64.tmp.exe"="C:\\WINDOWS\\TEMP\\win64.tmp.exe:*:Enabled:win64.tmp"
"C:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"="C:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe:*:Enabled:VideoAccelerator"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"


Remaining Files:
—————

Backups Folder: - C:\SDFix\backups\backups.zip

Checking For Files with Hidden Attributes:

C:\Program Files\F?nts\rundll32.exe
C:\WINDOWS\system32\?icrosoft\w?auboot.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp

Finished



SMITFRAUDFIX log:

SmitFraudFix v2.186

Scan done at 22:44:25.69, 23/05/2007
Run from C:\Documents and Settings\Randy Leduc\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Randy Leduc


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Randy Leduc\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»»


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32



»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End




Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:46:33 PM, on 23/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\BenQ\QMusic2\QMAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\FNTS~1\rundll32.exe
C:\WINDOWS\system32\?icrosoft\w?auboot.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Hijackthis\Analyze.exe.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0B5B81C4-5D94-4039-91C4-5047389CD52C} - C:\WINDOWS\system32\byxvu.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9E598C2F-5B4A-4404-90B6-F03F2F43295e} - C:\WINDOWS\system32\adqgimyg.dll (file missing)
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QMusic2] "C:\Program Files\BenQ\QMusic2\QMAgent.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avp] C:\WINDOWS\system32\avp.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvten.dll,startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\K-litePro\K-litePro.exe" -tray
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Aaou] "C:\PROGRA~1\FNTS~1\rundll32.exe" -vt yazb
O4 - HKCU\..\Run: [Vdpbb] C:\WINDOWS\system32\?icrosoft\w?auboot.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS2.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN; Search - res://C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Search; - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414YYUS
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_adult/We…e/bridge-c9.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi ranled,

The message about Joedanger is just to clarify that SmitfraudFix is made and supported by a programmer named S!Ri, I think Joedanger is someone who tried to take credit for or profit from the program.

Regarding the detection: process.exe is used by SmitfraudFix and is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. Further info is available here.

Please print/save a copy of these instructions because we will be using Safe Mode, during which time you won't have access to the internet. Again, if you have any problems with these instructions, please stop and let me know.

Please open Start->Control Panel->Add/Remove Programs, look down the list for Outerinfo and remove it.

Don't reboot!

Then download and run this uninstaller:
http://www.outerinfo.com/OiUninstaller.exe

Tutorial for the uninstaller if needed
http://www.outerinfo.com/howto.html

Next press Start->Run, copy/paste notepad C:\WINDOWS\system32\drivers\etc\hosts into the box and press OK
Notepad will open with your 'hosts' file. Copy the following lines and paste them to the bottom of the file:

127.0.0.1 cu.outerinfo.com
127.0.0.1 update.outerinfo.com
127.0.0.1 update2.outerinfo.com

Then close Notepad and when asked whether to save the changes, say Yes

Next, please open Start->Control Panel->Add/Remove Programs again and consider these uninstalls:

Party Poker has been reported as being malware-related so I strongly recommend you remove it. To do so, find PartyPoker on the list and select Remove

You have Viewpoint Media Player installed on your system. This program is not malware but it is foistware in that it is usually installed without the user's knowledge or approval, and for this reason I recommend you remove it. If you actually use this program, I recommend you try using alternatives such as VLC Player or Media Player Classic.
To remove, find Viewpoint Media Player (Remove Only) and select Remove

You have LimeWire, a P2P file sharing program installed on your computer. This program does not come bundled with malware as some similar programs do, but P2P file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove it, but of course the choice is yours. To remove it, find LimeWire 4.12.6 on the list and select Remove

The previous warning also applies for K-litePro, however I can't see an uninstall entry so Add/Remove Programs won't remove it. The program may have an uninstaller in the Start Menu or in it's C:\Program Files\K-litePro folder. If you have any problems please let me know and I'll help you remove it.

Next, download ComboFix to your desktop
  • Double click combofix.exe and follow the prompts.
  • Note: Do not click ComboFix's window while it's running - it may cause it to stall!
  • When finished, it shall produce a log for you, please post it in your next response.
Next, download, install, and update AVG Anti-Spyware 7.5
Download the installer from this page:
http://www.ewido.net/en/download/
  • Save the installer to desktop
  • Double click the installer, select your language, and then select OK
  • Click NEXT->Do or don't read the "User License Agreement"
    Select I Agree->NEXT->INSTALL
  • AVG will now install and afterwards click FINISH - the main screen will then open
  • Click the Update tab at the top. Under Manual Update click Start update.
  • After the update finishes the status bar at the bottom will display Update successful
  • Close AVG Anti-Spyware. Do not run a scan yet.
Next, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines (if present):
O2 - BHO: (no name) - {0B5B81C4-5D94-4039-91C4-5047389CD52C} - C:\WINDOWS\system32\byxvu.dll (file missing)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9E598C2F-5B4A-4404-90B6-F03F2F43295e} - C:\WINDOWS\system32\adqgimyg.dll (file missing)
O4 - HKLM\..\Run: [avp] C:\WINDOWS\system32\avp.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvten.dll,startup
O4 - HKCU\..\Run: [Aaou] "C:\PROGRA~1\FNTS~1\rundll32.exe" -vt yazb
O4 - HKCU\..\Run: [Vdpbb] C:\WINDOWS\system32\?icrosoft\w?auboot.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414YYUS
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_adult/We…e/bridge-c9.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab


If you removed PartyPoker then you can also check these lines (if present):
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe


Then all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Then click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Press OK and Yes to confirm

Next, reboot your computer into Safe Mode
To boot into Safe Mode, please restart your computer. Tap F8 before Windows loads.
Select Safe Mode at the top, on the screen that appears.
Sign in with your normal user account

Once in safe mode:
  • Then run AVG Anti-Spyware 7.5 and click on the Scanner tab at the top
  • Click the Settings tab and then change the recommended action to Quarantine and ensure that Automatically generate report after every scan is selected and Un-check Only if Threats are found
  • Click back to the Scan tab and then click on Complete System Scan.
  • This scan can take quite a while to run, so be prepared.
  • AVG Anti-Spyware 7.5 will list any infections found on the left hand side.
  • Then, next to Set all elements to: click on Recommended action and select Quarantine from the list
  • Click the Apply all actions button. AVG Anti-Spyware 7.5 will display All actions have been applied on the right hand side.
  • Click on Save Report, then Save Report As. This will create a text file. Make sure you know where to find this file again (like on the Desktop).
Now reboot your computer normally

Once complete, please post the ComboFix log, the AVG Antispyware log along with a new HijackThis log, and let me know how your computer is running.
my computer won't let me download the outerinfo uninstaller, its says my security settings won't allow it. What do i have to change my settings to? I'm currently at medium security.
I have put the file in a zip archive and attached it to this post - it's called OiUninstaller.zip

Download the attachment to your Desktop
Right-click the file and choose Extract All..
Press Next twice then Finish and a folder will open with the file inside.

Then continue with the instructions, any further problems let me know :)
i tried to download the zip file but it said i don't have permission to use that feature, even though i'm logged in. Maybe you could email it to me: removed email address
i downloaded it but my computer says the file is invalid or corrupted. Thanks for removing my email i had no idea about the spamming thing.
Sorry that you are having problems!

I have emailed the file to you. If it again doesn't work, make sure Outerinfo has been uninstalled from Add/Remove Programs, skip the uninstaller step, and continue with the instructions.
The outerinfo unistaller didn't work again so i skipped it and did the rest of the steps. The only problem i had was that i couldn't find a way to unistall k-litePro. My computer seems to be working better, i'll post another reply tomorrow about how its working. Here are the logs again:
p.s. it said my post was too long so i'm posting the AVG log in a second post.

COMBOFIX LOG:
"Randy Leduc" - 2007-05-25 21:34:21 Service Pack 2
ComboFix 07-05.26.3.V - Running from: "C:\Documents and Settings\Randy Leduc\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\uulxforo.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


"C:\Program Files\Common Files\Yazzle1162OinAdmin.exe"
"C:\Program Files\winupdates\a.zip"
"C:\WINDOWS\system32\wintsvcc.exe"
"C:\WINDOWS\system32\klikalka.exe"
"C:\Program Files\winupdates"

Purity Folders:

C:\WINDOWS\system32\ICROSO~1
C:\Program Files\STEM~1
C:\Program Files\RACLE~1



((((((((((((((((((((((((((((((( Files Created from 2007-04-25 to 2007-05-25 ))))))))))))))))))))))))))))))))))


2007-05-23 08:35 d——– C:\VundoFix Backups
2007-05-22 00:05 488,144 –a—— C:\Program Files\HJTsetup.exe
2007-05-21 12:40 1,308,216 –a—— C:\Program Files\Analyze.exe.exe
2007-05-21 12:02 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-05-21 12:00 d——– C:\Documents and Settings\RANDYL~1\.housecall6.6
2007-05-21 12:00 d——– C:\DOCUME~1\RANDYL~1\.housecall6.6
2007-05-17 19:14 93,696 –a—— C:\WINDOWS\system32\drvten.dll
2007-05-10 10:38 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-03 22:56 d——– C:\Program Files\QuickTime


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-05-26 01:27:32 ——– d—–w C:\Program Files\Viewpoint
2007-05-26 01:26:59 ——– d—–w C:\Program Files\PartyGaming
2007-05-26 01:01:47 ——– d—–w C:\Program Files\Lx_cats
2007-05-26 01:01:42 ——– d—–w C:\Program Files\SP2 Connection Patcher
2007-05-17 20:27:45 ——– d—–w C:\Program Files\a2 free
2007-05-07 23:51:52 ——– d—–w C:\Program Files\SpeedBit Video Accelerator
2007-05-04 02:53:26 ——– d—–w C:\Program Files\Apple Software Update
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-03-17 13:43:01 292,864 —-a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 —-a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 —-a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 —-a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 —-a-w C:\WINDOWS\system32\win32k.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll [2006-10-26 12:28]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 21:38]
{0B5B81C4-5D94-4039-91C4-5047389CD52C}=C:\WINDOWS\system32\byxvu.dll []
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 03:23]
{9E598C2F-5B4A-4404-90B6-F03F2F43295e}=C:\WINDOWS\system32\adqgimyg.dll []
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll [2005-09-20 19:12]
{BDF3E430-B101-42AD-A544-FADC6B084872}=C:\Program Files\Norton AntiVirus\NavShExt.dll [2003-11-24 09:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-12-22 17:45]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 18:44]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"CARPService"="carpserv.exe" [2003-05-21 15:35 C:\WINDOWS\system32\carpserv.exe]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-04-03 13:28]
"QMusic2"="C:\Program Files\BenQ\QMusic2\QMAgent.exe" [2004-10-04 13:11]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38]
"LXBSCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll" [2004-03-17 12:26]
"MemoryCardManager"="C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe" [2004-02-02 13:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"avp"="C:\WINDOWS\system32\avp.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"SP2 Connection Patcher"="C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" [2005-07-11 07:51]
"Shareaza"="C:\Program Files\K-litePro\K-litePro.exe" []
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BenQ]
D:\BenQJoybeePlayer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
"C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe

*Newly Created Service* -PROCEXP90

Contents of the 'Scheduled Tasks' folder
2007-05-04 02:53:30 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-04-21 01:59:17 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Randy Leduc.job
2007-05-25 19:41:29 C:\WINDOWS\tasks\Symantec NetDetect.job

********************************************************************

catchme 0.3.681 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-25 21:38:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBSCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …


********************************************************************

Completion time: 2007-05-25 21:39:26
C:\ComboFix-quarantined-files.txt … 2007-05-25 21:39

— E O F —


HIJACKTHIS LOG:


Logfile of HijackThis v1.99.1
Scan saved at 12:39:20 PM, on 26/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\BenQ\QMusic2\QMAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hijackthis\Analyze.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QMusic2] "C:\Program Files\BenQ\QMusic2\QMAgent.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\K-litePro\K-litePro.exe" -tray
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS2.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB2.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
Here's the AVG LOG part 1: AVG LOG: ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 11:29:58 AM 26/05/2007 + Scan result: C:\QooBox\Quarantine\C\WINDOWS\system32\uulxforo.dll.vir -> Adware.BHO : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097734.dll -> Adware.BHO : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP685\A0097986.dll -> Adware.BHO : Cleaned with backup (quarantined). C:\VundoFix Backups\adqgimyg.dll.bad -> Adware.BHO : Cleaned with backup (quarantined). C:\Program Files\ProSiteFinder\bsk3aop1.DLL -> Adware.ClearSearch : Cleaned with backup (quarantined). C:\Program Files\ProSiteFinder\uq9ryx7d.DLL -> Adware.ClearSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP682\A0095509.dll -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP682\A0095535.dll -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP683\A0095594.dll -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP683\A0095629.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP683\A0095643.dll -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097694.dll -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097857.dll -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097858.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097865.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\Downloads\RiskIISetup-dm[1].exe -> Adware.Trymedia : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097688.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097690.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097692.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097701.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\cbxuvuu.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\ddcdbyv.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\gebxvut.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\khfeefd.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\MediaGatewayX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/win49.tmp.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097767.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/smanager.7.exe -> Downloader.Alphabet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP682\A0095469.exe -> Downloader.Alphabet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP682\snapshot\MFEX-2.DAT -> Downloader.Alphabet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097757.exe -> Downloader.Alphabet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097764.exe -> Downloader.Alphabet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP682\A0095462.exe -> Downloader.INService : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP682\A0095457.exe -> Downloader.LoadAdv : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1162OinAdmin.exe.vir -> Downloader.PurityScan.eg : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP685\A0097983.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097856.exe -> Downloader.PurityScan.ej : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\klikalka.exe.vir -> Hijacker.Small.mu : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP685\A0097985.exe -> Hijacker.Small.mu : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/win44.tmp.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP681\A0095034.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097766.exe -> Logger.Agent.or : Cleaned with backup (quarantined). C:\Program Files\Hijackthis\backups\backup-20070525-231207-461.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv605.jar-3149e4b4-7a3c8f34.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@network-ca.247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@cupolaventures.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@ford.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@msnportal.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@networksolutions.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@pch.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@adbrite[3].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][2].txt -> TrackingCookie.Dealtime : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][2].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@goclick[1].txt -> TrackingCookie.Goclick : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Live : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][3].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@overture[2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@revsci[1].txt -> TrackingCookie.Revsci : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\[removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\Randy Leduc\Cookies\randy_leduc@yadro[1].txt -> TrackingCookie.Yadro : Cleaned. C:\SDFix\backups\backups.zip/backups/win1A.tmp.exe -> Trojan.Agent.qt : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/win6B.tmp.exe -> Trojan.Agent.qt : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/winC2.tmp.exe -> Trojan.Agent.qt : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097765.exe -> Trojan.Agent.qt : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097768.exe -> Trojan.Agent.qt : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097769.exe -> Trojan.Agent.qt : Cleaned with backup (quarantined). C:\WINDOWS\system32\drvten.dll -> Trojan.Agent.qt : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP684\A0097735.dll -> Trojan.Dialer.qn : Cleaned with backup (quarantined). C:\VundoFix Backups\winiur32.dll.bad -> Trojan.Dialer.qn : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\wintsvcc.exe.vir -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{CD9D4EA6-9C71-4318-B2DA-EA61D372528F}\RP685\A0097984.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete1.11.06.Pride.And.Prejudice.RERip.READ.NFO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\1-More PhotoCalendar 1.80.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\1000 Cell Phone Java Games.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\105 Premium Windows XP Wallpapers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\115 Great WallPaPerS.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\12.08.05.Elvis.The.Early.Years.2005-DnB.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\12.11.05.William.Hung.Hangin.With.Hung.2004-FiCO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\138 Dreamweaver Extensions.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\17 Windows Programs.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\175 Premium XP Wallpapers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\1Click DVD Copy 2.0.0.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\1Click DVD Copy 4.1.1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\1Click DVD Copy 4.2.9.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\1Click DVD Copy Pro 1.0.0.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\200 Winks and Moods for MSN 7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\22 3D Screensaver.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\24 Gigs of METAL (deathheavyblacketc metal).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\247 Aqua Flag Bubble Avatars.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\261MB Php Scripts Archive.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\2Pac - Makaveli The Don The Way He Wanted It.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\2Pac - The Prophet Returns (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\2Pac - The Prophet Returns.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\3D Home Architect Design Suite Deluxe 6.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\3D MP3 Sound Recorder 3.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\3D SexVilla 17.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\3D Studio Max 8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\3D World Map 2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\3DMark 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\3DMark06 Basic Professional Edition Build 1.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\3GP Softwares.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\480 Brush Sets Photoshop CS - CS2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\4826 Polyphonic Ringtones.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\4X4 Evolution.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\50 Funny Computer Pranks.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\A Bronx Tale.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\A-Mac Address Change 4.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\A1Click Ultra PC Cleaner 1.01.35.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\A9CAD Pro 2.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AC Seven Spring.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ACD Systems Canvas X 925.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ACDSee 8.0.67 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ACDSee Photo Manager Pro 8.0.67.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AIO Tracing Utilities.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AMUST Registry Cleaner 2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AT Screen Thief 3.8.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AVConverter MP3 Converter Pro 4.1.18.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AVG Anti-Virus Professional Single.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AVG AntiVirus 7.1.362.652 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AVG Professional 7.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AVI MPEG WMV Joiner 1.9.85.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AVOne 3GP Video Converter 1.58.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Absolute Sound Recorder 3.32.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ace Utilities 3.0.0.4038.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AceBackup 2004 2.1.4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Acronis Bootable CD.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Acronis Disk Director Suite 9.0.534.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Acronis Solutions.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Acropolis 1.0.1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Active WebCam 6.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ad-Aware SE Pro 1.0.6r1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ad-Aware SE Professional Edition 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AdLib eXpress Server 3.0.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AddFlow ActiveX Control 5.4.0.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe After Effects 7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe Audition 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe Encore DVD 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe Illustrator CS2 12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe Keys Bundle.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe Livecycle Designer 7.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe Photoshop 9 CS2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe Photoshop CS2 9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Adobe Premiere Pro 2.0 WinXP.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Advanced Emailer 2.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Advanced Outlook Repair 1.1.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Advanced Registry Doctor Pro 6.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Aeon flux XviD HQ.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Age Of Empires 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Age Of Mythology.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Age of Nemesis - Psychgeist (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Agnitum Outpost Firewall Pro 3.5.638.457.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ahead DVD Ripper Standard Edition 1.3.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ahead DVD Ripper Standard Edition 1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Aio Macromedia Studio 8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alarm Plus Plus 7.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alcazar - Alcastar (CDS 2005) - Dance.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alcohol 120% 1.9.5.3105.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alias Maya Unlimited 7.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alien Skin Exposure 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alien Skin Software 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alive Business Organizer v 1.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alive DVD Ripper.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Alive Task Manager 1.2.0.54.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\All InterVideo Great Products In One C.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\All Media Fixer Pro 5.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\All Office.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Always On Time vv1.0.1.14.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Amazon DVD Shrinker 2.4.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Amigo Easy Video Converter 4.2.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Amor WMV to AVI MPEG VCD DVD Converter 2.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Anastacia - Pieces of a Dream.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Angel City - Love Me Right (2005) - Dance.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Animation Workshop 2.0a10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Antares Autotune 4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Anti Tracks 5.98.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Anti Trojan Elite 3.3.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Anti Trojan Elite 3.43.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Anti-Porn 7.2.8.19.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AntiVir PersonalEdition Classic 7.0 Be.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AnyDVD 5.5.5.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AnyDVD 5.8.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AnyDVD V.5.6.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AoA DVD Ripper 3.89.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ap PDF Split Merge 2.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Aphex Twin - all albums.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Apollo Audio DVD Creator 1.1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Apollo Audio DVD Creator 1.1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Apollo DVD Creator 2.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Aquarium Desktop 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ArcMedia Wine illustrated Guide.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Are We There Yet (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Arial Audio Converter 2.3.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ArtixMedia Menu Studio 3.7.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\As I Lay Dying - Frail Words Collapse.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ashampoo AntiSpyware 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ashampoo MP3 AudioCenter 1.70.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ashampoo Magic Defrag 1.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ashampoo PowerUp XP Platinum 2 2.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Atlantis III - The New World.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Atomix Virtual DJ 3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Audio DVD Creator 1.9.1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Audio Edit Magic 7.7.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Aurora Media Desktop 2.2.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Aurora Media Workshop 2.5.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Aurora Media Workshop 2.59.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Auto FX PhotoGraphic Edges 6.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Auto Form Filler Pro 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AutoFX AutoEye 2.11 for Photoshop.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AutoPatcher XP SP2 (32-bit) January 20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\AutoRun Professional 3.0.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Autodesk 3ds Max 8 - 2CD.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Autodesk AutoCAD 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Autodesk Inventor 10 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Autodesk Survey 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Avast Antivirus Pro 4.6.691.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Avast Professional 4.6.739.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Avast! Pro-Home Edition 4.6.774.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Axialis IconWorkshop ver.6.01 Corporate.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Axoio LionFTP Pro 2006 1.1.51010.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\BWMeter 2.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bad CD Repair Pro 4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\BadCopy Pro 3.80.1108.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bandwith Monitor 2.8B605.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Basic Torrenting Tools AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Batch Video Converter 2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Battle Engine Aquila.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Battle Mages.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Battlefield 2 (RS).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Battlefield 2 - Special Forces.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Beastie Boys - Solid Gold Hits.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Before.It.Had.a.Name.2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bejeweled 2 Deluxe Plus.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Better File Rename 4.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Better Jpeg 1.5.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Betting Genius 3.06.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Beyonce Feat Jayz - Crazy In Love.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\BitDefender Professional Plus 9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\BitTorrent 4.40.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bitdefender Internet Security 9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Black & White 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Blade III Trinity.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Blaze Media Pro 6.0.0.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\BlazeVideo HDTV Player 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bluetooth PC Dialer 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bob Dylan, Slow Train Coming.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bon Jovi - Have A Nice Day - 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\BootSafe 1.0.1002.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bopup Messenger 4.1.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Brice de Nice (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Britney Spears - B In The Mix (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Brokeback Mountain (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Brooklyn Bounce - The Early Years (2005) - Dance.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Bubba Sparxx - Deliverance.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Buffer 2.0.0.139.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Buggles - Video Killed The Radio Star.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Burn Baby Burn , 11 DvD Prog.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Business Card Designer Pro 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Business Cards and Certificates Deluxe 1.6.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Busta Rhymes - Extinction Level Event.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Buzzcocks - Flat-Pack Philosophy (2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\C in a Nutshell.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CCProxy 6.3.3 (rus descript).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CCProxy 6.3.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CDCheck 3.1.10.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CDMenuPro 5.00.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CDRoller 6.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CHM To PDF Converter Professional 3.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CSI The.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CYBERsitter 9.6.2.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CakeWalkSteinberg AIO vol 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Caliban - The Undying Darkness (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Camtasia Studio 3.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Captain Claw v PL.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Card Master 9.0.1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cartoon Maker Pack 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Casino Island To Go.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Charlie Chaplin - The Kid (1921).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Chat Watch 4.28.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Chat Watch 4.280.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CheckMail 2.53.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cheetah DVD Burner 1.57.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Chris Rea The Very Best of Chris Rea.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ChrisTWEAK 1.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Civilization 4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Clint Mansell Requiem for a Dreamv.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Clipboard Box 2.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CloneCD 5.2.6.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CloneDVD 3.9.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CloneDVD Mobile 1.0.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CloneDVD Mobile 1.0.2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CoCSoft Stream Down 5.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Codec Pack 6.0.2.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Codename Panzers Phase Two.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Coffee and Cigarettes (2003).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CoffeeCup Flash Form Builder ver. 4.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CoffeeCup HTML Editor 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cold War.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Collectorz.com Book Collector.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Comic Book Creator 1.07.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Commercial Fonts.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Computer Rental Controller 2.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ComputerTime 1.0.1.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CopyToDVD 3.1.3.137.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Corel Designer Technical Suite 12.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Corel Draw Graphics Sutie X3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Corel Photo Album 6 Deluxe.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Corel WordPerfect Office X3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CorelDRAW Graphics Suite X3 13.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CorelDRAW Graphics Suite X3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Counter Strike Source.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CounterSpy 1.5.77.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CoverPro 7.2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cowon JetAudio Plus! VX 6.2.6.833.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cpu Tools.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Crazy Frog - Crazy Hits.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Crazy Frog Crazy Hits (Christmas.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cucusoft DVD Ripper 3.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cucusoft iPod Movie-Video Converter 3.06.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CursorArts IconForge 7.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CyberLink PowerDVD Copy 1.0.0.701.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\CyberMotion 3D-Designer 11.0.50.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cyberlink PowerDVD Deluxe 6.0.0.2023.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Cyberlink PowerDVD Deluxe 6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DJ Exclusive - Eminem - The Freestyle.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DJ Pantshead Weapons of Ass Destructio.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DJ Tiesto - Live @ Heineken Music Hall.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DJ ToneXpress 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DSL Speed 2.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD Attack.of.the.Killer.Tomatoes.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD Power Burner Pro 2.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD Rebuilder Professional 1.06.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD Rebuilder Professional 1.07.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD Region+CSS Free 5.9.5.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD Wizard Pro 5.75.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD X Studios CloneDVD 3.9.1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD to iPod Converter 3.13.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVD2One 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVDFab Platinum 2.9.6.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVDFab Platinum 2.9.7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVDFab Platinum 2.9.7.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVDInfoPro 4.54.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DVFilm Atlantis 2.0D.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DameWare NT Utilities 5.003.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Danware Netop Desktop Firewall 3.0.180.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DaySmart 5.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dead to Rights 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Death To Rights.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Delta Force 3 Land Warrior.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Delta Force Black hawk down.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DeskCalc TaxPro 3.41.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Deuce Bigalow Male Gigolo.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Diacrit v 4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DiaryOne 5.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DigitByte Photo Slide Show 3.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Digital Audio Editor 4.3.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Digital FilmTools 55mm 6.0 for Photoshop.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Direct MIDI to MP3 Converter 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dirty Deeds.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Disk.Space.Inspector 3.3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DiskMonitor 2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Disneys Kids Games 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DivXToDVD 1.99.23.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DocRepair 2.20.0718.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Download Accelerator Plus 8.0.3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Download Accelerator Plus 8.0.3.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dr Explain 1.5.34.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dr. DivX 2.0.0 Beta 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dr.Web 4.33.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dragon NaturallySpeaking 8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dream Match Tennis 1.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dreamweaver 8 The Missing Manual.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Driver Cleaner Pro 1.3.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Driver Genius Professional.2005 6.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\DropToCD (DataCD) 3.22.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Droppix ISO PowerPack 1.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dumber.Than.Dirt.2005-FiCO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dynadvance.Notifier 1.1.205.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Dynasty Warrior 4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ER.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\EarthDesk 3.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy CD-DA Extractor 9.0.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy CD-DA Extractor 9.02.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy CD-DA Extractor Professional 9.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy DVD CD Burner 3.0.61.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy DVD CD Burner 3.0.65.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy DVD to DVD Copy 3.0.27.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy DVD to DVD Copy 3.0.29.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy File Sharing Web Server 3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy Music CD Burner 3.0.31.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy Real Converter 1.54.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy Video Capture 1.30.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Easy Webtv & Radio 1.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Elecard DVD Player 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Elecard MPEG Player 4.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Eltima SWF Toolbox 2.7.0.15.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Elvis Presley AIO (50 CD Box Set).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Eminem - Curtain Call.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Eminem - Encore - Complete CD.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Encryption Workshop 3.0.50623.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\EngInSite MySQL Client 1.4.9.180.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Engine Analyzer Pro 3.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Enigma 15 Years After Box-Set.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Equatronic Too Close,Too Far and Gone.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Eric Prydz Executive Mix Volume 2v.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\EximiousSoft GIF Creator 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ExplorerPlus 6.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Expresso 2.1.2150.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Extensis Portofolio 8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Extreme Dmoz Extractor 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\F.E.A.R.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FTP Now 2.6.32.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FTP Synchronizer Pro 1.1.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FTP Voyager 12.3.0.1 ES.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fable - The Lost Chapters.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FaceFilter 1.0.518.1 Studio.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FaceOnBody 2.2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Faith Hill - Cry.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fantasydvd Player Professional 8.70.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fast Plans 10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fast food tycoon 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fastlane Pinball.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fatboy Slim - Praise You.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fatboy Slim - Weapon Of Choice.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Feeding Frenzy Plus.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fifa 06.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fifa 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fight Club (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Figure Drawing Without a Model.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\File Control 1.3.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\File Splitter Deluxe 3.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Finale 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fiona Apple - Extraordinary Machine.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FireDaemon Pro 1.9 GA.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FireGraphic 8.5.810.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Firehand Ember Max 7.3.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Firewalls AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FirmTools AlbumCreator 3.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fish Tycoon.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Decompiler 2.5.9.325.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Game - BMX Tricks.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Game - FF Sim Date.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Game - Heli Attack 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Game - Love Hina.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Game - Sexy Slots.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Game - Tubing on Lake.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Game - xGolf.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Player Pro 2.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash Spider 2.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flash eBook AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FlashGet 1.7.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flight Simulator 2004.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Flight.Plan.2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FlightPlan.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Floorplan 3d Design Suite 10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Folly - Resist Convenience (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\FontExpert 2005 7.0r2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Four.Brothers-DMT.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Foxit Reader Pro 1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Frankie Goes To Hollywood - Relax.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Freegine Flash Effects CD1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Fresh RAM 3.3.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Friends The One With All The Trivia.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Frischluft Lenscare 1.1 for After Effe.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Game Jackal 2.7.11.312.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Game-Cloner 1.15.1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Gamehouse Phlinx To Go 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Garth Brooks 4 Classic s.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Gear Video 8.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Genie Soft Backup Manager Pro 5.0.25.1288.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ghostys Phone Games AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\GiPo ScreenCapture 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Gif Animation and 3 D Text Tools AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Glory Road (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Golden FTP Server Pro 2.70.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Goo Goo Dolls - Dizzy Up The Girl.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Google Earth Pro 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Google Video.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\GoogleEarth Pro June.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Gothic II.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\GrabJPG 1.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Grandmas Boy (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Graphic Workshop Professional 2.0a.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Greatest Hits Of The Millennium.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Green Day - 6 Albums.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Greeting Card Factory Deluxe 5.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Guilty Gear Isuka and Guilty Gear XX Reload.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Guitar Pro 5 Full Realistic Sound Engi.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HDD Regenerator.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HItman Code 47.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hack XP AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HackerSmacker 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HackerSmacker 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HackersCrackers Toolkit Suite 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hacking Pack 1 -BlackIDTEAM.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hacking the PSP.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Half-Life2 Antlion Troopers Deuce.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hangman Bible 1.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hard Disk Sentinel 1.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hard Drive Inspector 1.5.895.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hard Truck Tycoon.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hellraiser Hellworld (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HentaII 3D 17.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hero DVD Player 3.0.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hidden Camera 2.15.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hide IP Platinum 2.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hide IP Platinum 2.31.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hide IP Platinum 2.32.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hitler - The Rise Of Evil.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hoo WinTail 3.4.572.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hot Wheels.,Crash.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HyperCam 2.13.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HyperHealth Pro 5.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\HyperSnap-DX 6.02.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Hypnosis for beginner.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\I-Ninja.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\IE DOM Inspector 1.5.1.141.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\IP Anonymous Tools AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\IP Anonymous Tools Options.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ISOBuster Pro 1.9.0.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ISOpen 4.1.15.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\IView MediaPro 3.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\IconCool Studio 1.72.60109.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Iconico Screen Calipers 3.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ImTOO MPEG Encoder 2.1.54.922B.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ImToo Software Collection.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Important anti-virus AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Inetpromoter Web Rank 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Information Dashboard Design The Effective Visual Communicat.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Inside C#, Second.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\InstallShieldFLEXnet AdminStudio 7.0 Professional.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Interactive Atlas Of Human Anatomy 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Intercorr Predict 4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Internet Download Accelerator 4.1.2.845.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Internet Download Manager 5.01 (Multi.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Internet Explorer 7 Plus.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Invadazoid.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Invoice Organizer Pro 1.2 (195$).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\IrfanView 3.98.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\J.River Media Center 11.1.121.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\JAM Software TreeSize Professional 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\JBoss 4.0 - The Official Guide - SAMs.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\JIT Scheduler 8.30.815.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Jacked.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Jackson Browne - Solo Acoustic Vol. 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\James Blunt.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Jarboe - Thirteen Masks.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Jasc Paint Shop Pro 9.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Jay-Z - Rap Phenomenon III.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Jersey Girl.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Johnny Cash - The Complete Sun Singles.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Jpeg Enhancer 1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Juiced.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Just Like Heaven.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
And here's AVG LOG part 2: C:\Documents and Settings\Randy Leduc\Complete\K-Lite Codec Pack 2.64.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\K-Lite Mega Codec Pack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\K-lite Mega Codec Pack 1.16.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\KSoft Uploader 3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Karu 1.0 by Game Gekko.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Kaspersky Anti-Virus Personal 2007.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Kayne West - Registration.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Kerio Personal Firewall 4.13.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Keystroke Converter 5.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\King Kong (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Kingdia CD Extractor 1.2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Kingdia DVD Audio Ripper 1.7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Kiss, Kiss, Bang, Bang 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Kiss.Kiss.Bang.Bang.2005-FiCO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Kremlin 3.0 - Encryption and Security Software.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Lalim File Rename 1.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\LavaSoft Ad-Aware SE Professional 1.06r1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Lavasoft Ad-aware 6.0.3 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Law and Order Justice is Served.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Lego Racers 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Lemonade Website Developer 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Liberty Basic 4.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Life or Something Like It (2002).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Life or Something Like It 2002.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\LimeWire Pro 4.6.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\LimeWire Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\LimeWire.Pro.4.10.5-DEV.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Limewire 4.10.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Limewire Pro 4.10.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Limewire Pro 4.10.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Linux Server Hacks Volume Two.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Lounge for lovers 1-2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MP3 Collector Pro 2.24.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MP3 Splitter And Joiner 2.96.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MP3Producer 2.47.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MPEG4 Direct Maker 5.0.3.133.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MS Works 8.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MSN Applications.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MSN Messenger 8 Plus.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MTV Top 20 - Europen.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MaC Rapid 1.6a Beta11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Macromedia Contribute 3.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Macromedia Dreamweaver 8.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Macromedia Flash 8 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Macromedia Flash MX 2004.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Madden 06.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Madonna - Confessions on a Dance Floor.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Magic Ascii Studio 2.2.1201.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Magic DVD Ripper 3.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Magic Utilities 2006 4.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Magic Utilities 2006 4.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Magic Utilities 2006 4.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MagicMedia 3.25.50920.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Mass Downloader 3.2.0.631.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MaxBulk Mailer 4.2.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MaxBulk Mailer 4.3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MaxtoCode Professional 3.03.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\McAfee AntiSpyware 2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\McAfee Spamkiller 7.0.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\McAfee Wireless Security 4.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Mcafee 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Me and You and Everyone We Know (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Medal Of Honour - Allied Assault.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MediaFace 4.2.83.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MediaMonkey 2.5.1.934.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MediaUndelete 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MeggieSoft Canasta 16.4 16404.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MeggieSoft Euchre and Ecarte 16.4 16404.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Messiah Studio ver. 2.2a.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MetaProducts WebStudio 4.4.259.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Michael Jackson - Black Or White.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft AntiSpyware 1.0.615 Beta.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft AutoRoute Europe 2006 (2 CD.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Defender Beta 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Flight Simulator 2004.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Money 2006 Premium.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Office 12 Suite Enterprise Edition 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Office 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Office Pro 2003 (5in1).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Plus Digital Media Edition 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft SQL Server 2005 32-Bit.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Virtual PC 2004 Service Pack 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Vista 5231 Full (DVD ISO).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Vista.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Visual Studio 2005 Professiona.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Windows Genuine Advantage Cr.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Windows Genuine Product Activation Fix.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Windows Vista (dvd).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Windows Vista 5231.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Windows XP Gold Edition 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Microsoft Windows XP Inside Out, Secon.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Mil Shield 4.6 (rus descript).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Miss E. So Addictive.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Missy Elliot Da Real World.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MixMeister Pro 6.0.7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MooTools RC Localize 3.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Most Beautifull Women Of The World.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Motorama 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Movie DVD Maker 1.3.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Movie DVD Maker 1.4.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Movie Label 2006 1.0.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\MovieDV 6.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Mozilla Firefox 1.501.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Multiboot Recovery CD 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Multiboot Recovery CD.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Music Editing Master 4.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Musicmatch Jukebox Plus 10.00.4033.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\My Password Manager 1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Myst V End Of Ages.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NASA World Wind 1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NBA 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NBA Live 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NCH Express Rip 1.40.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NCH ExpressBurn 1.09.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NCH Golden Records 1.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NETSpeedBoost 3.98.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NHL-2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NOD32 Antivirus System 2.51.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nas - Hood Prophet (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Need For Speed Most Wanted.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Need for Speed Most Wanted Black.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero 7 Plugins Pack Pro 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero 7 Ultra Edtion - One single Pack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero 7 Ultra.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero 7.0.1.4b 32mb.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero 7.0.1.4b Premium & Plugin’s.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero 7.0.5.4 Premium.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero 7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero Burning Rom 7.0.5.4 Premium.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero Premium 7.0.1.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nero Premium 7.0.1.4B.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NeroVision Express 3.1.0.25.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Net Firewall 2.3.1.13.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Net Meter 3.0.239.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Net Transport 2.01.304.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NetConceal Anonymizer 2.97.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NetConceal Anonymizer 2.98.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NetOp School 4.00.2006026.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NetPumper Pro 1.0.2.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NetSarang Xshell 2.0.0712.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Network Administrator s Toolkit 6.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Network LookOut Administrator 1.82.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\NewsLeecher 1.3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Newtek Lightwave 8.2 and 8.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nirvana - About A Girl (MTV Unplugged.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\No One Lives Forever.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\No1 Video Converter 4.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nofeel FTP Server 3.0.2630.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nokia PC Suite 6.7 Release 21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\North Country (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Norton 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Norton Antivirus 2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Norton Antivirus 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Norton Ghost 10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Norton PartitionMagic 8.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Norton Utilities 2006 MegaPack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Notepad ++ (Notepad alternative).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Notorious B.I.G-Duets-the Final Chapter.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Nsauditor Network Security Auditor 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\O&O Complete Suite AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\OST - Underworld Evolution.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ObjectRescue.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ocean FTP Server Professional 1.1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Odds Wizard 1.80.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Offline Explorer Enterprise 4.1.2328.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\OmniPage Professional 15.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\One Click Ringtone Converter 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\One Click Ringtone Converter 1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Online TV Player 2.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Only PCTools 1-ACT Anti KeyLogger 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Only PCTools 1-ACT AntiPhishing 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Only PCTools 1-ACT AntiVirus 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Opera 9 Technology Preview 2 (9.00.8212).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Opera 9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Orchid Medical Spa 5.21.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Outlook Attachment and Picture Extractor 1.39.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Over 4600 Ringtones For Mobile Phone.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\P.O.D Testify.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\P.O.D. - Testify (2006) - Rock.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\P.O.D. - Testify (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PC Agent 4.0.1.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PC Auto Shutdown 1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PC Auto Shutdown 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PC MightyMax 9.0.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PC TODAY April 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PC World Magazine Feb 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PCAutoRepair.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PCHeal 1.1.30.2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PCMedik 6.5.16.2005.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PCThrust 1.1.9.2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PDF Password Remover 2.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PDF Split-Merge 2.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PDF to Word 1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PHP Nuke Templates (boxedart) - Fonts.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PPRecorder 1.53.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PSPWare 2.1.4.283.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PageUpdater II 1.0.2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Panda Titanium 2006 Antivirus + Antisp.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Panda Titanium Antivirus Plus Antispyware 2006 5.01.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Panzer Elite Action.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Paragon Partition Manager Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PayPal Flash Button Creator 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Perfect Sound Recorder 6.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Pes 5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Petz 5 Catz and Dogz.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Photo-Realistic Icons.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PhotoS 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PhotoWatermark Professional.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Photomatix Pro 2.2.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Photoshop Plugins 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Photoshop Plugins.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PicDownloader 4.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Pinnacle Studio Plus 10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Placebo - Meds (Retail 2006) - Alternative.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Placebo Meds.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Planning A Server 2003 Network Infrastructure.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Plato DVD Ripper 4.33.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Plato DVD to MP3 Ripper 4.3.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Playboy The Mansion.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Plesk.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Plugins for Adobe Premiere.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Pocket Snapshot 2.50.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Porno Searcher 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Postsmile 4.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Power Spy 2006 4.0.0.56.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Power Video Converter 1.58.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PowerArchiver 2004 9.20.07.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PowerArchiver 2006 9.51.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PowerDVD Copy 1.0.0.701.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PowerISO 2.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PowerPoint To Flash 2.0 (rus descript).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PowerPoint to Flash 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Prince of Persia - Warrior Within.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Prison Tycoon.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Privacy Defender 7.0.2.R.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Privacy Defender 7.0.2n.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Privacy Shield 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Privacy Shredder 3.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Pro Evolution Soccer 5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\PromiScan 3.0.9.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ProtoPort Personal Firewall 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Punch Home Design Architectural Series.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Quake 4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Queen - Bohemian Rhapsody.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Quick View Folder Size 2.90.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\QuickTime Pro 7.04.80 (rus descript).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Quicken 2006 Premier Home.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\R.I.P. - ActionShooter.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RAPIDSHARE ACCOUNT GENERATOR.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RTF To XHTML Converter 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RaidenFTPD 2.4.2570.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Rainbow Six LockDown.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Rambo 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RapidShare - MegaUpload Universal Pack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RapidShare Anti-Leech Decrypter 4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Rapideshare Gold Pack 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Rapidshare Leecher 4.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Rapidshare Premium Accounts.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ReGet Deluxe 4.1.247.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Real Draw Pro 4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Real Password Protector 2005 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Real Spy Monitor 2.40.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Real Spy Monitor 2.42.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Real Spy Monitor 2.44.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Real Spy Monitor 2.45.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Real War Rogue States.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RealPlayer 10.5 Gold.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RealPlayer 10.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Reallusion iClone Studio Edition 1.0.1213.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Reatogo-X-PE 2.56a.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Recipe Keeper Plus 6.5a.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Recover My Files 3.84.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Recover My Files 3.9.0.338.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Recover My Files 3.90.3328.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Recover My Files 3.92.3356.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RegDoctor 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RegDoctor 1.50.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RegDoctor 1.53.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RegDoctor 1.55.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RegFreeze 5.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RegVac 4.02.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RegVac Registry Cleaner 4.02.11.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RegVac Registry Cleaner 4.02.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Registry Clean Expert 3.66.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Reindeer Graphics Focus Extender 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Remedy - Code Red (2003).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Requiem for a Dream.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Restaurant Empire.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Restauraunt Empire.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Rhythm Rascal 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\River Past Audio CD Ripper 5.10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\River Past Audio Capture 6.10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\River Past Audio Converter Pro 6.10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\River Past Cam Do Webmaster Ed 2.10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\River Past Screen Recorder Pro 6.10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\River Past Talkative 4.10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\River Past Video Cleaner Pro 6.010.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\River Past Video Perspective 6.10.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Road Rush 1.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Robert Palmer - Addicted To Love.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Robin Hood Legend of Sherwood.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Robot Chicken S01E21 Christmas Special.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RockIt 2000 Pro DJ 3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RocketDock 1.1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Roebling WXDesigner 2.13C.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Roller Coaster Tycoon 3 Wild.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\RonyaSoft ProPoster 1.01.16.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Roxio Easy Media Creator 8 Suite Plus.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Roy Orbison - All-Time Greatest Hits.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Rutanil myFiles 1.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SEE Electrical LT 2005.57.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SNMP-Probe 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SONYMAP Route Planner Europe.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SQL Server Backup 5.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Saab Performance Team Show.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sacred.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SagaSoft Power CD to MP3 Maker 1.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Salon Iris 5.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Salon Styler Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SamLogic MultiMailer 2005 4.0.14 Professional.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sams Teach Yourself SQL in 10 Minutes.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sandia Software Cadrail 8.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Saw II (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Scary movie 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Scooter - Apache Rocks The Bottom.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SeaWorld Adventure Parks Tycoon 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sean Paul - Chronicles (2003).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sean Paul - The Trinity.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Second Sight.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sepultura - Dante XXI (2006) - promo.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Serenity Forest Screensaver.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Serv-U 6.1.0.1 Corporate.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Settlers 3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Shaggy Clothes Drop (Advance).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ShareWare Assistant 1.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Shark Tale - PC game.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Shoot-n-Roll.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Shut Down Expert 4.7.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Signature Creator 1.11.40.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SizeExplorer Pro 3.72.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Skype 2.0.0.73.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Slysoft CloneDVD 2.8.8.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Smart DVD CD Burner 3.0.43.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Smart Wedding 4.0.0.1057.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SmartDraw Suite Edition 7.50.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SmartFTP 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SmartWrap 1.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SoftCAT Plus 2.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Softinabox Paste Fast 1.2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Softinterface Convert Doc 3.73.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Softsilver Transformer 2.5.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SolSuite 2006 6.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Solar System 3D Screensaver 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sonic Backup my PC Deluxe 6.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sonic PDF Creator 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sony CD Architect 5.2a.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sony PSP Media Manager.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sony Vegas Movie Studio + DVD 6.0a Bui.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Soundtrack Transporter 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Soundtrack Underworld 2 Evolution.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Space Taxi 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SpecForce.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Species III, RS.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Spector Pro 5.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Speed Video Converter 3.0.4 (rus descript).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SpeedItUp Extreme 3.50.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Splinter Cell - Chaos Theory.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Splinter Cell Pandora Tommorow.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Spy Emergency 2005 2.0.320.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Spy Emergency 2005 Build 2.0.315.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SpyBlocker 9.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SpyRemover 2.43.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SpyStopper Pro 4.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Spyware Doctor 3.2.2.453.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Spyware Doctor 3.5.0.478.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Spyware Terminator 1.1.04.515.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Star Wars Battlefront II (rip).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Stardock Icon Packager 3.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Stardock IconPackager 3.10 Enhanced.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Stardock Windows Blind 5 Enhanced.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Stealth Storage 1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Steganos Security Suite 2006 8.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Steganos Security Suite 2006 8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Steganos Security Suite.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Steinberg MyMP3Pro 5.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sting - Mercury Falling.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\StopCounter 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Stunt GP.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Style XP 3.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Style XP 3.14.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Style XP 3.15.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\StyleXP 3.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Super Internet TV 6.1.0.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Super Jigsaw Mega Bundle 1.3.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Super Utilities Pro 6.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Super Video Converter 2.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SuperCleaner 2.89.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SuperVideoCap 4.38.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SuperVideoCap 4.4.530.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Swish Mx, SWiSH - Make Flash Animation the Easy Way.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\SwordSearcher 4.8.1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sygate Personal Firewall Pro 5.5.2710.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Sygate Personal Firewall Pro 5.6.2808.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Symantec AntiVirus Corp.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Symantec Ghost Solution Suite ver. 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\System Mechanic 6.0j Professional.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\System Mechanic Professional 6.0 S.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\System Mechanic Professional 6.0s.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\System Mechanic Professional 6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Systerac XP Tools 3.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Systerac XP Tools 3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\T-NES - Serious business.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TRANSDAT 10.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Tactile 3d 1.4.2820.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Talisman Desktop 2.9.2900.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Talisman Desktop 2.95.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TamoSoft Essential NetTools 4.0.184.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Techno.com 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Teleport Pro 1.4.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Template Monster 9225.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Template Monster Mega Pack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Teratrax Performance Monitor 2.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Thalia - Amar Sin Ser Amada and Bonus.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Beach.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Cave (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Chronicles of Narnia (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Da Vinci Code trailer 2006 (Drama, Mystery, Thriller).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Dandy Warhols-Odditorium or Warlor.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Dark Hours (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Descent.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Fog.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Hellacopters - Rock & Roll Is Dead.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Incredibles , Rise Of The Underminer.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Legend of Zorro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Lion King Grubalicious.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Little Mermaid Pinball.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Matador.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Oxford Advanced Learners Dictionar.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Panorama Factory 4.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The RZA Hits (1999).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The Strategus Group PassCache 1.0.1864.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The.Last.Drop.2005-TDL.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\The.New.World.SCR-maVen.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ThinSoft BeTwin 2.0.227.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ThinSoft WinConnect Server XP 2.0.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TigerPad 3.5.2 (Dimonius Notepad).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Tindersticks - Curtains.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Tiny Handy Tools 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Token2 Plus 4.5.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Tony Sheridan&The Beatles-Hamburg 1961.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Tools to picture compression AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Top Ten RAM Optimizers.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TopStyle Pro 3.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Total Commander 6.53 Final(!-Full).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Total Commander 6.54 Public Beta 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Touratech QV 4.0.43.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Tradewinds Legends.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Translation 10.0 Plus.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Transporter 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Trendy Flash Site Builder.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Trials Mountain Heights.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TuneUp Utilities 2006 5.0.2331.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TweakNT - Removes Windows Timebomb.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TweakNow PowerPack 2006 1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TweakNow PowerPack 2006 Professional 1.1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TweakNow PowerPack 2006 Professional 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TweakNow PowerPack 2006 Professional.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\TweakNow Powerpack 2006 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Two Weeks Notice.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\U2 - Communication (Limited Edition 2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\UEStudio 05.10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\UML Diagrammer 5.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ulead CD.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ulead DVD MovieFactory 4.0 TBYB.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ultimate Package 3D Icons.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ultimate Rapidleecher ver. 3.1.5 (late.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ultra DVD Creator 1.3.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ultra DVD Creator 1.4.4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ultra DVD Creator 1.4.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ultra MPEG to DVD Burner 1.46.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ultra Video Joiner 2.3.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Ultra WMV Converter 2.0.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\UltraISO Media Edition 7.65 SR-2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Underworld Evolution (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Underworld.Evolution.TS-maVen.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Universal Vista Inspirat Brico Pack All Themes.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Unlocker 1.7.7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Unlocker.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Unreal Tournament 2004.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Unreal Tournament.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\UpDownloader 2.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\UpdateSoft IP AIO.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\V.A. - RAPStar vol. 1 (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\VA - Eminem and Friends - Game Over Sessions (2005) - Hip Ho.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\VA - Eros (2006) - Jazz.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\VA - Hits and Dance 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\VA Trance Nation 22 3CD-2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\VA-Big Mike And Big Stress-Something F.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\VMware Workstation 5.5 Build 18007 RC.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\VMware Workstation 5.5.1.19175.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Vagelis - Picasso (Limited edition).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Valentine Fever Vol 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Valentine Fever Vol 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Venom (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Video Converter Plus 3.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Virtual CD 7.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Virtual CD 7.1.0.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Virus (The Game).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Vista Tranformation Pack 2 XP.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Vocab Arcade 1.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Vray 14803 Full For Max - Works Fine In Max 8 Wit.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WWW File Share Pro 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Wallpapers 1280x1024.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Wallpapers Collection TOP100 Nature.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Wallpapers for Firefox Fans.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Warcraft 3 The Frozen Throne ISO (Fast Server).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Weather Display 10.31Q.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Web Access Screen Pen 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Web Translator 5.00.5100.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Webroot Window Washer 6.0.1.40.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Webroot Window Washer.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\When a Stranger Calls (2006).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\White Bear (ero-Game).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Will Smith - Lost And Found (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Willing Webcam 3.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Win TinyXP Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinAVI Video Converter 7.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinArcHelper 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinBackup Pro 2.1.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinBackup Pro 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinGuard Pro 2006 6.0.8 (rus descript).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinGuard Pro 2006 6.0.8.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinQuota 2.04.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinRAR 3.50 Corp - Salusoft Team.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinRAR 3.51 Gold.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinRAR Crystal Special.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinRAR Extra Utilities Pack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinUtilities 1.6.0101.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinXMedia AVIWMV 3GP Converter 2.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinXMedia AVIWMV PSP Converter 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinXP Manager 4.94.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinXP Manager 4.95.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WinZip Pro 10.0.6685.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Winamp 5.1.1 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Winamp 5.12 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Winamp 5.13 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Winamp Pro 5.13.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Winamp Skins Creator 1.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows Media Player Dolby Surround II Plugin.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows Mobile 5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows Service Process Identifier.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows Vista Codename Longhorn.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows XP 64 Bit Edition (CD).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows XP 64-bit Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows XP Live Edition 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows XP Media Center.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows XP PowerPacker 1.0.7.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows XP Pro SP3 Extras.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows XP Professional 64 Bit.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Windows XP Sp2 9in1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Winter Town 3D Screensaver 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\WiseDesktop 1.2.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Workplace Angel 0.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\World Soccer Winning Eleven 8 International.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\World TV 7.1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Worms 4 Mayhem.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Worms World Party.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\X-Blocker 2.1.1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\X-Copy Media Center 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\X-Setup Pro 7.0.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XFormation 2.0.3.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XL Delete 1.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XLS Converter 1.5.9.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XP Repair Pro 2006 ver. 3.0.20.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XP Shutdown 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XPCSpy Pro 2.54.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XPCSpy Pro 2.58.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XPVista gWin 3D Icons.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XSite Pro 1.53b plus PowerPack.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XYplorer Professional v 4.40.0082.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Xara 3D.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Xceed Ultimate Suite 2006 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Xceed Ultimate Suite 2006 1.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Xilisoft AVI MPEG Converter 2.1.55.12.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Xilisoft DVD To 3GP Converter 4.0.39.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XnView 1.82 (rus descript).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\XoftSpy 4.19.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Xoftspy 4.21.142.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Yahoo Messenger Archiever Decoder 3.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Your Uninstaller! 2006 Pro 5.0.0.225.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Your Uninstaller! 2006 Pro V.5.0.0.225.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Zathura(2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Zend Studio Enterprise Edition 5.1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ZipScan 2.0C.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\ZoneLabs ZoneAlarm Security Suite 6.1.737.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Zoner Photo Studio 7.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Zoom Player Professional 4.51.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Zuma Deluxe Plus.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\Zyl Soft Shut Down Expert 4.7.3.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\iCash 2.0.2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\mIRC 6.16.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\nik Color Efex Pro 2.0 (Photoshop Plug.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\podXP 1.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\Documents and Settings\Randy Leduc\Complete\rReplikator 4.03.77.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\Program Files\winupdates\a.zip.vir/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined). ::Report end

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI