This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tr/crypt.xpack.gen Malware

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! I'm new here, found you through Google while looking for help for a Trojan/Rootkit I have found on my computer. Stumbled upon this topic: http://forums.tomcoyote.org/Trojan_Found_P…dat_t79088.html

My antivirus is NOD32 and as soon as the virus definitions file #2405 (2007/07/18) came in, it popped up with a "C:\WINDOWS\system32\perfc000.dat" problem, calling it the "TR/Crypt.XPACK.Gen" Trojan/Malware. I asked it to delete/quarantine the file but it kept popping up, each time telling me a different running .exe on my computer had created it. firefox.exe, notepad.exe, services.exe, winamp.exe, and so on. I created an empty file with the same name, perfc000.dat, deleted the one in system32 and put the dummy one. Then, my antivirus stopped popping up each 2 seconds. When I tried deleting the regkey "AppInit_DLLs" located in "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" with the value "C:\WINDOWS\system32\perfc000.dat". I had Tiny Personal Firewall telling me that each of my running .exe files was trying to create the key, I tried to prevent it but one of the programs on my trust list must have ended up creating it back.

After reading the above topic, I know that the malware sits somewhere in user32.dll and I'm not sure of what I should be doing since they went through a lot of steps and not all of them worked. So I guess we'll go through the normal removing procedure :)

Here is my HijackThis! log:

Logfile of HijackThis v1.99.1
Scan saved at 1:28:01 AM, on 19/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\PFShared\UmxCfg.exe
C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe
C:\Program Files\Common Files\PFShared\UmxPol.exe
C:\Program Files\Tiny Firewall Pro\UmxAgent.exe
C:\Program Files\Tiny Firewall Pro\UmxTray.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Subversion\bin\svnservice.exe
C:\Program Files\Subversion\bin\svnserve.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\PFShared\umxlu.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ULI5289\ALi5289.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WhatPulse\WhatPulse.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\FeedReader30\feedreader.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\regedit.exe
C:\WINDOWS\explorer.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
G:\Files\Programmes\F-Secure Rootkit Remover\fsbl2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
G:\Files\Programmes\HijackThis!\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qc-net.com/
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\default.bol\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\default.bol\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab48295.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169866054515
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143835158390
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab28578.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SVNService - Clansoft - C:\Program Files\Subversion\bin\svnservice.exe
O23 - Service: FW Event Manager (UmxAgent) - Computer Associates International, Inc. - C:\Program Files\Tiny Firewall Pro\UmxAgent.exe
O23 - Service: FW Configuration Interpreter (UmxCfg) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\UmxCfg.exe
O23 - Service: FW User-Mode Helper (UmxFwHlp) - Computer Associates International, Inc. - C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe
O23 - Service: FW Live Update (UmxLU) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\umxlu.exe
O23 - Service: FW Policy Manager (UmxPol) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\UmxPol.exe
O23 - Service: wampapache - Unknown owner - G:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - G:\wamp\mysql\bin\mysqld-nt.exe

Thank you very much in advance!

The guidelines say to not reply to my own message, but it won't let me edit it :/

I just want to mention that after putting the dummy file and rebooting, I was able to remove the registry key without having it recreating itself all the time.

However, I still get (but very very rarily) IE pop-ups, and its not the browser I'm browsing with (its not even opened).

I would still like to have my log checked if possible. Thank you very much
Logfile of HijackThis v1.99.1
Scan saved at 9:42:10 AM, on 22/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\PFShared\UmxCfg.exe
C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe
C:\Program Files\Common Files\PFShared\UmxPol.exe
C:\Program Files\Tiny Firewall Pro\UmxAgent.exe
C:\Program Files\Tiny Firewall Pro\UmxTray.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Subversion\bin\svnservice.exe
C:\Program Files\Subversion\bin\svnserve.exe
C:\Program Files\Common Files\PFShared\umxlu.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ULI5289\ALi5289.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\WhatPulse\WhatPulse.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Xfire\Xfire.exe
C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Last.fm\LastFM.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\FeedReader30\feedreader.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
G:\Files\Programmes\HijackThis!\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qc-net.com/
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {60DB71BD-AAA2-4D6A-BAA7-55D0CEDD24C3} - C:\WINDOWS\Config\untafx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\default.bol\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\default.bol\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab48295.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169866054515
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143835158390
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab28578.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: PFW - C:\WINDOWS\SYSTEM32\UmxWnp.Dll
O20 - Winlogon Notify: untafx - C:\WINDOWS\Config\untafx.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SVNService - Clansoft - C:\Program Files\Subversion\bin\svnservice.exe
O23 - Service: FW Event Manager (UmxAgent) - Computer Associates International, Inc. - C:\Program Files\Tiny Firewall Pro\UmxAgent.exe
O23 - Service: FW Configuration Interpreter (UmxCfg) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\UmxCfg.exe
O23 - Service: FW User-Mode Helper (UmxFwHlp) - Computer Associates International, Inc. - C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe
O23 - Service: FW Live Update (UmxLU) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\umxlu.exe
O23 - Service: FW Policy Manager (UmxPol) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\UmxPol.exe
O23 - Service: wampapache - Unknown owner - G:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - G:\wamp\mysql\bin\mysqld-nt.exe

Here you go!
Hi

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

1. Download combofix from one of these links:
Link1
Link2
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Post:

- a fresh HijackThis log (taken after vundofix & combofix)
- combofix report
- vundofix report
Sorry for the delay!

HiJackThis! log:

Logfile of HijackThis v1.99.1
Scan saved at 4:20:25 PM, on 28/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\PFShared\UmxCfg.exe
C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe
C:\Program Files\Common Files\PFShared\UmxPol.exe
C:\Program Files\Tiny Firewall Pro\UmxAgent.exe
C:\Program Files\Tiny Firewall Pro\UmxTray.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Subversion\bin\svnservice.exe
C:\Program Files\Subversion\bin\svnserve.exe
C:\Program Files\Common Files\PFShared\umxlu.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ULI5289\ALi5289.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
G:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Xfire\Xfire.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\cmd.exe
C:\ComboFix\vfind.cfexe
C:\WINDOWS\system32\NOTEPAD.EXE
G:\Files\Programmes\HijackThis!\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qc-net.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - G:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - G:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "G:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Append to existing PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\default.bol\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\default.bol\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab48295.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169866054515
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143835158390
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab28578.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: PFW - C:\WINDOWS\SYSTEM32\UmxWnp.Dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SVNService - Clansoft - C:\Program Files\Subversion\bin\svnservice.exe
O23 - Service: FW Event Manager (UmxAgent) - Computer Associates International, Inc. - C:\Program Files\Tiny Firewall Pro\UmxAgent.exe
O23 - Service: FW Configuration Interpreter (UmxCfg) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\UmxCfg.exe
O23 - Service: FW User-Mode Helper (UmxFwHlp) - Computer Associates International, Inc. - C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe
O23 - Service: FW Live Update (UmxLU) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\umxlu.exe
O23 - Service: FW Policy Manager (UmxPol) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\UmxPol.exe
O23 - Service: wampapache - Unknown owner - G:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - G:\wamp\mysql\bin\mysqld-nt.exe

ComboFix-quarantined log:

2004-08-03 21:07	  2804224	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\_000219_.tmp.dll.vir
2004-08-03 21:07	  2804224	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\_000233_.tmp.dll.vir
2005-02-05 09:28	  164	–a——	C:\Qoobox\Quarantine\C\RECYCLER\desktop.ini.vir
2007-07-18 22:27	  0	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\perfc000.dat.vir


Folder PATH listing for volume System
Volume serial number is BBDD-F240
C:\QOOBOX
\—Quarantine
	+—C
	|   +—RECYCLER
	|   |	   desktop.ini.vir
	|   |	   
	|   \—WINDOWS
	|	   \—system32
	|			   perfc000.dat.vir
	|			   _000219_.tmp.dll.vir
	|			   _000233_.tmp.dll.vir
	|			   
	\—Registry_backups

ComboFix log:

"Mathieu" - 2007-07-28 15:39:56 - ComboFix 07-07-23.6 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


c:\RECYCLER\desktop.ini
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\_000219_.tmp.dll
C:\WINDOWS\system32\_000233_.tmp.dll
C:\WINDOWS\system32\perfc000.dat
C:\WINDOWS\zzzx.exe


((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-28 )))))))))))))))))))))))))))))))


2007-07-28 16:07 36 –a—— C:\WINDOWS\system32\drivers\Ids_cfg.dat
2007-07-28 15:39 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-28 15:33 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet
2007-07-28 15:17 d——– C:\VundoFix Backups
2007-07-28 11:55 d——– C:\Program Files\Common Files\Control Panels
2007-07-28 11:51 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\ALM
2007-07-28 10:26 d——– C:\Program Files\Bonjour
2007-07-28 10:18 d——– C:\Program Files\Common Files\Macrovision Shared
2007-07-18 23:37 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-07-10 07:54 d——– C:\Program Files\JRTwine Software
2007-07-08 20:09 d——– C:\To move
2007-07-08 13:00 d–hs—- C:\found.001
2007-07-06 11:40 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
2007-07-05 17:32 d——– C:\DOCUME~1\Mathieu\APPLIC~1\Winamp
2007-07-03 21:42 56 -r-hs—- C:\WINDOWS\system32\FFB85C6D03.sys
2007-07-03 21:41 2,514 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2007-07-03 21:39 d——– C:\Program Files\Common Files\Enterbrain
2007-07-03 03:29 d——– C:\DOCUME~1\Mathieu\APPLIC~1\Joost
2007-07-03 03:28 d——– C:\Program Files\Joost
2007-07-02 01:09 443,752 –a—— C:\WINDOWS\system32\d3dx10_33.dll
2007-07-02 01:09 261,480 –a—— C:\WINDOWS\system32\xactengine2_7.dll
2007-07-02 01:09 1,123,696 –a—— C:\WINDOWS\system32\D3DCompiler_33.dll
2007-07-02 01:08 3,495,784 –a—— C:\WINDOWS\system32\d3dx9_33.dll
2007-06-30 23:50 d——– C:\DOCUME~1\Mathieu\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-06-28 15:39 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-06-28 15:39 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-06-28 15:39 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-06-28 15:39 d——– C:\DOCUME~1\Mathieu\AppData


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-28 20:11:51 ——– d—–w C:\DOCUME~1\Mathieu\APPLIC~1\Xfire
2007-07-28 20:05:15 59,064 —-a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k
2007-07-28 19:51:13 ——– d—–w C:\DOCUME~1\Mathieu\APPLIC~1\Skype
2007-07-28 18:41:50 ——– d—–w C:\DOCUME~1\Mathieu\APPLIC~1\Hamachi
2007-07-28 17:02:17 ——– d—–w C:\Program Files\eMule
2007-07-28 14:42:06 ——– d—–w C:\Program Files\Opera
2007-07-28 13:58:48 ——– d—–w C:\Program Files\FeedReader30
2007-07-28 04:15:21 ——– d—–w C:\DOCUME~1\Mathieu\APPLIC~1\Azureus
2007-07-27 17:46:00 ——– d-s—w C:\Program Files\Xfire
2007-07-24 13:39:12 ——– d—–w C:\Program Files\mIRC
2007-07-19 17:58:24 ——– d—–w C:\Program Files\Last.fm
2007-07-12 20:30:59 3,304 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-07-11 17:04:11 ——– d—–w C:\DOCUME~1\Mathieu\APPLIC~1\DMCache
2007-07-11 17:02:10 ——– d—–w C:\DOCUME~1\Mathieu\APPLIC~1\IDM
2007-07-10 11:44:02 ——– d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-07-08 17:30:15 ——– d—–w C:\Program Files\WhatPulse
2007-07-06 15:49:07 ——– d—–w C:\Program Files\Azureus
2007-07-05 21:33:22 ——– d—–w C:\Program Files\Winamp
2007-07-05 04:21:08 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-05 04:19:46 ——– d—–w C:\Program Files\QuickTime
2007-06-27 02:15:42 ——– d—–w C:\Program Files\WinPcap
2007-06-27 02:14:59 ——– d—–w C:\Program Files\Messenger Plus! Live
2007-06-20 22:05:16 ——– d–h–r C:\DOCUME~1\Mathieu\APPLIC~1\SecuROM
2007-06-20 22:05:14 108,144 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-06-18 11:13:30 438,272 ——w C:\WINDOWS\almgp.exe
2007-06-12 23:01:49 ——– d—–w C:\Program Files\UltraISO
2007-06-12 23:01:49 ——– d—–w C:\Program Files\Common Files\EZB Systems
2007-06-07 16:00:56 ——– d—–w C:\Program Files\MSN Messenger
2007-06-06 00:18:39 ——– d—–w C:\Program Files\XviD
2007-06-05 23:44:44 ——– d—–w C:\Program Files\TechSmith
2007-06-02 17:12:37 ——– d—–w C:\Program Files\Windows Live
2007-05-28 16:38:33 ——– d—–w C:\Program Files\Bandwidth Reporter
2007-05-28 15:09:49 ——– d—–w C:\Program Files\MessengerDiscovery
2007-05-28 14:06:50 ——– d—–w C:\Program Files\Common Files\Skype
2007-05-28 14:05:19 ——– d—–w C:\Program Files\Pamela
2007-05-28 14:05:19 ——– d—–w C:\DOCUME~1\Mathieu\APPLIC~1\Pamela
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-05 07:51:03 729,088 —-a-w C:\WINDOWS\iun6002.exe
2007-05-05 05:04:35 1,523 —-a-w C:\WINDOWS\eReg.dat
2006-06-08 01:19:42 560 —-a-w C:\DOCUME~1\Mathieu\APPLIC~1\ViewerApp.dat
2004-10-05 01:57:41 318,016 —-a-w C:\DOCUME~1\Mathieu\APPLIC~1\GDIPFONTCACHEV1.DAT


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2003-05-15 19:45]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2005-02-01 19:28]
"UltraMon"="C:\Program Files\UltraMon\UltraMon.exe" [2005-05-14 18:23]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 05:50 C:\WINDOWS\LOGI_MWX.EXE]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2006-04-12 00:20]
"OSSelectorReinstall"="C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe" [2006-04-12 15:15]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 05:09 C:\WINDOWS\SOUNDMAN.EXE]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 23:25 C:\WINDOWS\KHALMNPR.Exe]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-16 21:17]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-16 21:13]
"nwiz"="nwiz.exe" [2006-08-11 22:43 C:\WINDOWS\system32\nwiz.exe]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47]
"ALi5289"="C:\Program Files\ULI5289\ALi5289.exe" [2005-03-10 15:56]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"NvMediaCenter"="NvMCTray.dll" [2006-10-20 23:32 C:\WINDOWS\system32\nvmctray.dll]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 15:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-05 00:18]
"Acrobat Assistant 8.0"="G:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46]
"@"="" []
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gestionnaire Antidote.exe"="C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe" [2006-12-06 17:43]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2004-12-05 06:20]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-07-02 17:10]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 17:22]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:07]
"MessengerPlus3"="C:\Program Files\Messenger Plus! 3\MsgPlus.exe" [2006-06-20 21:33]

C:\Documents and Settings\Mathieu\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-02-13 17:28:33]
Xfire.lnk - C:\Program Files\Xfire\Xfire.exe [2007-07-10 21:07:46]
Y'z ToolBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-09-29 09:41:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-02-13 17:28:33]
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2007-06-28 11:29:41]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-10-13 17:22:24]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"= c:\Program Files\InterMute\SpySubtract\sshook.dll [2005-02-06 15:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2005-07-11 23:26 73728 C:\WINDOWS\system32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=C:\WINDOWS\pss\Picture Package Menu.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=C:\WINDOWS\pss\Picture Package VCD Maker.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^wbsched.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\wbsched.lnk
backup=C:\WINDOWS\pss\wbsched.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mathieu^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Mathieu\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mathieu^Start Menu^Programs^Startup^SAM.lnk]
path=C:\Documents and Settings\Mathieu\Start Menu\Programs\Startup\SAM.lnk
backup=C:\WINDOWS\pss\SAM.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mathieu^Start Menu^Programs^Startup^SmartCapture.lnk]
path=C:\Documents and Settings\Mathieu\Start Menu\Programs\Startup\SmartCapture.lnk
backup=C:\WINDOWS\pss\SmartCapture.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mathieu^Start Menu^Programs^Startup^UberIcon.lnk]
path=C:\Documents and Settings\Mathieu\Start Menu\Programs\Startup\UberIcon.lnk
backup=C:\WINDOWS\pss\UberIcon.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mathieu^Start Menu^Programs^Startup^Y'z Shadow.lnk]
path=C:\Documents and Settings\Mathieu\Start Menu\Programs\Startup\Y'z Shadow.lnk
backup=C:\WINDOWS\pss\Y'z Shadow.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcctMgr]
C:\Program Files\Norton Password Manager\AcctMgr.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
"C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Blaxx Manager]
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileZilla Server Interface]
"C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ]
"C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
"C:\Program Files\Microsoft IntelliPoint\point32.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
Logi_MwX.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerDiscovery]
C:\Program Files\MessengerDiscovery\msgdiscoveryx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
"C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\System32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrevxHome]
C:\Program Files\PREVX\Prevx Home\SAGUI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"g:\program files\steam\steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iFtpSvc"=2 (0x2)
"x10nets"=3 (0x3)
"WinbackupScheduler"=2 (0x2)
"vsmon"=3 (0x3)
"rpcapd"=3 (0x3)
"MySQL"=2 (0x2)
"mi-raysat_3dsmax8"=2 (0x2)
"IDriverT"=3 (0x3)
"FileZilla Server"=3 (0x3)
"ezProxy"=3 (0x3)
"PrevxAgent"=2 (0x2)

R0 KmxNdis;KmxNdis;C:\WINDOWS\system32\DRIVERS\kmxndis.sys
R0 m5228;m5228;C:\WINDOWS\system32\DRIVERS\m5228.sys
R0 m5281;m5281;C:\WINDOWS\system32\DRIVERS\m5281.sys
R0 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 speedfan;speedfan;C:\WINDOWS\system32\speedfan.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R0 TPkd;TPkd;C:\WINDOWS\system32\drivers\TPkd.sys
R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys
R1 AFD;AFD Networking Support Environment;C:\WINDOWS\system32\drivers\afd.sys
R1 AmdK8;AMD Processor Driver;C:\WINDOWS\system32\DRIVERS\AmdK8.sys
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;C:\WINDOWS\system32\DRIVERS\AvgArCln.sys
R1 cdrbsdrv;cdrbsdrv;C:\WINDOWS\system32\drivers\cdrbsdrv.sys
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys
R1 KmxIds;KmxIds;C:\WINDOWS\system32\DRIVERS\kmxids.sys
R1 mbmiodrvr;mbmiodrvr;\??\C:\WINDOWS\System32\mbmiodrvr.sys
R1 mnmdd;mnmdd;C:\WINDOWS\system32\drivers\mnmdd.sys
R1 NetworkX;NetworkX;C:\WINDOWS\system32\ckldrv.sys
R1 Npfs;Npfs;C:\WINDOWS\system32\drivers\Npfs.sys
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment;C:\WINDOWS\system32\drivers\ws2ifsl.sys
R2 aslm75;aslm75;\??\C:\WINDOWS\system32\drivers\aslm75.sys
R2 BCMNTIO;BCMNTIO;\??\C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys
R2 Hardlock;Hardlock;\??\C:\WINDOWS\system32\drivers\hardlock.sys
R2 Haspnt;Haspnt;\??\C:\WINDOWS\system32\drivers\Haspnt.sys
R2 KmxBiG;KmxBiG;C:\WINDOWS\system32\DRIVERS\KmxBiG.sys
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys
R2 lanmanserver;Server;C:\WINDOWS\system32\svchost.exe -k netsvcs
R2 lanmanworkstation;Workstation;C:\WINDOWS\system32\svchost.exe -k netsvcs
R2 MAPMEM;MAPMEM;\??\C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys
R2 maya70docserver;Maya 7.0 Documentation Server;"C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf"
R2 SamVirtualCable;SAM Virtual Cable;C:\WINDOWS\system32\Drivers\samvckmd.sys
R2 Sentinel;Sentinel;C:\WINDOWS\system32\Drivers\SENTINEL.SYS
R2 SVNService;SVNService;C:\Program Files\Subversion\bin\svnservice.exe
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
R2 UltraMonUtility;UltraMon Utility Driver;\??\C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys
R2 UmxAgent;FW Event Manager;"C:\Program Files\Tiny Firewall Pro\UmxAgent.exe"
R2 UmxCfg;FW Configuration Interpreter;"C:\Program Files\Common Files\PFShared\UmxCfg.exe"
R2 UmxLU;FW Live Update;"C:\Program Files\Common Files\PFShared\umxlu.exe"
R2 UmxPol;FW Policy Manager;"C:\Program Files\Common Files\PFShared\UmxPol.exe"
R2 WinDriver;WinDriver;C:\WINDOWS\system32\drivers\WINDRVR.SYS
R2 winmgmt;Windows Management Instrumentation;C:\WINDOWS\system32\svchost.exe -k netsvcs
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys
R3 LHidKe;Logitech SetPoint HID Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\LHidKE.Sys
R3 LMouKE;Logitech SetPoint Mouse Filter Driver;C:\WINDOWS\system32\Drivers\LMouKE.sys
R3 Pcouffin;Low level access layer for CD devices;C:\WINDOWS\system32\Drivers\Pcouffin.sys
R3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys
R3 wdmaud;Microsoft WINMM WDM Audio Compatibility Driver;C:\WINDOWS\system32\drivers\wdmaud.sys
S0 PREVXDriver;Prevx Driver;C:\WINDOWS\system32\drivers\pxfsf.sys
S2 DS1410D;DS1410D;C:\WINDOWS\system32\drivers\DS1410D.SYS
S3 ASUSHWIO;ASUSHWIO;\??\C:\WINDOWS\System32\drivers\ASUSHWIO.sys
S3 ATI Remote Wonder II;ATI Remote Wonder II;C:\WINDOWS\system32\drivers\ATIRWVD.SYS
S3 ATIAVAIW;ATI T200 Unified AVStream service;C:\WINDOWS\system32\DRIVERS\atinavt2.sys
S3 atinevxx;ATI WDM Rage Theater Video NSP;C:\WINDOWS\system32\DRIVERS\atinevxx.sys
S3 atinrvxx;ATI WDM Rage Theater Video;C:\WINDOWS\system32\DRIVERS\atinrvxx.sys
S3 ATITUNEP;ATI WDM TV Tuner;C:\WINDOWS\system32\DRIVERS\atineuxx.sys
S3 ativraxx;ATI WDM Rage Theater Audio;C:\WINDOWS\system32\DRIVERS\atinraxx.sys
S3 ATIXSAudio;ATI WDM TV Audio Crossbar;C:\WINDOWS\system32\DRIVERS\atinesxx.sys
S3 DC280USB;Kodak DC280 USB Driver;C:\WINDOWS\system32\DRIVERS\DC280u.sys
S3 dtscsi;dtscsi;C:\WINDOWS\system32\Drivers\dtscsi.sys
S3 Icam4USB;Intel PC Camera Pro;C:\WINDOWS\system32\Drivers\Icam4USB.sys
S3 L8042mou;Logitech SetPoint PS/2 Mouse Filter Driver;C:\WINDOWS\system32\Drivers\L8042mou.sys
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service;"C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe"
S3 mnmsrvc;NetMeeting Remote Desktop Sharing;C:\WINDOWS\System32\mnmsrvc.exe
S3 MPE;BDA MPE Filter;C:\WINDOWS\system32\DRIVERS\MPE.sys
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver;C:\WINDOWS\system32\drivers\msmpu401.sys
S3 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR;C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe -sSONY_MEDIAMGR
S3 MVDCODEC;ATI WDM Specialized MVD Codec;C:\WINDOWS\system32\DRIVERS\atinmdxx.sys
S3 nm;Network Monitor Driver;C:\WINDOWS\system32\DRIVERS\NMnt.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S3 nvax;Service for NVIDIA® nForce™ Audio Enumerator;C:\WINDOWS\system32\drivers\nvax.sys
S3 NVENET;NVIDIA nForce Networking Controller Driver;C:\WINDOWS\system32\DRIVERS\NVENET.sys
S3 nvnforce;Service for NVIDIA® nForce™ Audio;C:\WINDOWS\system32\drivers\nvapu.sys
S3 odserv;Microsoft Office Diagnostics Service;"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
S3 PCDCODEC;ATI WDM Specialized PCD Codec;C:\WINDOWS\system32\DRIVERS\atinpdxx.sys
S3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
S3 Sntnlusb;Rainbow USB SuperPro;C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR;C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE -i SONY_MEDIAMGR
S3 StillCam;Still Serial Digital Camera Driver;C:\WINDOWS\system32\DRIVERS\serscan.sys
S3 vaxscsi;vaxscsi;C:\WINDOWS\system32\Drivers\vaxscsi.sys
S3 wampapache;wampapache;"G:\wamp\apache2\bin\Apache.exe" -k runservice
S3 wampmysqld;wampmysqld;G:\wamp\mysql\bin\mysqld-nt.exe –defaults-file=G:\wamp\mysql\my.ini wampmysqld
S4 ezProxy;ezProxy;C:\Program Files\LavaSoft\ezProxy\ezEngine.exe -r

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Usnsvc usnsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\SETUP.EXE


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-28 16:09:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\\x00d01\xe8w\xff\xff\xff\xff;_\xe7w4\xb2\xd4w\2]
"91A14B995DF7C0B42ABAA16065968F3A"="C:\Program Files\Alias\Maya7.0\presets\Ashli\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\002109030000000000000000F01FEC\Usage]
"GrooveFiles"=dword:36fc0274
"ProductFiles"=dword:36fc06da
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\002109AB0090400000000000F01FEC\Usage]
"GrooveFilesIntl_1033"=dword:36fc0274
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA330100007706000000000030\Usage]
"AcrobatElements"=dword:36fc0009
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\WU]
"FlushCacheFiles"=str(7):"\x6264\2\xc8f8\f\\b\\xffd8\xffff\x686c\3\xb320\x35a\x5dda\x78e8\x2fb\xc877\1\x7a58\x2fb\xce8\x7a58\x2fb\xce8\xffa8\xffff\x6b6e \xeef0\xaf4a\x9dba\x1c7\\x6e20\x2fb\2\\xc9e8\x39f\xffff\xffff\\xffff\xffff\x3bb0\xffff\xffffH\\\\\b\x6553\x7672\x6369\x7365\xffd8\xffff\x6b76\v@\x7770\x2fb\1\1\x2f3\x6944\x7073\x616c\x4979\x6f63\xff6e\xffff\xffff\xffd8\xffff\x6b76\16\4\x80002\1\1\x6944\x7073\x616c\x5679\x7265\x6973\x6e6f\xffe8\xffffM928366\011\xfff0\xffff\xa5b0\x395\xa710\x395\\xffc0\xffff\x686c\6\x7020\x2fb\xbe58\x1b4\x7358\x2fb\x4bfb\x6eb4\x7408\x2fb\xb17d\x576d\x7638\x2fb\xc2c2\xddf2\x7c90\x2fb\xf730\x227a\x7e18\x2fb\xb881\x97c\\\xff88\xffff\x6b6e \x89cc\xa80f\x54fd\x1c6\\x7c90\x2fb\\\xffff\xffff\xffff\xffff\1\x7a40\x2fb\x3bb0\xffff\xffff\\ \26\$\x3937\x3137\x3966\x3831\x612d\x3438\x2d37\x3434\x3033\x392d\x3732\x2d39\x6134\x3235\x3164\x6665\x3165\x6438\\xffa8\xffff\x6b6e \x9ad4\xd7c4\x9dba\x1c7\\x6e20\x2fb\1\\xbe58\x39f\xffff\xffff\\xffff\xffff\x3bb0\xffff\xffff\34\\\er\5\x6553\x7574ps\xffa8\xffff\x6b6e \xd4aa\x579e\xe1c7\x1c6\\xa0d0\x245\\\xffff\xffff\xffff\xffff\x86\xbd60\x2fb\x3bb0\xffff\xffff\\\30\xa4\M\4\x6548\x706cso\xffd8\xffff\x6b76\vX\x7ef0\x2fb\1\1\xc001\x6c68\x3970\x6535\x2e6e\x6c64l\x223\xffa0\xffffC:\Program Files\Microsoft Office\OFFICE11\\\x1000\xfff8\xffff\x8a88\x2fb\xffd8\xffff\x6b76\n<\x7f80\x2fb\1\1o\x6572\x6461\x656d\x682e\x706ceSA\xffc0\xffffC:\Program Files\DevStudio\VB\xffd8\xffff\x6b76\n<\x8020\x2fb\1\1\x4f0\x6572\x6461\x656d\x632e\x746e\x4f0\xf627\x4f0\xffe8\xffff9.00.2980\x6268\x6e69\x8000\x2fb\x1000\\\\\\xffc0\xffffC:\Program Files\DevStudio\VB\xffd8\xffff\x6b76\t \x8088\x2fb\1\1\x6164\x336f\x2e35\x6e63t\\xff90\xffffC:\WINDOWS\Help\Common Files\Microsoft Shared\DAO\\\xffd8\xffff\x6b76\t \x8120\x2fb\1\1\x6164\x336f\x2e35\x6c68p\\xff90\xffffC:\WINDOWS\Help\Common Files\Microsoft Shared\DAO\\\xffe0\xffff\x6b76\aF\x81b0\x2fb\1\1\xe16b\x7263\x2e77\x6c68\xe270\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xe2e2\x52f1\xe232\xffe0\xffff\x6b76\aF\x8c00\x2fb\1\1\x6276\x2e35\x6e63t\xffd8\xffff\x6b76\v(\x8248\x2fb\1\1\x646f\x6362\x656a\x2e74\x6e63t\\xffd0\xffffC:\WINDOWS\System32\\xffd8\xffff\x6b76\v(\x82a0\x2fb\1\1\xd6\x646f\x6362\x656a\x2e74\x6c68p\x7c80\xd6\xffd0\xffffC:\WINDOWS\System32\x5f80\xd8\xffd8\xffff\x6b76\f(\x83d8\x2fb\1\1\x128\x646f\x6362\x6e69\x7473\x632e\x746e\x2e18\x128\xffd8\xffff\x6b76\f(\x8320\x2fb\1\1\x128\x646f\x6362\x746a\x776e\x632e\x746e\x2e18\x128\xffd0\xffffC:\WINDOWS\System32\\xffd8\xffff\x6b76\f(\x8378\x2fb\1\1\xd6\x646f\x6362\x746a\x776e\x682e\x706c\x7c80\xd6\xffd0\xffffC:\WINDOWS\System32\x5f80\xd8\xffd8\xffff\x6b76\tF\x8498\x2fb\1\1\x6572\x7670\x2e62\x6c68p\\b\x7c50\x2fb\xffd0\xffffC:\WINDOWS\System32\\xffd8\xffff\x6b76\f(\x8430\x2fb\1\1\xd6\x646f\x6362\x6e69\x7473\x682e\x706c\x7c80\xd6\xffd0\xffffC:\WINDOWS\System32\x5f80\xd8\xffd8\xffff\x6b76\fF\x85a0\x2fb\1\1\x6552\x6f70\x7473\x7972\x682e\x706c\\xfff0\xffff\\x6f6e\x656e\\xffb0\xffffC:\Program Files\DevStudio\VB\help\\\xffd8\xffff\x6b76\tF\x8510\x2fb\1\1\xd6\x6572\x7670\x2e62\x6e63\x7b74\xd6\x7c80\xd6\xffb0\xffffC:\Program Files\DevStudio\VB\help\x128\x9fa8\x128\xffd8\xffff\x6b76\n \x86b0\x2fb\1\1\x6276\x6435\x6665\x682e\x706c\\xffe8\xffff\x686c\2\xed98\x2fb\x2cf5\1\xeeb0\x2fb\x37a7\1\xffb0\xffffC:\Program Files\DevStudio\VB\help\\\xffd8\xffff\x6b76\fF\x8618\x2fb\1\1\xd6\x6552\x6f70\x7473\x7972\x632e\x746e\x7c80\xd6\xffb0\xffffC:\Program Files\DevStudio\VB\help\x128\x9fa8\x128\xffd8\xffff\x6b76\fF\x8778\x2fb\1\1\x127\x6164\x6174\x6f66\x6d72\x632e\x746e\x9fa8\x128\xffe0\xffff\x6b76\aF\x8b40\x2fb\1\1\x129\x6276\x2e35\x6c68\x170\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\v \x8700\x2fb\1\1\xd6\x6576\x7266\x6664\x2e33\x6c68p\x7c80\xd6\xffd8\xffffC:\WINDOWS\help\xef90\x11a\xffd8\xffff\x6b76\fF\x8898\x2fb\1\1\x127\x656a\x6474\x6665\x3533\x682e\x706c\x9fa8\x128\xffd8\xffff\x6b76\fF\x88e8\x2fb\1\1\x128\x656a\x6574\x7272\x3533\x632e\x746e\xd970\x128\xffb0\xffffC:\Program Files\DevStudio\VB\Help\\\xffd8\xffff\x6b76\fF\x87f0\x2fb\1\1\x128\x6164\x6174\x6f66\x6d72\x682e\x706c\xd970\x128\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd8\xef90\x11a\xffd8\xffff\x6b76\fF\x8998\x2fb\1\1\x127\x656a\x6574\x7272\x3533\x682e\x706c\x9fa8\x128\xffd8\xffff\x6b76\fF\x89e8\x2fb\1\1\x128\x656a\x7374\x6c71\x3533\x632e\x746e\xd970\x128\xfff8\xffff\xaf80\x2fb\xffb0\xffffC:\Program Files\DevStudio\VB\Help\\\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd8\xef90\x11a\xffd8\xffff\x6b76\fF\x8aa0\x2fb\1\1\x127\x656a\x7374\x6c71\x3533\x682e\x706c\x9fa8\x128\xffd8\xffff\x6b76\vF\x8af0\x2fb\1\1\x128\x6862\x6c65\x3370\x2e32\x6e63\x174\xd970\x128\xfff0\xffff\\x6f6e\x656e\\xffb0\xffffC:\Program Files\DevStudio\VB\Help\\\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd8\xef90\x11a\xffd8\xffff\x6b76\vF\x8bb0\x2fb\1\1\x127\x6862\x6c65\x3370\x2e32\x6c68\x170\x9fa8\x128\xffd8\xffff\x6b76\vF\x8cc8\x2fb\1\1\x129\x6276\x6e65\x726c\x2e33\x6e63\x174\x70e8\x129\xffe8\xffff\x6b76\00\xefc8\x2fb\1\000\xffb0\xffffC:\Program Files\DevStudio\VB\Help\\\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd8\xef90\x11a\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\xd970\x128\xffe0\xffff\x6b76\b \x9c00\x2fb\1\1\x6e69\x7465\x632e\x746e\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\x70e8\x129\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd8\xef90\x11a\xffd8\xffff\x6b76\vF\x8c78\x2fb\1\1\x11a\x6276\x6e65\x726c\x2e33\x6c68\x170\x2ce8\x128\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\x6fb8\x129\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd6\x8088\xd6\xffd8\xffff\x6b76\nF\x8d40\x2fb\1\1\x128\x6276\x6535\x7478\x682e\x706c\x128\xd720\x128\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\x6fe0\x129\b\x8c50\x2fb\xffd8\xffff\x6b76\nF\x8dc0\x2fb\1\1\x129\x6276\x6535\x7478\x632e\x746e\xd6\x78b8\xd6\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd8\xf100\x11a\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\x7530\x129\xffd8\xffff\x6b76\vL\x9020\x2fb\1\1\xd6\x6173\x706d\x656c\x2e73\x6c68p\x7c80\xd6\xfff0\xffff\\x6f6e\x656e\\xffd8\xffff\x6b76\nF\x8ec0\x2fb\1\1\xd6\x6276\x7035\x7373\x632e\x746e\xd6\x7b48\xd6\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x127\x2ce8\x128\xffb0\xffffC:\Program Files\DevStudio\VB\samples\xffd8\xffff\x6b76\nh\x9108\x2fb\1\1\xd6\x6962\x6c62\x6f69\x682e\x706c\xd6\x7c80\xd6\xffe8\xffff\xf258\x2fb\xf288\x2fb\xf2b8\x2fb\xf320\x2fb\xf348\x2fb\xffd8\xffff\x6b76\nF\x8e10\x2fb\1\1\x128\x6276\x7035\x7373\x682e\x706c\x128\xd8b0\x128\xffd8\xffff\x6b76\vL\x8f10\x2fb\1\1\x128\x6173\x706d\x656c\x2e73\x6e63\x174\xd970\x128\xfff0\xffff\\x6f6e\x656e\\x6268\x6e69\x9000\x2fb\x1000\\\\\\xffb0\xffffC:\Program Files\DevStudio\VB\samples\xffd8\xffff\x6b76\fN\x9098\x2fb\1\1\x458b\x6276\x6e6f\x696c\x656e\x682e\x706c\x8bf0\xf44d\xffa8\xffffC:\Program Files\DevStudio\VB\vbonline\x68ff\x14c0\x109\xffe8\xffff\x686c\2\xf9b8\x2fb\xecfe\x8db\xfa20\x2fb\xb972\xe828\xff90\xffffC:\Program Files\DevStudio\VB\samples\PGuide\Biblio\xd8b0\x128\xffd8\xffff\x6b76\fF\x91a0\x2fb\1\1U\x6573\x7574\x7770\x7a69\x682e\x706cbo\xffb0\xffffC:\Program Files\DevStudio\VB\help\04\x3350\xffd8\xffff\x6b76\fF\x9340\x2fb\1\1\xd6\x6573\x7574\x7770\x7a69\x632e\x746e\x7c80\xd6\xffd8\xffff\x6b76\fN\x9240\x2fb\1\1\x6276\x6e6f\x696c\x656e\x632e\x746e\xffff\xe8ff\xffa8\xffffC:\Program Files\DevStudio\VB\vbonline\x8908\xc51\x8e8b\xffd8\xffff\x6b76\fF\x92c0\x2fb\1\1\x6977\x647a\x6e6d\x7267\x632e\x746e\\xffb0\xffffC:\Program Files\DevStudio\VB\help\\\xffd8\xffff\x6b76\fF\x9440\x2fb\1\1\xd6\x6977\x647a\x6e6d\x7267\x682e\x706c\x7c80\xd6\b\x9178\x2fb\xffb0\xffffC:\Program Files\DevStudio\VB\help\x128\x9fa8\x128\xffd8\xffff\x6b76\vF\x93b8\x2fb\1\1\x128\x7061\x7770\x727a\x2e64\x6e63\x174\xd970\x128\xffb0\xffffC:\Program Files\DevStudio\VB\help\x129\x7620\x129\xffd8\xffff\x6b76\vF\x9548\x2fb\1\1\x129\x7061\x7770\x727a\x2e64\x6c68\x170\xb2d0\x129\xfff0\xffff\\x4441\x4542\\xffb0\xffffC:\Program Files\DevStudio\VB\help\x128\x9fa8\x128\xffd8\xffff\x6b76\vF\x94b8\x2fb\1\1\x6c63\x7773\x727a\x2e64\x6e63t\\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\xd970\x128\xffd8\xffff\x6b76\vF\x9658\x2fb\1\1\x129\x6c63\x7773\x727a\x2e64\x6c68\x170\x70e8\x129\xffe8\xffff\x686c\2\xf960\x2fb\xc5da\1\xfac8\x2fb\xc4f\xffb0\xffffC:\Program Files\DevStudio\VB\help\xd8\xef90\x11a\xffd8\xffff\x6b76\fF\x95c0\x2fb\1\1\xd6\x7266\x646d\x636f\x7a77\x632e\x746e\x7b48\xd6\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x127\x2ce8\x128\xffd8\xffff\x6b76\fF\x9770\x2fb\1\1\x128\x7266\x646d\x636f\x7a77\x682e\x706c\xd8b0\x128\xffe0\xffff\x6b76\b \x9c28\x2fb\1\1\x6e69\x7465\x682e\x706c\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\xb2d0\x129\xffd8\xffff\x6b76\fF\x96d0\x2fb\1\1\x129\x7463\x636c\x7772\x647a\x632e\x746e\x7a68\x129\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd8\xef90\x11a\xffd8\xffff\x6b76\fF\x9890\x2fb\1\1\x127\x7463\x636c\x7772\x647a\x682e\x706c\x9fa8\x128\xffd8\xffff\x6b76\fF\x97c0\x2fb\1\1\x129\x7270\x706f\x6770\x7a77\x632e\x746e\x7620\x129\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\x7530\x129\xffb0\xffffC:\Program Files\DevStudio\VB\Help\xd6\x78b8\xd6\xffd8\xffff\x6b76\fF\x9838\x2fb\1\1\xd6\x7270\x706f\x6770\x7a77\x682e\x706c\x7dc0\xd6\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x128\xd720\x128\b\x96a8\x2fb\xffb0\xffffC:\Program Files\DevStudio\VB\Help\x129\x70e8\x129\xffd8\xffff\x6b76\v \x9908\x2fb\1\1\x82f7\x736d\x6174\x3962\x2e36\x6e63\x8274\x24d8\x82f7\xffd8\xffffC:\WINDOWS\Help\x24d8\x82f7\xffd8\xffff\x6b76\v \x9958\x2fb\1\1\xd6\x736d\x6174\x3962\x2e36\x6c68p\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\xffd8\xffff\x6b76\f \x99a8\x2fb\1\1\x736d\x6c66\x6778\x6472\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \x99f8\x2fb\1\1\xd6\x736d\x6c66\x6778\x6472\x682e\x706c\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\xffd8\xffff\x6b76\f \x9a48\x2fb\1\1\x6264\x696c\x7473\x3639\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \x9a98\x2fb\1\1\xd6\x6264\x696c\x7473\x3639\x682e\x706c\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\xffd8\xffff\x6b76\f \x9ae8\x2fb\1\1\x6264\x7267\x6469\x3639\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \x9b38\x2fb\1\1\xd6\x6264\x7267\x6469\x3639\x682e\x706c\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\xffd8\xffff\x6b76\v \x9b88\x2fb\1\1\x6f63\x636d\x6c74\x2e32\x6e63t\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\v \x9bd8\x2fb\1\1\xd6\x6f63\x636d\x6c74\x2e32\x6c68p\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffffC:\WINDOWS\Help\\xfff0\xffff\1\x5045\x4f53\x3045\x3632\xffd8\xffff\x6b76\v \x9c88\x2fb\1\1\x6276\x6d63\x396e\x2e36\x6c68p\xff\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\v \x9cd8\x2fb\1\1\xd6\x6276\x6d63\x396e\x2e36\x6e63t\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\xffd8\xffff\x6b76\f \x9d28\x2fb\1\1\x7472\x6266\x786f\x3639\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \x9d78\x2fb\1\1\xd6\x7472\x6266\x786f\x3639\x682e\x706c\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\xffd8\xffff\x6b76\n \x9dc8\x2fb\1\1\x616d\x6970\x3639\x632e\x746e\\xff00\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\n \x9e18\x2fb\1\1\x616d\x6970\x3639\x682e\x706c\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \x9e68\x2fb\1\1\x6d6d\x6465\x6169\x3639\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \xa020\x2fb\1\1\x6d6d\x6465\x6169\x3639\x682e\x706c\\b\x9ec0\x2fb\xffd8\xffff\x6b76\f \x9ee8\x2fb\1\1\x736d\x6863\x7472\x3639\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \x9f38\x2fb\1\1\xd6\x736d\x6863\x7472\x3639\x682e\x706c\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\xffd8\xffff\x6b76\f \x9f88\x2fb\1\1\x736d\x6977\x736e\x6b63\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \x9fd8\x2fb\1\1\xd6\x736d\x6977\x736e\x6b63\x682e\x706c\x7c80\xd6\xffd8\xffffC:\WINDOWS\Help\xef90\x11a\x6268\x6e69\xa000\x2fb\x1000\\\\\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\v \xa070\x2fb\1\1\x7973\x6973\x666e\x2e6f\x6e63t\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\v \xa0c0\x2fb\1\1\x7973\x6973\x666e\x2e6f\x6c68p\\xff78\xffffC:\WINDOWS\Help\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\n \xa228\x2fb\1\1\x6f63\x6d6d\x3639\x632e\x746e\\xffe8\xffffmapi.dll\xa9c1\xffd8\xffff\x6b76\f \xa1b0\x2fb\1\1\x6970\x6363\x706c\x3639\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \xa200\x2fb\1\1\x6970\x6363\x706c\x3639\x682e\x706c\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\n \xa278\x2fb\1\1\x6f63\x6d6d\x3639\x682e\x706c\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \xa2c8\x2fb\1\1\xff\x616d\x6b73\x6465\x3639\x632e\x746e\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\f \xa318\x2fb\1\1\x616d\x6b73\x6465\x3639\x682e\x706c\\xffd8\xffffC:\WINDOWS\Help\\xffd8\xffff\x6b76\vz\xa368\x2fb\1\1\x7865\x6874\x6c65\x2e70\x6c68p\\xff80\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Help\\xffd8\xffff\x6b76\tz\xa410\x2fb\1\1\x736d\x6564\x2e76\x6c68p\\xff80\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Help\\xfff0\xffff\xac88\x3fb\xad28\x3fb\\xffd8\xffff\x6b76\n~\xa4c8\x2fb\1\1\x6173\x706d\x656c\x642e\x6d73\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Macros\\\xffd8\xffff\x6b76\vz\xa578\x2fb\1\1\x7865\x6874\x6c65\x2e70\x6e63t\\xff80\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Help\\xffd8\xffff\x6b76\v\x80\xa620\x2fb\1\1\xe187\x6163\x7577\x6974\x2e6c\x6c68\xe270\x7669\xe12c\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\x7e41\xe270\xffd8\xffff\x6b76\f\x80\xa6d0\x2fb\1\1\xe20d\x6c63\x7069\x7361\x7473\x682e\x706c\xe359\xe230\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\x1319\xe19a\xffe0\xffff\x6b76\b\x80\xa778\x2fb\1\1\xe2df\x7463\x7069\x682e\x706c\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\x5af1\xe178\xffd8\xffff\x6b76\n\x80\xa828\x2fb\1\1\xe176\x6c64\x6267\x7261\x682e\x706c\xe2a5\x22f9\xe215\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\x8519\xe2d8\xffd8\xffff\x6b76\n\x80\xa8d8\x2fb\1\1\xd6\x6f64\x7263\x6765\x682e\x706c\xd6\x7c80\xd6\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\x6cc0\x129\xffd8\xffff\x6b76\v\x80\xa988\x2fb\1\1\x129\x7567\x6469\x6567\x2e6e\x6c68\x170\x6fe0\x129\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\x1bc8\x12b\xffe0\xffff\x6b76\b\x80\xaa30\x2fb\1\1\x12b\x6469\x656c\x682e\x706c\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\f\x80\xaae0\x2fb\1\1\x616d\x6970\x6f63\x706d\x682e\x706c\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\xf7d9\xe271\xffd8\xffff\x6b76\t\x80\xab90\x2fb\1\1\x74c0\x656d\x6964\x2e61\x6c68p\xffff\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\x20e9\xe243\xffe0\xffff\x6b76\a\x80\xac38\x2fb\1\1\xe285\x636f\x2e63\x6c68\xe170\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\v\x80\xace8\x2fb\1\1\xe271\x776f\x646e\x6172\x2e77\x6c68\xe270\xe859\xe16d\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\v\x80\xad98\x2fb\1\1\x6f73\x6b63\x7465\x2e73\x6c68p\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\n\x80\xae48\x2fb\1\1\x7073\x616c\x6873\x682e\x706c\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\f\x80\xaef8\x2fb\1\1\x7073\x696c\x7474\x7265\x682e\x706c\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffe8\xffff\x6b76\24\xc710\x2fb\1\\xbbb6\xffd8\xffff\x6b76\v\x80\xb020\x2fb\1\1\xe192\x6170\x656c\x7474\x2e65\x6c68\xe270\x1401\xe166\xffd8\xffff\x6b76\t\x80\xb0a8\x2fb\1\1\x6f70\x7570\x2e70\x6c68p\\xffe8\xffffSYSTEM\1\x3aa8\1\x6268\x6e69\xb000\x2fb\x1000\\\\\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\v\x80\xb158\x2fb\1\1\x7270\x676f\x6c64\x2e67\x6c68p\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\v\x80\xb208\x2fb\1\1\x7270\x706f\x6873\x2e74\x6c68p\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffd8\xffff\x6b76\f\x80\xb2b8\x2fb\1\1S\x6f74\x6c6f\x6974\x7370\x682e\x706c\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xffe0\xffff\x6b76\6d\xb360\x2fb\1\1\x636d\x682e\x706c\xff98\xffffC:\Program Files\Microsoft Visual Studio\VC98\Bin\xffe0\xffff\x6b76\al\xb3e8\x2fb\1\1\x6368\x2e77\x6e63t\xff90\xffffC:\Program Files\Microsoft Visual Studio\Common\Tools\xffe0\xffff\x6b76\al\xb7c0\x2fb\1\1\x6368\x2e77\x6c68p\xffe0\xffff\x6b76\bl\xb578\x2fb\1\1\x6873\x6465\x682e\x706c\xffe0\xffff\x6b76\6x\xb5e8\x2fb\1\1\x6372\x682e\x706c\xfff0\xffff\x686c\1\xe488\x2fb\xc2ff\x7b1\xffd8\xffff\x6b76\v\x80\xb4f0\x2fb\1\1\x7473\x7461\x6162\x2e72\x6c68p\\xff78\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\\xff90\xffffC:\Program Files\Microsoft Visual Studio\Common\Tools\xff80\xffffC:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\\xffd8\xffff\x6b76\f\x80\xb690\x2fb\1\1\xffff\x6e73\x7061\x6976\x7765\x682e\x706c\xffff\xffff\xff78\xffffC:\Program Files\Common Files\Microsoft Shared\Snapshot Viewer\\x9aa1\x1c4\xffd8\xffff\x6b76\fr\xb740\x2fb\1\1d\x5145\x454e\x5444\x3233\x632e\x746eol\xff88\xffffC:\Program Files\Common Files\Microsoft Shared\EQUATION\\\xfff8\xffff\xc750\x2fb\xff90\xffffC:\Program Files\Microsoft Visual Studio\Common\Tools\xffd8\xffff\x6b76\fr\xb858\x2fb\1\1\x28d5\x5145\x454e\x5444\x3233\x682e\x706c\x2710\x28d5\xff88\xffffC:\Program Files\Common Files\Microsoft Shared\EQUATION\l\xffd8\xffff\x6b76\f\2\x8000\\1\1\x776e\x6e69\x6364\x3973\x632e\x746e\\xff98\xffff\x6b6e \x3704\x57a1\xe1c7\x1c6\\x7bd0\x331\\\xffff\xffff\xffff\xffff\1\xb960\x2fb\x3bb0\xffff\xffff\\\\2OF\21\x6f64\x6e77\x656c\x6576\x5f6c\x6170\x6c79\x616fdLES\xfff8\xffff\xb990\x2fb\xffd8\xffff\x6b76\n\2\x8000\\1\1\x776e\x6e69\x3964\x682e\x706c\\xffe8\xffff\x6b76\2\x8000\\1\m\xffe8\xffff\x686c\2\xba28\x2fb\x5422\x1ffe\xb8f8\x2fb\x1201\xcce4\xffe8\xffff\x6b76\2\x8000\\1\\\xffe0\xffff\x6b76\4"\x5f60\x30f\2\1M\x6150\x6874\x7441\x6574\b\xb9d8\x2fb\xffd8\xffff\x6b76\n\2\x8000\\1\1\x776e\x6e69\x3964\x632e\x746e\\xff98\xffff\x6b6e \x3704\x57a1\xe1c7\x1c6\\x7bd0\x331\\\xffff\xffff\xffff\xffff\1\xba90\x2fb\x3bb0\xffff\xffff\\\\2OF\22\x6f64\x6e77\x656c\x6576\x5f6c\x616d\x696e\x6566\x7473LES\xfff8\xffff\xb9c0\x2fb\xff88\xffff\x6b6e \xadb2\x45d4\x28a8\x1c7\\x1f38\xd9\3\\xcd0\x2f0\xffff\xffff\1\xef90\r\x3bb0\xffff\xffff \\\30os&\x307b\x3639\x4443\x3137\x2d41\x3730\x3638\x312d\x4431\x2d31\x3539\x4146\x302d\x3830\x4330\x3837\x4545\x4233\x7d42S\xfff0\xffff2.0\x43fc\xbbb6\xfff8\xffff\xc7e8\x2fb\xffd8\xffff\x6b76\f(\xbb50\x2fb\1\1.\x4950\x544e\x504c\x4441\x482e\x504cre\xffd0\xffffC:\WINDOWS\system32FF\xffd8\xffff\x6b76\f(\xbba8\x2fb\1\012\x4950\x544e\x504c\x4541\x482e\x504c98\xffd0\xffffC:\WINDOWS\system32\016\xffd8\xffff\x6b76\f,\xbc00\x2fb\1\015\x4d49\x5045\x4441\x4e45\x482e\x504cFD\xffd0\xffffC:\WINDOWS\IME\SHARED\xffd8\xffff\x6b76\n:\xbc58\x2fb\1\1\x2fc9\x4d49\x504a\x4c43\x482e\x504c\x21f\x54cd\x9c0\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\xd3af\xffd8\xffff\x6b76\v:\xc020\x2fb\1\1\x2fc9\x4d49\x504a\x4c43\x2e45\x4c48\x250\x54cd\x9c0\xffd8\xffff\x6b76\n:\xc060\x2fb\1\1\x8af1\x4d49\x504a\x4d53\x482e\x504c\x226\xca2\x39b5\xfff8\xffff\xebe0\x2fb\xffa0\xffff\x6b6e \x5af2\x9521\x28b5\x1c7\\x5e58\x30f\\\xffff\xffff\xffff\xffff\2\x4810\xd0\x318\xffff\xffff\\\24\36rF\n\x7250\x706f\x7265\x6974\x7365\x490\xe5\xfff0\xffff\x2ed0\x331\x2fd8\x331\\xfd88\xffff\x7ec8\x2fb\x7f58\x2fb\x7fc0\x2fb\x8060\x2fb\x80f8\x2fb\x8190\x2fb\x8220\x2fb\x8278\x2fb\x82f8\x2fb\x8350\x2fb\x82d0\x2fb\x8408\x2fb\x83a8\x2fb\x84e8\x2fb\x8460\x2fb\x85f0\x2fb\x8560\x2fb\x86d8\x2fb\x8668\x2fb\x87c8\x2fb\x8728\x2fb\x8750\x2fb\x8840\x2fb\x8868\x2fb\x8938\x2fb\x8960\x2fb\x8a38\x2fb\x8200\x2fb\x8690\x2fb\x8a60\x2fb\x8c50\x2fb\x8d98\x2fb\x8d18\x2fb\x8e98\x2fb\x8fa0\x2fb\x8e60\x2fb\x8fc8\x2fb\x8f60\x2fb\x9070\x2fb\x9218\x2fb\x9178\x2fb\x91f0\x2fb\x9298\x2fb\x9310\x2fb\x9390\x2fb\x9408\x2fb\x9490\x2fb\x9508\x2fb\x9598\x2fb\x9610\x2fb\x96a8\x2fb\x9720\x2fb\x9748\x2fb\x9810\x2fb\x98e0\x2fb\x9930\x2fb\x9980\x2fb\x99d0\x2fb\x9a20\x2fb\x9a70\x2fb\x9ac0\x2fb\x9b10\x2fb\x9c60\x2fb\x9cb0\x2fb\x9b60\x2fb\x9bb0\x2fb\x8b90\x2fb\x9638\x2fb\x9d00\x2fb\x9d50\x2fb\x9ec0\x2fb\x9f10\x2fb\x9f60\x2fb\x9fb0\x2fb\x9da0\x2fb\x9df0\x2fb\x9e40\x2fb\x9e90\x2fb\xa188\x2fb\xa1d8\x2fb\xa048\x2fb\xa098\x2fb\xa148\x2fb\xa250\x2fb\xa2a0\x2fb\xa2f0\x2fb\xa4a0\x2fb\xa550\x2fb\xa340\x2fb\xa3e8\x2fb\xa5f8\x2fb\xa6a8\x2fb\xa758\x2fb\xa800\x2fb\xa8b0\x2fb\xa960\x2fb\xaa10\x2fb\xaab8\x2fb\xab68\x2fb\xac18\x2fb\xacc0\x2fb\xaf98\x2fb\xafc0\x2fb\xb130\x2fb\xb1e0\x2fb\xad70\x2fb\xae20\x2fb\xaed0\x2fb\xb4c8\x2fb\xb290\x2fb\xb340\x2fb\xb3c8\x2fb\xb458\x2fb\xb478\x2fb\xb498\x2fb\xb668\x2fb\xb718\x2fb\xb830\x2fb\xb8d0\x2fb\xb968\x2fb\xba00\x2fb\xbfd8\x2fb\xbb28\x2fb\xbb80\x2fb\xbbd8\x2fb\xbc30\x2fb\xbc98\x2fb\xbcc0\x2fb\xc0a0\x2fb\xc108\x2fb\xc170\x2fb\xc1d8\x2fb\xc238\x2fb\xc2a0\x2fb\xc2a0\x2fb\\\\\\\\\\\\\\\\\\\\\\\xffd8\xffff\x6b76\f\2\x8000\\1\1\x776e\x6e69\x6364\x3973\x682e\x706c\\x6268\x6e69\xc000\x2fb\x1000\\\\\\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\xc310\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\x9718\xffd8\xffff\x6b76\v:\xc0c8\x2fb\1\1\xc8e8\x4d49\x504a\x4d53\x2e45\x4c48\x250\xd58a\x76fe\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\x782a\xffd8\xffff\x6b76\n:\xc130\x2fb\1\1\x6d69\x726b\x3136\x682e\x706c\\xffc0\xffffC:\WINDOWS\ime\imkr6_1\help\\\xffd8\xffff\x6b76\f:\xc198\x2fb\1\1\x6d69\x726b\x6e65\x3136\x682e\x706c\\xffc0\xffffC:\WINDOWS\ime\imkr6_1\help\\\xffe0\xffff\x6b76\6:\xc1f8\x2fb\1\1\x6e65\x682e\x706c\xffc0\xffffC:\WINDOWS\ime\Shared\imepad\\xffd8\xffff\x6b76\n<\xc260\x2fb\1\1\x4843\x4154\x5450\x482e\x504c\\xffc0\xffffC:\WINDOWS\IME\CHTIME\APPLETS\xffd8\xffff\x6b76\f<\xc2c8\x2fb\1\1\x4843\x4154\x5450\x4e45\x482e\x504c\\xffc0\xffffC:\WINDOWS\IME\CHTIME\APPLETS\xffa0\xffff\x6b6e \x5e68\x94d6\xa7cb\x1c7\\xa0d0\x245\\\xffff\xffff\xffff\xffff4\xe3b0\x2fb\x3bb0\xffff\xffff\\$\x8e\\t\x5448\x4c4d\x4820\x6c65\xff70\xff\\xffe0\xffff\x6b76\b|\xc388\x2fb\1\1\xffff\x6d66\x3032\x632e\x6d68\xff80\xffffC:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\1033\\xff30\xffffMicrosoft.Office.Interop.InfoPath, Version=12.0.0.0, Culture=neutral, PublicKeyToken=71E9BCE111E9429C\xffa8\xffff{00020424-0000-0000-C000-000000000046}ion\xffa8\xffff\x6b6e \xadb2\x45d4\x28a8\x1c7\\xba98\x2fb\\\xffff\xffff\xffff\xffff\2\x5d28\x29a\x3bb0\xffff\xffff\\\16NyT\a\x7954\x6570\x694cb\xffa8\xffff{FD34A360-115F-43CA-8D6F-BBD45FD6F828}p.I\xff88\xffff\x6b6e \xd4c0\x45db\x28a8\x1c7\\x1f38\xd9\3\\xc728\x2fb\xffff\xffff\1\x8890\x2fb\x3bb0\xffff\xffff \\\24eu&\x307b\x3639\x4443\x3137\x2d38\x3730\x3638\x312d\x4431\x2d31\x3539\x4146\x302d\x3830\x4330\x3837\x4545\x4233\x7d427\xffa0\xffff\x6b6e \x100c\x45d7\x28a8\x1c7\\xc5e0\x2fb\\\xffff\xffff\xffff\xffff\1\xcc8\x2f0\x3bb0\xffff\xffff\\\N\\20\x7250\x786f\x5379\x7574\x4362\x736c\x6469\x3233\xffa8\xffff{00020424-0000-0000-C000-000000000046}\\\xffe8\xffffSignature\xffd8\xffff\x686c\3\x740\x2fc\x2363\x8ea1\xc658\x2fb\x43fc\xbbb6\x508\x2fc\xd71d\xa70f\x7672\x7265\x3233\xffe0\xffff\x6b76\4N\xe4e0\x2fb\1\1\x632e\x6d68\\xffa8\xffff{00020424-0000-0000-C000-000000000046}tur\xffe0\xffff\x6b76\a\b\xbb10\x2fb\1\1t\x6556\x7372\x6f69n\xffe8\xffff\x6b76N\x690\x2fc\1\\x2fb\xffe8\xffff\x6b76N\xada8\x300\1\\xffd8\xffff\x6b76\f\x8e\xc840\x2fb\1\1\xd6\x776f\x7263\x7064\x3031\x632e\x6d68\x87b0\xd6\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\\nHa\xffd8\xffff\x6b76\f\x8e\xcab0\x2fb\1\1\xd6\x776f\x7263\x7373\x3031\x632e\x6d68\x87b0\xd6\xffd8\xffff\x6b76\f\x8e\xc928\x2fb\1\1\xd6\x776f\x7663\x6162\x3031\x632e\x6d68\x8b00\xd6\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\C:\\xffd8\xffff\x6b76\f\x8e\xc9e8\x2fb\1\1\xd6\x776f\x6463\x7373\x3031\x632e\x6d68es\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\urc\xffd8\xffff\x6b76\f\x8e\xcc40\x2fb\1\1\xd6\x776f\x7263\x6863\x3031\x632e\x6d68\x87b0\xd6\xfff8\xffff\xee50\x2fb\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\ck=\xffd8\xffff\x6b76\f\x8e\xcb70\x2fb\1\1\xd6\x776f\x6463\x6863\x3031\x632e\x6d68\x8c48\xd6\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\\0392\xffd8\xffff\x6b76\nb\xcdd8\x2fb\1\1\x7264\x6761\x6e6f\x632e\x6d68\\xfff0\xffff\xa750\x38d\xa7d0\x38d\xa420\x38d\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\ft \xffd8\xffff\x6b76\f\x8e\xcd00\x2fb\1\1\xd6\x776f\x6663\x6e75\x3031\x632e\x6d68\x8c48\xd6\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\ co\xffd8\xffff\x6b76\f\x8e\xcf18\x2fb\1\1\x1cb8\x574f\x5243\x5353\x3131\x432e\x4d48\x4a66\x3858\xffe8\xffffMathieu G\xff98\xffffC:\Program Files\ScanSoft\NaturallySpeaking\Help\\xffd8\xffff\x6b76\fb\xce68\x2fb\1\1\xd6\x6574\x6863\x7573\x7070\x632e\x6d68\x87b0\xd6\xff98\xffffC:\Program Files\ScanSoft\NaturallySpeaking\Help\xd6\xffd8\xffff\x6b76\f\x8e\xd1a0\x2fb\1\1\xd6\x574f\x5243\x4843\x3131\x432e\x4d48\x9278\xd6\xffe0\xffff\x6b76\5\4\x8000\x1618\4\1\x2a2\x6c4f\x6f72\xef78\x2a2\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\x105d\xeb21\xbf7\xffd8\xffff\x6b76\f\x8e\xd020\x2fb\1\1\xd6\x574f\x5643\x4142\x3131\x432e\x4d48\x87b0\xd6\xffd8\xffff\x6b76\f\x8e\xd108\x2fb\1\1\xd6\x574f\x5243\x4c50\x3131\x432e\x4d48\x8c48\xd6\x6268\x6e69\xd000\x2fb\x1000\\\\\\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\x10c7\x81a1\x1c13\xffd8\xffff\x6b76\f\x8e\xd290\x2fb\1\1\xd6\x574f\x4643\x4e55\x3131\x432e\x4d48\xf6c8\x11c\xffd8\xffff\x6b76\f\x8e\xd328\x2fb\1\1\xd6\x574f\x5243\x5044\x3131\x432e\x4d48\x87b0\xd6\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\x233f\x6a41\x21e9\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\xd6\x8138\x118\xffd8\xffff\x6b76\f\x8e\xd420\x2fb\1\1\xd6\x574f\x4443\x4843\x3131\x432e\x4d48\x8c48\xd6\xffd8\xffff\x6b76\f\x8e\xd4b8\x2fb\1\1\xd6\x574f\x4443\x4c50\x3131\x432e\x4d48\x9278\xd6\xfff8\xffff\xd8b0\x2fb\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\x2fe0\x8c81\x2fb1\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\x520\x6887\x520\xffd8\xffff\x6b76\f\x8e\xd5b8\x2fb\1\1\x166\x574f\x4443\x5353\x3131\x432e\x4d48\x69c0\x182\xffe0\xffffCertificate\x6f69\x566e\xfff8\xffff\xc800\x2fb\xfff0\xffff\\x4441\x4542\\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\x220d\xa1e8\x220d\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\xd6\x8138\x118\xffd8\xffff\x6b76\f\x8e\xd728\x2fb\1\1\x776f\x6463\x6c70\x3031\x632e\x6d68\x6b76\xffd8\xffff\x6b76\f\x8e\xd7c0\x2fb\1\1o\x776f\x7263\x6c70\x3031\x632e\x6d68ff\xffe8\xffffD:\I386\\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\11\1033\\xff5\xca1\x35d2\xffa0\xffff\x6b6e \xe8fe\x45cf\x28a8\x1c7\\xba98\x2fb\\\xffff\xffff\xffff\xffff\1\xfc00\x2ea\x3bb0\xffff\xffff\\\NDo\16\x7250\x786f\x5379\x7574\x4362\x736c\x6469e\xffe0\xffff\x6b76\a\b\xd6d0\x2fb\1\1t\x6556\x7372\x6f69n\xfff0\xffff2.0\x43fc\xbbb6\xffd8\xffff\x6b76\vb\xd938\x2fb\1\1\xe6\x6276\x7061\x3162\x2e30\x6863m\\xffe0\xffff\x6b76\a\24\x7fe8\x2fb\1\1\x6556\x7372\x6f69\x516e\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\ram\xff68\xffffC:\Program Files\Common Files\Microsoft Shared\Web Components\10\1033\\xe6\x2710\x28d5\xffd0\xffff\x6b76\22\\xda20\x2fb\1\1\x6143\x746d\x7361\x6169\x7453\x6475\x6f69\x632e\x6d68\\xffd8\xffff\x6b76\fB\xda80\x2fb\1\1T\x4950\x544e\x474c\x454e\x432e\x4d48UI\xffe0\xffff\x6b76\4F\xf188\x2fb\1\1\x6d6d\x3378\x6b76\17\xffa0\xffff\x6b6e \xe8fe\x45cf\x28a8\x1c7\\xba98\x2fb\\\xffff\xffff\xffff\xffff\1\xf78\x2e9\x3bb0\xffff\xffff\\\NOf\20\x7250\x786f\x5379\x7574\x4362\x736c\x6469\x3233\b\xeb71\xaec0\xff98\xffffC:\Program Files\Microsoft Office\OFFICE11\1033\u\xffd8\xffff\x6b76\fB\xd9c8\x2fb\1\1I\x4950\x544e\x474c\x544e\x432e\x4d48c\xffb8\xffffC:\WINDOWS\system32\IME\PINTLGNTN\xfff0\xffff\x686c\1\xef08\x2fb\xb427\x1a0f\xffa0\xffffC:\Program Files\TechSmith\Camtasia Studio 4\\xffb8\xffffC:\WINDOWS\system32\IME\PINTLGNTH\xffd8\xffff\x6b76\f \xdaf0\x2fb\1\1n\x4950\x544e\x504c\x4541\x432e\x4d48e.\xffd8\xffffC:\WINDOWS\help.e\xffd8\xffff\x6b76\v:\xdc30\x2fb\1\1\x2fc9\x4f56\x4349\x4a45\x2e50\x4843\x14d\x54cd\x9c0\xfff0\xffff\x686c\1\xedf0\x2fb\xb427\x1a0f\xffd8\xffff\x6b76\f \xdb78\x2fb\1\1u\x4950\x544e\x504c\x4441\x432e\x4d486-\xffd8\xffffC:\WINDOWS\helpin\xffd8\xffff\x6b76\f:\xdbc8\x2fb\1\1\x2fc9\x4f56\x4349\x4545\x474e\x432e\x4d48\x54cd\x9c0\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\xc8f4\xffd8\xffff\x6b76\n:\xdd08\x2fb\1\1\x2fc9\x4d49\x504a\x4c43\x432e\x4d48\x2c0\x54cd\x9c0\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\xe4d0\xffd8\xffff\x6b76\v:\xdc98\x2fb\1\1\x2fc9\x4d49\x504a\x4c43\x2e45\x4843\x24d\x54cd\x9c0\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\x40b6\xffd8\xffff\x6b76\n:\xdde8\x2fb\1\1\x1a5d\x4d49\x504a\x4d53\x432e\x4d48\x2e0\xed12\x24fa\xfff8\xffff\xdfa0\x2fb\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\x7abc\xffd8\xffff\x6b76\v:\xdd70\x2fb\1\1\xc941\x4d49\x504a\x4d53\x2e45\x4843M\x445b\x4853\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\xa0f2\xffd8\xffff\x6b76\n:\xded0\x2fb\1\1\x5f97\x4d49\x504a\x5554\x432e\x4d48\xca\xcde9\x895a\xfff0\xffff\x686c\1\xef68\x2fb\xcff6\xce9b\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\xf029\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\x88e\xffd8\xffff\x6b76\n:\xde90\x2fb\1\1\xc733\x4d49\x504a\x5444\x432e\x4d48\xdd\x7e37\x24d6\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\x2b33\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\x4294\xffd8\xffff\x6b76\v:\xdf38\x2fb\1\1\x5c41\x4d49\x504a\x5444\x2e45\x4843M\xdebe\x5c4e\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\x476e\xffd8\xffff\x6b76\f:\xe0d8\x2fb\1\1\xccc6\x504a\x504e\x4441\x4e45\x432e\x4d48\x2668\x1e29\xffe0\xffff\x6b76\6\34\xe930\x2fb\1\1m\x7250\x676f\x4449m\xffd8\xffff\x6b76\n:\xde28\x2fb\1\1\x2591\x4d49\x504a\x4450\x432e\x4d48\xc9\xb473\x4f54\xffe8\xffffMagnifier\x6268\x6e69\xe000\x2fb\x1000\\\\\\xffd8\xffff\x6b76\n:\xe048\x2fb\1\1\x6d69\x726b\x3136\x632e\x6d68\\xffc0\xffffC:\WINDOWS\ime\imkr6_1\help\\\xffd8\xffff\x6b76\f:\xe1d8\x2fb\1\1\x6d69\x726b\x6e65\x3136\x632e\x6d68\\xffd8\xffff\x6b76\f:\xe118\x2fb\1\1\x6d69\x6470\x6f6b\x3136\x632e\x6d68\\xffc0\xffffC:\WINDOWS\ime\imjp8_1\Help\\xbbb3\xffc0\xffffC:\WINDOWS\ime\imkr6_1\help\\\xffd8\xffff\x6b76\f:\xe180\x2fb\1\1\x6f6b\x7072\x6461\x6e65\x632e\x6d68\\xffc0\xffffC:\WINDOWS\ime\imkr6_1\help\\\xffe8\xffffNarrator\\xffc0\xffffC:\WINDOWS\ime\imkr6_1\help\\\xffd8\xffff\x6b76\f(\xe240\x2fb\1\1\x4843\x5054\x4441\x4e45\x432e\x4d48\\xffd0\xffffFolder:IMEPADEN.CHM\\xffd8\xffff\x6b76\n<\xe298\x2fb\1\1\x4843\x4154\x5450\x432e\x4d48\\xffc0\xffffC:\WINDOWS\IME\CHTIME\APPLETS\xffd8\xffff\x6b76\v\4\x8000\xbb8\4\1\x6544\x6976\x6563\x444d\x304d0\\xffa0\xffff\x6b6e \x77c4\x33e4\xec90\x1c3\\xa0d0\x245\1\\xb4b8\x2fb\xffff\xffff\\xffff\xffff\x3bb0\xffff\xffff\16\\\\\t\x5449\x7453\x726f\x6761e\\xffc0\xffff\x686c\6\xa128\x245\xf69d\x7e25\x7e70\x2fb\x22719\xc308\x2fb\x2bce\x6bf3\xe300\x2fb\x12c6\xf7f6\xe538\x2fb\xb890\x97e\xec58\x333\xe94d\x95c1\xdf78\x2fb\xe020\x2fb\xfff0\xffff\\x4441\x4542\\xff28\xffff\xc368\x2fb\xc818\x2fb\xc900\x2fb\xc9c0\x2fb\xc8d8\x2fb\xcb48\x2fb\xca80\x2fb\xccd8\x2fb\xcc08\x2fb\xce40\x2fb\xcd98\x2fb\xcfb0\x2fb\xcfd8\x2fb\xced0\x2fb\xd0b8\x2fb\xd0e0\x2fb\xd238\x2fb\xd260\x2fb\xd3c0\x2fb\xd550\x2fb\xd578\x2fb\xd6e0\x2fb\xd858\x2fb\xd888\x2fb\xd9a0\x2fb\xdb50\x2fb\xdac8\x2fb\xdb18\x2fb\xdba0\x2fb\xdc08\x2fb\xdc70\x2fb\xdcd8\x2fb\xdd48\x2fb\xddb0\x2fb\xdfc0\x2fb\xde68\x2fb\xdf10\x2fb\xdf78\x2fb\xe020\x2fb\xe088\x2fb\xe0b0\x2fb\xe158\x2fb\xe218\x2fb\xe270\x2fb\x4198\x322\x3c30\x320\x3cd8\x320\x3d80\x320\x3e28\x320\x3ed0\x320\x3f78\x320\xfc00\x314\\xffa8\xffff\x6b6e \x77c4\x33e4\xec90\x1c3\\xe300\x2fb\\\xffff\xffff\xffff\xffff\1\xb7b8\x2fb\x3bb0\xffff\xffff\\\bN\\a\x6946\x646e\x7265s\xffa8\xffff{adb880a4-d8ff-11cf-9377-00aa003b7a11}\\\xffa8\xffff\x6b6e \x77c4\x33e4\xec90\x1c3\\xa0d0\x245\\\xffff\xffff\xffff\xffff\\xffff\xffff\x3bb0\xffff\xffff\\\\\\5\x6853\x6c65l\xff98\xffff\x6b6e \xb05a\x6fe0\x3362\x1c7\\xf7c8\x208\3\\x38b8\27\xffff\xffff\\xffff\xffff\x3bb0\xffff\xffff$\\\\\23\x6957\x646e\x776f\x2073\x4543\x5320\x7265\x6976\x6563s\\xffa0\xffff\x6b6e \xd926\x3e1a\xf2b6\x1c5\\xe590\x2fb\\\xffff\xffff\xffff\xffff!\xec78\x2fb\x3bb0\xffff\xffff\\\26\4\\n\x7250\x786f\x5079\x726f\x7374\\xffd8\xffff\x6b76\v\4\x8000\xbb9\4\1\x6544\x6976\x6563\x444d\x304d1\\xffd8\xffff\x6b76\v\4\x8000\xbba\4\1\x6544\x6976\x6563\x444d\x304d2\\xffd8\xffff\x6b76\v\4\x8000\xbbb\4\1\x6544\x6976\x6563\x444d\x304d3\\xffd8\xffff\x6b76\v\4\x8000\xbbc\4\1\x6544\x6976\x6563\x444d\x304d4\\xffd8\xffff\x6b76\v\4\x8000\xbbd\4\1\x6544\x6976\x6563\x444d\x304d5\\xffd8\xffff\x6b76\v\4\x8000\xbbe\4\1\x6544\x6976\x6563\x444d\x304d6\\xffd8\xffff\x6b76\v\4\x8000\xbbf\4\1\x6544\x6976\x6563\x444d\x304d7\\xffd8\xffff\x6b76\v\4\x8000\xbc2\4\1\x2a2\x6544\x6976\x6563\x444d\x314d\x230\xef98\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbc0\4\1\x6544\x6976\x6563\x444d\x304d8\\xffd8\xffff\x6b76\v\4\x8000\xbc1\4\1\x6544\x6976\x6563\x444d\x304d9\\xffd8\xffff\x6b76\v\4\x8000\xbc4\4\1\x2a2\x6544\x6976\x6563\x444d\x314d\x232\xef98\x2a2\b\xe770\x2fb\xffd8\xffff\x6b76\v\4\x8000\xbc3\4\1\x6544\x6976\x6563\x444d\x314d1\\xffd8\xffff\x6b76\v\4\x8000\xbc6\4\1\x2a2\x6544\x6976\x6563\x444d\x314d\x234\xef98\x2a2\xfff0\xffff\\x4441\x4542\\xffd8\xffff\x6b76\v\4\x8000\xbc5\4\1\x6544\x6976\x6563\x444d\x314d3\\xffd8\xffff\x6b76\v\4\x8000\xbc8\4\1\x2a2\x6544\x6976\x6563\x444d\x314d\x236\xef98\x2a2\xffe8\xffff\x14d0\x2fc\x1778\x2fc\x19c0\x2fc\x19f0\x2fc\xcc79\x3a63\xffd8\xffff\x6b76\v\4\x8000\xbc7\4\1\x6544\x6976\x6563\x444d\x314d5\\xffd8\xffff\x6b76\v\4\x8000\xbca\4\1\x2a2\x6544\x6976\x6563\x444d\x314d\x238\xef98\x2a2\xffe0\xffffMsScp.MSSCP.1\xffd8\xffff\x6b76\v\4\x8000\xbc9\4\1\x6544\x6976\x6563\x444d\x314d7\\xffd8\xffff\x6b76\v\4\x8000\xbcc\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x230\xef98\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbcd\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x231\xf140\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbcb\4\1\x6544\x6976\x6563\x444d\x314d9\\xffd8\xffff\x6b76\v\4\x8000\xbce\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x232\xef98\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbcf\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x233\xf140\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbd0\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x234\xef20\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbd1\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x235\xf0d8\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbd2\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x236\xee48\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbd3\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x237\xf020\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbd4\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x238\xf228\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbd5\4\1\x2a2\x6544\x6976\x6563\x444d\x324d\x239\xef20\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbd6\4\1\x2a2\x6544\x6976\x6563\x444d\x334d\x230\xf0d8\x2a2\xffd8\xffff\x6b76\v\4\x8000\xbd7\4\1\x2a2\x6544\x6976\x6563\x444d\x334d\x231\xf2c8\x2a2\xffa0\xffff\x6b6e \x8c7e\xd716\x2988\x1c7\\xf7c8\x208\4\\xf108\x2fb\xffff\xffff\1\xbce8\x2fb\x318\xffff\xffff\24\\"\24\\r\x6957\x646e\x776f\x2073\x654d\x6964a\xffd0\xffff\x6b76\21\24\xa2c0\x245\1\1\x154\x6944\x6572\x7463\x2058\x654d\x6964\x2061\x2e360*\xffa8\xffff\x6b6e \x974\xf7d0\xc7bc\x1c5\\xeb80\x2fb\2\\x8588\x2fb\xffff\xffff\2\x8120\x2fa\x318\xffff\xffff\6\\24fth\a\x6e45\x6f63\x6564r\xfff0\xffff\\x4441\x4542\\xff78\xffff\xe2d8\x2fb\xe658\x2fb\xe680\x2fb\xe6a8\x2fb\xe6d0\x2fb\xe6f8\x2fb\xe720\x2fb\xe748\x2fb\xe798\x2fb\xe7c0\x2fb\xe770\x2fb\xe818\x2fb\xe7e8\x2fb\xe878\x2fb\xe840\x2fb\xe8e0\x2fb\xe8a0\x2fb\xe950\x2fb\xe908\x2fb\xe9c8\x2fb\xe978\x2fb\xe9a0\x2fb\xe9f0\x2fb\xea18\x2fb\xea40\x2fb\xea68\x2fb\xea90\x2fb\xeab8\x2fb\xeae0\x2fb\xeb08\x2fb\xeb30\x2fb\xeb58\x2fb\xcef8\x2fb\xffd8\xffff\x6b76\nf\xed28\x2fb\1\1\x6e49\x7473\x6c61\x446c\x7269\x96b9\x5ee9\x1c4\xff90\xffffC:\Program Files\Windows Media Components\Encoder\\xff\x9a98\xff\xffa8\xffff\x6b6e \x221a\x98ae\x5ee9\x1c4\\xec10\x2fb\1\\xdb40\x2fb\xffff\xffff\\xffff\xffff\x318\xffff\xffff\30\\\\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000002ce
"TracesSuccessful"=dword:00000017

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\maya70docserver]
"ImagePath"="\"C:\Program Files\Alias\Maya7.0\docs\wrapper.exe\" -s \"C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf\""

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\wampmysqld]
"ImagePath"="G:\wamp\mysql\bin\mysqld-nt.exe –defaults-file=G:\wamp\mysql\my.ini wampmysqld"

Completion time: 2007-07-28 16:18:04 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-28 16:15

— E O F —

VundoFix log:


VundoFix V6.5.6

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 3:17:13 PM 28/07/2007

Listing files found while scanning….

C:\WINDOWS\Config\untafx.dll
C:\WINDOWS\Config\xfatnu.bak1
C:\WINDOWS\Config\xfatnu.bak2
C:\WINDOWS\Config\xfatnu.ini
C:\WINDOWS\Config\xfatnu.tmp

Beginning removal…

Attempting to delete C:\WINDOWS\Config\untafx.dll
C:\WINDOWS\Config\untafx.dll Has been deleted!

Attempting to delete C:\WINDOWS\Config\xfatnu.bak1
C:\WINDOWS\Config\xfatnu.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\Config\xfatnu.bak2
C:\WINDOWS\Config\xfatnu.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\Config\xfatnu.ini
C:\WINDOWS\Config\xfatnu.ini Has been deleted!

Attempting to delete C:\WINDOWS\Config\xfatnu.tmp
C:\WINDOWS\Config\xfatnu.tmp Has been deleted!

Performing Repairs to the registry.
Done!
Hi

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Please click this link–>Jotti

When the jotti page has finished loading, click the Browse button and navigate to the following file and click Submit.

C:\WINDOWS\almgp.exe

Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/
File: almgp.exe
Status: OK
MD5: 53d338a1d33978e64e6c75dc1765325d
Packers detected: -
Bit9 reports: File not found

Scanner results
Scan taken on 29 Jul 2007 12:08:05 (GMT)

A-Squared
Found nothing

AntiVir
Found nothing

ArcaVir
Found nothing

Avast
Found nothing

AVG Antivirus
Found nothing

BitDefender
Found nothing

ClamAV
Found nothing

CPsecure
Found nothing

Dr.Web
Found nothing

F-Prot Antivirus
Found nothing

F-Secure Anti-Virus
Found nothing

Fortinet
Found nothing

Kaspersky Anti-Virus
Found nothing

NOD32
Found nothing

Norman Virus Control
Found nothing

Panda Antivirus
Found nothing

Rising Antivirus
Found nothing

Sophos Antivirus
Found nothing

VirusBuster
Found nothing

VBA32
Found nothing
Hi

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases

  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Post:

- a fresh HijackThis log
- kaspersky report
Runned the scan! Nothing interesting… quarantined items from my actual and my old antivirus programs, locked items, adware bundlers, etc. Unless I missed something?

Logfile of HijackThis v1.99.1
Scan saved at 5:43:51 PM, on 02/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\PFShared\UmxCfg.exe
C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe
C:\Program Files\Common Files\PFShared\UmxPol.exe
C:\Program Files\Tiny Firewall Pro\UmxAgent.exe
C:\Program Files\Tiny Firewall Pro\UmxTray.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Subversion\bin\svnservice.exe
C:\Program Files\Subversion\bin\svnserve.exe
C:\Program Files\Common Files\PFShared\umxlu.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ULI5289\ALi5289.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
G:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\mIRC\mirc.exe
G:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe
C:\Program Files\WhatPulse\WhatPulse.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\FeedReader30\feedreader.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\notepad.exe
G:\Files\Programmes\HijackThis!\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qc-net.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - G:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - G:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ALi5289] C:\Program Files\ULI5289\ALi5289.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "G:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Append to existing PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://G:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\default.bol\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\default.bol\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab30149.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab48295.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169866054515
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143835158390
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab30149.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab28578.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: PFW - C:\WINDOWS\SYSTEM32\UmxWnp.Dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Unknown owner - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe" -win32service (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SVNService - Clansoft - C:\Program Files\Subversion\bin\svnservice.exe
O23 - Service: FW Event Manager (UmxAgent) - Computer Associates International, Inc. - C:\Program Files\Tiny Firewall Pro\UmxAgent.exe
O23 - Service: FW Configuration Interpreter (UmxCfg) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\UmxCfg.exe
O23 - Service: FW User-Mode Helper (UmxFwHlp) - Computer Associates International, Inc. - C:\Program Files\Tiny Firewall Pro\UmxFwHlp.exe
O23 - Service: FW Live Update (UmxLU) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\umxlu.exe
O23 - Service: FW Policy Manager (UmxPol) - Computer Associates International, Inc. - C:\Program Files\Common Files\PFShared\UmxPol.exe
O23 - Service: wampapache - Unknown owner - G:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - G:\wamp\mysql\bin\mysqld-nt.exe

KASPERSKY ONLINE SCANNER REPORT
Thursday, August 02, 2007 5:17:01 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 2/08/2007
Kaspersky Anti-Virus database records: 370608

Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\

Scan Statistics
Total number of scanned objects 926270
Number of viruses found 87
Number of infected objects 641
Number of suspicious objects 34
Duration of the scan process 15:06:37

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Adobe\ALM\alm.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\FLEXnet\adobe_00080000_tsf.data Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\E2152C Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine213272B/photo.jpg .scr Infected: Email-Worm.Win32.Mabutu.a skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine213272B ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine213272B CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine2F67917 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine38B001D.tmp Infected: Net-Worm.Win32.Mytob.bi skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine3C13FE0.tmp Infected: Trojan-Downloader.Java.OpenStream.w skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine3E33B32.tmp Infected: Trojan-Downloader.Java.OpenStream.c skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine3E6652E.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine3E6652E.zip ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine3E6652E.zip CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine4307F9F.exe Infected: Trojan-Downloader.Win32.IstBar.ju skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine4375398.exe Infected: Trojan-Downloader.Win32.IstBar.ju skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine4741D66.tmp Infected: Net-Worm.Win32.Mytob.bi skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine4A2303F Infected: Email-Worm.Win32.NetSky.ac skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine4B85B01.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine51D7CA0 Suspicious: Exploit.HTML.Mht skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine5682DCB.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine5682DCB.zip/Counter.class Infected: Trojan.Java.ClassLoader.h skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine5682DCB.zip/Parser.class Infected: Trojan.Java.ClassLoader.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine5682DCB.zip ZIP: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine5682DCB.zip CryptFF: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine65A5C3A/Important.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine65A5C3A ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine65A5C3A CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine70D6277.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine7454677 Infected: Trojan-Downloader.Win32.IstBar.er skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine76C0618/Textfile.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine76C0618 ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine76C0618 CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine77A7F2F/[From [removed]][Date Thu, 25 Nov 2004 10:42:59 UTC]/auto__mail.iam.9984.txt.zlq Infected: Email-Worm.Win32.Sober.i skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine77A7F2F Mail: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine77A7F2F CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine7AF13A1.tmp Infected: Email-Worm.Win32.Doombot.g skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine80C0A3F.tmp Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine86373A7.tmp Infected: Trojan.Java.ClassLoader.h skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine86C6778 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine88A0181 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine8A0073E Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine8A85746.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine8A86232.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine9805B13 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineA366B4A.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineA5828FE.tmp Infected: Email-Worm.Win32.Doombot.g skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineA8B0512 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineAAB020E.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineADB021A/jenifer.jpg .scr Infected: Email-Worm.Win32.Mabutu.a skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineADB021A ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineADB021A CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineAF2309E Infected: Email-Worm.VBS.Lectus.a skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineB4858D6 Infected: Email-Worm.Win32.NetSky.ac skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineCB1020C Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineCE20817.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineCEA16A1/[From [removed]][Date Wed, 24 Nov 2004 23:59:13 GMT]/im_shocked.zlo Infected: Email-Worm.Win32.Sober.i skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineCEA16A1 Mail: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineCEA16A1 CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineD404876.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineD5A6898.tmp Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineD756975.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineDA3639F.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineDB05D35.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineDF250E4 Infected: Email-Worm.Win32.NetSky.ac skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineDFB5D23.tmp Infected: Net-Worm.Win32.Mytob.bi skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineE0B6ACE.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineE7D416C.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineED83540 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\QuarantineF2317D1.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\10BF2ED7 Infected: Email-Worm.Win32.NetSky.q skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\10E14343 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11456808.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11595760 Infected: Trojan-Downloader.Win32.IstBar.er skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\117D6DB5.tmp Infected: Trojan.Java.ClassLoader.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11BA4FC2/[From [removed]][Date 14 Sep 2004 06:20:44 -0000]/UNNAMED/[From [removed]][Date Tue, 14 Sep 2004 15:20:39 +0900]/UNNAMED/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11BA4FC2/[From [removed]][Date 14 Sep 2004 06:20:44 -0000]/UNNAMED/[From [removed]][Date Tue, 14 Sep 2004 15:20:39 +0900]/UNNAMED/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11BA4FC2/[From [removed]][Date 14 Sep 2004 06:20:44 -0000]/UNNAMED/[From [removed]][Date Tue, 14 Sep 2004 15:20:39 +0900]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11BA4FC2/[From [removed]][Date 14 Sep 2004 06:20:44 -0000]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11BA4FC2 Mail: suspicious - 4 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11BA4FC2 CryptFF: suspicious - 4 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\11E94359.cla Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\129F40C3 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12A52DD9 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\139E4A32 Infected: Email-Worm.Win32.NetSky.q skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\13BF19B5.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\13E516F6.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\13FE6631 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\143A1A84.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\14885BD4.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\15707AAC.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\16D3321D Infected: Email-Worm.Win32.NetSky.ac skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\170307D5.tmp Infected: Net-Worm.Win32.Mytob.ar skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1724422D.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\180F684E.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1817222A Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1829192B Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\18B01608 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\18FC3344.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\19574ADF.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\196B46CA.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\19B368F4.tmp Infected: Email-Worm.Win32.Doombot.g skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1B4A7B42.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1B9D079B.tmp Infected: Trojan-Downloader.Java.OpenConnection.aj skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1BA6227C.tmp Infected: Trojan-Downloader.Java.OpenConnection.aj skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1BC24DCD Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1BC879E5 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1BEA019F.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1C0E526A.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1C4C7026.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1C8439E9.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1CE86F64.tmp Infected: Email-Worm.Win32.NetSky.q skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1D170CFD Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1D3C12F7.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1D5B259B.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1DE86548 Infected: Trojan-Downloader.Win32.INService.h skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1E3F5301.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1E611B1C Infected: Email-Worm.Win32.NetSky.ac skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1EAC5D59.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1ED96C9D.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F4159DA Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1F91529F.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2009680A Infected: Email-Worm.Win32.Bagle.au skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\204C50A7.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\20842B7C.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\21170C1C.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\21C80A35 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2212668B/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2212668B ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2212668B CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\226D22EB.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\23186CE2/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\23186CE2 ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\23186CE2 CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\235254A8 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243D5587/[From [removed]][Date Thu, 25 Nov 2004 11:52:16 UTC]/job68_3456.DOC.zl6 Infected: Email-Worm.Win32.Sober.i skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243D5587 Mail: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243D5587 CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\253612B2/Important.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\253612B2 ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\253612B2 CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\266F6C45.tmp/doc.pif Infected: Net-Worm.Win32.Mytob.c skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\266F6C45.tmp ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\266F6C45.tmp CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\267F3A6A Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\26D5451E.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27464558.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27A9318F.tmp/[From ferreol-1-82-66-170-129.fbx.proxad.net [82.66.170.129]][Date Tue, 15 Feb 2005 20:00:05 +0100]/UNNAMED/[From [removed]][Date Tue, 15 Feb 2005 20:00:03 +0100]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27A9318F.tmp/[From ferreol-1-82-66-170-129.fbx.proxad.net [82.66.170.129]][Date Tue, 15 Feb 2005 20:00:05 +0100]/UNNAMED/[From [removed]][Date Tue, 15 Feb 2005 20:00:03 +0100]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27A9318F.tmp/[From ferreol-1-82-66-170-129.fbx.proxad.net [82.66.170.129]][Date Tue, 15 Feb 2005 20:00:05 +0100]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27A9318F.tmp Mail: suspicious - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\27A9318F.tmp CryptFF: suspicious - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\280B5C7B Infected: Email-Worm.Win32.NetSky.ac skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\28754CD6 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\28CC34BC.tmp Infected: Net-Worm.Win32.Mytob.bk skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29423220 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2985163C.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29ED76D6 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2A1C21E7.tmp Infected: Net-Worm.Win32.Mytob.r skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2A2E2A8A Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2A672363/Data.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2A672363 ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2A672363 CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2B150D02 Infected: Email-Worm.Win32.NetSky.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2BC75154.tmp Infected: HackTool.Win32.John skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2CA1315D/Informations.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2CA1315D ZIP: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2CA1315D CryptFF: infected - 1 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2DF42710.tmp Infected: Net-Worm.Win32.Mytob.bf skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E057521.tmp Infected: Backdoor.Win32.SdBot.xd skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2F495C4E Infected: Email-Worm.Win32.NetSky.d skipped
(continued) C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\301E64BB Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30C76228/instruction.html .scr Infected: Email-Worm.Win32.Mydoom.m skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30C76228 ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30C76228 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\30E8208C.tmp Infected: Trojan-Downloader.Java.OpenConnection.aj skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\310B3097/[From [removed]][Date Tue, 23 Nov 2004 16:21:16 UTC]/lariposte1587.eml.zlq Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\310B3097 Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\310B3097 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31844212/[From [removed]][Date Tue, 23 Nov 2004 16:21:16 UTC]/mail_2903.zlq Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31844212 Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31844212 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31A13BF2/[From [removed]][Date Tue, 23 Nov 2004 17:50:19 UTC]/re_mail.5429.bat Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31A13BF2 Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31A13BF2 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31BB0BD5/[From [removed]][Date Tue, 23 Nov 2004 18:06:43 GMT]/hotmail_5723.zlq Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31BB0BD5 Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31BB0BD5 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31C83A96 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31CF07BF/[From [removed]][Date Tue, 23 Nov 2004 18:06:43 GMT]/hotmail.6996.zl3 Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31CF07BF Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31CF07BF CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31EC019F/[From [removed]][Date Tue, 23 Nov 2004 18:06:43 GMT]/mail.zlo Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31EC019F Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31EC019F CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31FD538D/[From [removed]][Date Tue, 23 Nov 2004 20:04:48 GMT]/thats_hard_6195.zm9/message_text.txt .pif Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31FD538D/[From [removed]][Date Tue, 23 Nov 2004 20:04:48 GMT]/thats_hard_6195.zm9 Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31FD538D Mail: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\31FD538D CryptFF: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\32330754 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\32B460B5/Informations.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\32B460B5 ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\32B460B5 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\32F60CC9.tmp Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\335707A1.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\33691086.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\337B69FC.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\337B69FC.tmp ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\337B69FC.tmp CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\33B51B43 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\33CD409A.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\34B108D5.tmp Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\34C14000 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\35372A8B.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\357A3E37 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\35876629 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\35D76A81.tmp Infected: Trojan-Downloader.Java.OpenConnection.aj skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\35DB561F.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\35FC76EE.php Infected: Exploit.Perl.Spais skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\36256610.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\36A02634 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37372CE2.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37F509E8 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37FE3664 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\387A5673 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\38955253.tmp Infected: Net-Worm.Win32.Mytob.c skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\396A7E84/[From [removed]][Date Wed, 24 Nov 2004 13:30:19 GMT]/yahoo7696.zm9/message_text.txt .pif Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\396A7E84/[From [removed]][Date Wed, 24 Nov 2004 13:30:19 GMT]/yahoo7696.zm9 Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\396A7E84 Mail: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\396A7E84 CryptFF: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39A14C64.tmp Infected: Email-Worm.Win32.Doombot.g skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39AB463D/[From [removed]][Date Wed, 24 Nov 2004 17:13:20 GMT]/auto__mail.bosrup4269.scr Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39AB463D Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39AB463D CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39B86E2E/[From [removed]][Date Wed, 24 Nov 2004 19:08:39 GMT]/oh_nono.zl6 Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39B86E2E Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39B86E2E CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39BF4227/[From [removed]][Date Wed, 24 Nov 2004 21:18:15 GMT]/auto__mail.topmaintenance.zl3 Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39BF4227 Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39BF4227 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A61101F Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3ACF6134.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3B5637A8 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3B7B7886 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BEF5297.tmp/[From [removed]][Date Tue, 31 Jan 2006 10:56:40 -0800]/UNNAMED/[From [removed]][Date Tue, 31 Jan 2006 19:26:33 +0100]/your_bill.pif.VIRUS Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BEF5297.tmp/[From [removed]][Date Tue, 31 Jan 2006 10:56:40 -0800]/UNNAMED Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BEF5297.tmp Mail: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3BEF5297.tmp CryptFF: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C1F71E4 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C2000C0.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3C4A30EC.tmp Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CD13C64.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CE3098C.tmp Infected: Trojan-Downloader.Java.OpenStream.w skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3D3C7E0F.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3D7A64B8/[From [removed]][Date Wed, 16 Jun 2004 15:20:12 +0200]/UNNAMED/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3D7A64B8/[From [removed]][Date Wed, 16 Jun 2004 15:20:12 +0200]/UNNAMED/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3D7A64B8/[From [removed]][Date Wed, 16 Jun 2004 15:20:12 +0200]/UNNAMED/message.scr Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3D7A64B8/[From [removed]][Date Wed, 16 Jun 2004 15:20:12 +0200]/UNNAMED Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3D7A64B8 Mail: infected - 2, suspicious - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3D7A64B8 CryptFF: infected - 2, suspicious - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3DF1703B Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3E04251A.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3E051A56 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3E93173A Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EB73C61.tmp/[From [removed]][Date Thu, 3 Mar 2005 11:46:15 +0100]/UNNAMED/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EB73C61.tmp/[From [removed]][Date Thu, 3 Mar 2005 11:46:15 +0100]/UNNAMED/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EB73C61.tmp/[From [removed]][Date Thu, 3 Mar 2005 11:46:15 +0100]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EB73C61.tmp Mail: suspicious - 3 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EB73C61.tmp CryptFF: suspicious - 3 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3EB77F2E.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F605281 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F94474A Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F9F129F.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FBB6DCD Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FD473F0 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FD8468B.tmp Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40217C8F/[From [removed]][Date Wed, 24 Nov 2004 08:43:26 GMT]/menara.3991.zlo Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40217C8F Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40217C8F CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\405C704E/[From [removed]][Date Wed, 24 Nov 2004 08:43:26 GMT]/hotmail_5162.zlo Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\405C704E Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\405C704E CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40691840/[From [removed]][Date Wed, 24 Nov 2004 10:46:02 GMT]/auto__mail.free.DOC.zlo Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40691840 Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\40691840 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\41B41186.cla Infected: Exploit.Java.ByteVerify skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\421E5A2B Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\422518B8 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\425B3089.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\434207C2.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\434F56AE.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\43C048F2/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\43C048F2 ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\43C048F2 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\442D4E5C Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\44FB0CD6 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45220E5A/[From "Webmaster" ][Date Wed, 15 Dec 2004 19:29:08 +0000]/Joke.zl7 Infected: Email-Worm.Win32.Bagle.at skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45220E5A Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45220E5A CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4523460F.tmp Infected: HackTool.Win32.John skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4526700C.exe Infected: HackTool.Win32.John skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4526700C.tmp Infected: HackTool.Win32.John skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\452A1A08.dll Infected: Trojan-Downloader.Win32.IstBar.gen skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\454D3D20 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\45EC26F4.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\461D2BE9 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\462F1D67.tmp Infected: Trojan.Java.ClassLoader.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\463D0714 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\469F72A8 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\47765D48.htm Suspicious: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\47C802EA.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4831631D.tmp Infected: Trojan.Java.ClassLoader.h skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48686A2D.tmp/[From [removed]][Date Thu, 29 Sep 2005 14:49:23 +0200]/your_document.zlo Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48686A2D.tmp Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48686A2D.tmp CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\487047D1.tmp Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48A13D9B.tmp/[From [removed] (Mail Delivery System)][Date Wed, 5 Oct 2005 19:47:51 +0200 (CEST)]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48A13D9B.tmp/[From [removed] (Mail Delivery System)][Date Wed, 5 Oct 2005 19:47:51 +0200 (CEST)]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48A13D9B.tmp Mail: suspicious - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\48A13D9B.tmp CryptFF: suspicious - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\49325787.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4A067085 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4A075EA0 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4A481DBD Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4B2049AA Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4B222787 Suspicious: Exploit.HTML.Mht skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4B4F5733.tmp Infected: Trojan-Downloader.Java.OpenConnection.aj skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4B753470 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4BBE3D6B.tmp Infected: Net-Worm.Win32.Mytob.bk skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4BF643D1.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C2B40F5.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C565D09.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4C83797C Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4CE25BD2.tmp/[From [removed]][Date Thu, 29 Sep 2005 14:49:23 +0200]/your_document.zlo Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4CE25BD2.tmp Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4CE25BD2.tmp CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4D7F49C2.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4D8F1BB0.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4E06700D.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4E800DBD Infected: Trojan-Downloader.Win32.INService.h skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F2A16FC.tmp/[From [removed]][Date Fri, 19 Aug 2005 03:39:22 -0700]/UNNAMED/[From [removed]][Date Fri, 19 Aug 2005 12:09:20 +0200]/your_picture.zlo.VIRUS Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F2A16FC.tmp/[From [removed]][Date Fri, 19 Aug 2005 03:39:22 -0700]/UNNAMED Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F2A16FC.tmp Mail: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F2A16FC.tmp CryptFF: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F6226E3 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4F850ABC.tmp Infected: Trojan-Dropper.Win32.Delf.fd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4FAD0975.tmp/doc.scr Infected: Net-Worm.Win32.Mytob.c skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4FAD0975.tmp ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4FAD0975.tmp CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\501A450A.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\501B51BC Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\503D5D34.tmp Infected: Trojan-Downloader.Java.OpenConnection.aj skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\508D7906.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\518B563C.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51AE3EE9.tmp Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51C4714C.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51DC6D98.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51E50510 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe/bpk.exe Infected: not-a-virus:Monitor.Win32.Perflogger.ad skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe/bpkun.exe Infected: not-a-virus:Monitor.Win32.Perflogger.an skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe/bpkvw.exe Infected: not-a-virus:Monitor.Win32.Perflogger.aq skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe/Setup.exe Infected: not-a-virus:Monitor.Win32.Perflogger.af skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe/bpkhk.dll Infected: not-a-virus:Monitor.Win32.Perflogger.al skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe/bpkwb.dll Infected: Trojan-Spy.Win32.Perfloger.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe/bpkr.exe Infected: Trojan-Spy.Win32.Perfloger.ab skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe RAR: infected - 7 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\544E729E.exe CryptFF: infected - 7 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\54D05DF2 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\550E6619/[From [removed]][Date Wed, 24 Nov 2004 22:52:38 GMT]/aol.6792.zlo Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\550E6619 Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\550E6619 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\55D86309 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\56A1538A.cla Infected: Trojan.Java.ClassLoader.Dummy.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\57DB0815.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5832469A.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\594502FE Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\59571626.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\59896E62 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\59D10C1E.tmp Infected: HackTool.Win32.John skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A07735D.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5A401D99 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5B350B0A/[From [removed]][Date Thu, 25 Nov 2004 13:08:25 GMT]/hotmail.3863.zlq Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5B350B0A Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5B350B0A CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5B60129C.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5C1737A6.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5C4F7C0E/Important.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5C4F7C0E ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5C4F7C0E CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5D750960 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E027D56 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E071471.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E0817A4.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E2D069D.tmp Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB1022F/Part-2.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB1022F ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB1022F CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB42C2C Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EB727CD Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EE77BE0 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EF26F29.tmp Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EF9141E.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EF9141E.tmp ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5EF9141E.tmp CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F166965 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F231157 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F5704BA.tmp/[From moutng.kundenserver.de [212.227.126.186]][Date Wed, 9 Mar 2005 12:43:30 +0100]/UNNAMED/[From [removed]][Date Wed, 9 Mar 2005 12:43:31 +0100]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F5704BA.tmp/[From moutng.kundenserver.de [212.227.126.186]][Date Wed, 9 Mar 2005 12:43:30 +0100]/UNNAMED/[From [removed]][Date Wed, 9 Mar 2005 12:43:31 +0100]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F5704BA.tmp/[From moutng.kundenserver.de [212.227.126.186]][Date Wed, 9 Mar 2005 12:43:30 +0100]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F5704BA.tmp Mail: suspicious - 3 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F5704BA.tmp CryptFF: suspicious - 3 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5F7B5892.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5FAD335B.tmp Infected: Email-Worm.Win32.Doombot.g skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5FE97048.tmp Infected: Trojan.Java.Binny.a skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\60660A1A.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6097210A.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\60E861DF.tmp Infected: HackTool.Win32.John skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\619B4FEE.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62225FD0 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\624961D2 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62572EF0.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62C833AB Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\63025107.tmp Infected: Net-Worm.Win32.Mytob.bi skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\634A00A6 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\63525B6F.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\63E01716 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\64662BED.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\65107845 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6580575D.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\65890ED4 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\65935347.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\65B40595.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\65B9436A.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\65C42F8B Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\65D620FA.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\664166A8.tmp/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\664166A8.tmp ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\664166A8.tmp CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\66574A71.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\66585A81/[From [removed]][Date Wed, 24 Nov 2004 11:59:08 UTC]/hotmail.zl6 Infected: Email-Worm.Win32.Sober.i skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\66585A81 Mail: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\66585A81 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\669648BF.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\67045008 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\67CD40ED.tmp Infected: Net-Worm.Win32.Mytob.bi skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\67EA6396.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\687B7439.tmp Infected: Exploit.Perl.Spais skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\68805BBC.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\68805BBC.tmp ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\68805BBC.tmp CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\68946ADB.tmp Infected: Net-Worm.Win32.Mytob.bf skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\698D3D56 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AE30025.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AF12AC6 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B32727E Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B3F1A70 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B491865 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B8277D0 Infected: not-a-virus:AdWare.Win32.Look2Me.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B94054D.tmp Infected: Net-Worm.Win32.Mytob.ar skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6BC400EE.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6C6117A1 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6CAB390F.tmp Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6CEC5B33.tmp Infected: Trojan.Java.ClassLoader.h skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6D616331.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6DE60284 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6EC7527C Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6EFC1159 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6F522F64 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6F8A7927 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6F935C9D Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\706962FD.pl Infected: Exploit.Perl.Spais skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\70E62DDE Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71244B99 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7151465A.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71607A1B.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\71D60867.tmp Infected: Trojan-Clicker.Win32.Small.is skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73050D5D.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\735C1F95 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73AA5776/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73AA5776 ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\73AA5776 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\74C2366B.tmp Infected: Trojan.Java.ClassLoader.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\760758DF.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\76A3057F.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\777C40D8.tmp Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77D01243 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77D1047B.tmp/[From [removed] (Mail Delivery System)][Date Fri, 14 Oct 2005 20:50:18 +0200 (CEST)]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77D1047B.tmp/[From [removed] (Mail Delivery System)][Date Fri, 14 Oct 2005 20:50:18 +0200 (CEST)]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77D1047B.tmp Mail: suspicious - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77D1047B.tmp CryptFF: suspicious - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\792B4264 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79313207.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\79D9159D.tmp Infected: Net-Worm.Win32.Mytob.c skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A074DB7.tmp/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A074DB7.tmp ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A074DB7.tmp CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A44079C.tmp Infected: Backdoor.Win32.SdBot.xd skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A4C5BCE/Notice.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A4C5BCE ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A4C5BCE CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A4F66F1.cla Infected: Exploit.Java.ByteVerify skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7A740214.tmp Infected: Net-Worm.Win32.Mytob.ar skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7B076A41/Informations.txt .exe Infected: Email-Worm.Win32.NetSky.aa skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7B076A41 ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7B076A41 CryptFF: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7B6B574D.tmp Infected: Net-Worm.Win32.Mytob.bi skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7BC669FD.tmp Infected: Net-Worm.Win32.Mytob.r skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7BDE0033 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C966902 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7CB3567F.tmp Infected: Net-Worm.Win32.Mytob.c skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7D0D5CA2 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7DB60620 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7DD6335A.tmp Infected: Trojan.Java.Binny.a skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7DDE5BBC Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7DF257A7 Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F392608 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F4E0207 Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F8141B9 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7F9F3B99 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7FAC638B Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7FB66180 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7FBF5F75 Infected: Email-Worm.Win32.NetSky.d skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Mathieu\Application Data\Microsoft\Outlook\outitems.log Object is locked skipped C:\Documents and Settings\Mathieu\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped C:\Documents and Settings\Mathieu\Application Data\Microsoft\Templates\NormalEmail.dotm Object is locked skipped C:\Documents and Settings\Mathieu\Application Data\Opera\Opera\mail\indexer\indexer.dat Object is locked skipped C:\Documents and Settings\Mathieu\Application Data\Opera\Opera\mail\lexicon\lexicon.dat Object is locked skipped C:\Documents and Settings\Mathieu\Application Data\Opera\Opera\mail\mailbase.dat Object is locked skipped C:\Documents and Settings\Mathieu\Application Data\Opera\Opera\profile\cache4\opr00NFR.js Object is locked skipped C:\Documents and Settings\Mathieu\Application Data\Sun\Java\Deployment\cache\6.0\39\7e41e267-127c7897/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped C:\Documents and Settings\Mathieu\Application Data\Sun\Java\Deployment\cache\6.0\39\7e41e267-127c7897 ZIP: infected - 1 skipped C:\Documents and Settings\Mathieu\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-5e55057-7d808c5e.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped C:\Documents and Settings\Mathieu\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-5e55057-7d808c5e.zip ZIP: infected - 1 skipped C:\Documents and Settings\Mathieu\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Application Data\Adobe\Acrobat\8.0\Updater\updater.log Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Application Data\Last.fm\Client\container.log Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Application Data\Last.fm\Client\lastfmhelper.log Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Application Data\Microsoft\Outlook\~Outlook.pst.tmp Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\History\History.IE5\MSHist012007080120070802\index.dat Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\fb_4660.lck Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo10 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo11 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo12 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo13 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo14 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo15 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo16 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo17 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo18 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo19 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo20 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo21 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo22 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo23 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo24 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo25 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo26 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo27 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo28 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo29 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo30 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo31 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo32 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo33 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo34 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo35 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo36 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo5 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo6 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo7 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo8 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\lilo9 Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\NeroDemo11606\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\Perflib_Perfdata_cd4.dat Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\~DF6AC4.tmp Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temp\~DF6AD9.tmp Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temporary Internet Files\Content.Word\~WRS{51425DBA-A384-4BE4-818A-88DA561993B4}.tmp Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temporary Internet Files\Content.Word\~WRS{67D760E5-C73E-4F5A-8DFF-3DA4F15C5E68}.tmp Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temporary Internet Files\Content.Word\~WRS{DA366878-2E7F-4CE6-89DF-73F369D6AD12}.tmp Object is locked skipped C:\Documents and Settings\Mathieu\Local Settings\Temporary Internet Files\Content.Word\~WRS{F2777701-BBBD-45BD-B3E5-65119487B0B7}.tmp Object is locked skipped C:\Documents and Settings\Mathieu\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Mathieu\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Mathieu\Sites\Kings of Chaos\Progs\KoCValues v1.21.exe/EXE-file Infected: Backdoor.Win32.VB.awg skipped C:\Mathieu\Sites\Kings of Chaos\Progs\KoCValues v1.21.exe Alloy: infected - 1 skipped C:\Mathieu\Sites\Kings of Chaos\Progs\KoCValues2.zip/KoCValues v1.21.exe/EXE-file Infected: Backdoor.Win32.VB.awg skipped C:\Mathieu\Sites\Kings of Chaos\Progs\KoCValues2.zip/KoCValues v1.21.exe Infected: Backdoor.Win32.VB.awg skipped C:\Mathieu\Sites\Kings of Chaos\Progs\KoCValues2.zip ZIP: infected - 2 skipped C:\Program Files\Common Files\Adobe\Adobe PCD\pcd.db Object is locked skipped C:\Program Files\Common Files\Adobe\caps\caps.db Object is locked skipped C:\Program Files\ESET\cache\CACHE.NDB Object is locked skipped C:\Program Files\ESET\cache\FND0.NFI Infected: Trojan-Downloader.Win32.INService.bl skipped C:\Program Files\ESET\cache\FND1.NFI Infected: Trojan-Downloader.Win32.Delf.bld skipped C:\Program Files\ESET\infected\2C2TFVDA.NQF Infected: not-a-virus:Porn-Dialer.Win32.PluginAccess.s skipped C:\Program Files\ESET\infected\E2MXFCBA.NQF Infected: not-a-virus:Porn-Dialer.Win32.PluginAccess.s skipped C:\Program Files\ESET\infected\EBYZ0DAA.NQF Infected: not-a-virus:Porn-Dialer.Win32.PluginAccess.s skipped C:\Program Files\ESET\infected\FPZ55NDA.NQF Infected: Backdoor.Win32.SubSeven.19 skipped C:\Program Files\ESET\infected\FVKQBPAA.NQF Infected: not-a-virus:Porn-Dialer.Win32.PluginAccess.s skipped C:\Program Files\ESET\infected\HDU2HPCA.NQF Infected: Backdoor.Win32.SubSeven.22 skipped C:\Program Files\ESET\infected\HOYQ23CA.NQF/stream/data0011 Infected: not-a-virus:AdWare.Win32.180Solutions skipped C:\Program Files\ESET\infected\HOYQ23CA.NQF/stream Infected: not-a-virus:AdWare.Win32.180Solutions skipped C:\Program Files\ESET\infected\HOYQ23CA.NQF NSIS: infected - 2 skipped C:\Program Files\ESET\infected\HOYQ23CA.NQF PE-Crypt.XorPE: infected - 2 skipped C:\Program Files\ESET\infected\MCVMF3CA.NQF Infected: Backdoor.Win32.Small.os skipped C:\Program Files\ESET\infected\NBCOESCA.NQF Infected: Trojan-Downloader.Win32.Delf.bld skipped C:\Program Files\ESET\infected\Q3CCCUBA.NQF Infected: Trojan.Win32.Dialer.oy skipped C:\Program Files\ESET\infected\RBXU0TDA.NQF Infected: Backdoor.Win32.SubSeven.21.Muie.a skipped C:\Program Files\ESET\infected\ZHX2DMBA.NQF Infected: not-a-virus:Porn-Dialer.Win32.PluginAccess.s skipped C:\Program Files\ESET\logs\virlog.dat Object is locked skipped C:\Program Files\ESET\logs\warnlog.dat Object is locked skipped C:\Program Files\FeedReader30\data\RSSENGINE.FDB Object is locked skipped C:\Program Files\mIRC\backup\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped C:\Program Files\mIRC\logs\MsgPlus\#banana.log Object is locked skipped C:\Program Files\mIRC\logs\MsgPlus\#msgplus.chat.log Object is locked skipped C:\Program Files\mIRC\logs\MsgPlus\#msgplus.fr.log Object is locked skipped C:\Program Files\mIRC\logs\MsgPlus\#msgplus.log Object is locked skipped C:\Program Files\mIRC\logs\MsgPlus\#msgplus.script.log Object is locked skipped C:\Program Files\mIRC\logs\QuakeNet\#clansjn.log Object is locked skipped C:\Program Files\mIRC\logs\QuakeNet\#perfectdarksource.log Object is locked skipped C:\Program Files\mIRC\logs\QuakeNet\#roux.log Object is locked skipped C:\Program Files\mIRC\logs\QuakeNet\#warsow.fr.log Object is locked skipped C:\Program Files\mIRC\logs\QuakeNet\powle.log Object is locked skipped C:\Program Files\mIRC\logs\QuakeNet\Sorbet.log Object is locked skipped C:\Program Files\mIRC\logs\SorceryNet\#forumdd.log Object is locked skipped C:\Program Files\mIRC\logs\SorceryNet\#t3hgeekcircle.log Object is locked skipped C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped C:\Program Files\RealVNC\VNC4\vncclipboard.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped C:\Program Files\RealVNC\WinVNC\othread2.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped C:\Program Files\RealVNC\WinVNC\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped C:\Program Files\RealVNC\WinVNC\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped C:\Program Files\Tiny Firewall Pro\Log70801_006.xml Object is locked skipped C:\Program Files\Winamp\Plugins\AudioScrobbler.log.txt Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{9E983177-BE18-47EC-887F-9274936B7892}\RP305\change.log Object is locked skipped C:\WINDOWS\CSC\000001 Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Downloaded Program Files\HDPlugin1101.dll Infected: not-a-virus:AdWare.Win32.Gator.1101 skipped C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped C:\WINDOWS\system32\config\OSession.evt Object is locked skipped C:\WINDOWS\system32\config\sam Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\security Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\hsperfdata_SYSTEM\700 Object is locked skipped C:\WINDOWS\TempFile Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped G:\Files\Programmes\BPFTP\ftpsetup.exe/data0005 Infected: not-a-virus:Server-FTP.Win32.BulletProof.221 skipped G:\Files\Programmes\BPFTP\ftpsetup.exe Inno: infected - 1 skipped G:\Files\Programmes\Edonkey\edonkey0.50.1fr.exe/data0081/UCMIE.DLL Infected: not-a-virus:AdWare.Win32.Ucmore.a skipped G:\Files\Programmes\Edonkey\edonkey0.50.1fr.exe/data0081 Infected: not-a-virus:AdWare.Win32.Ucmore.a skipped G:\Files\Programmes\Edonkey\edonkey0.50.1fr.exe NSIS: infected - 2 skipped G:\Files\Programmes\Hiren's Boot CD\Hiren86Plus.iso/System/Snad/Revelation.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped G:\Files\Programmes\Hiren's Boot CD\Hiren86Plus.iso/System/Snad/RevelationHelper.dll Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped G:\Files\Programmes\Hiren's Boot CD\Hiren86Plus.iso ISO image: infected - 2 skipped G:\Files\Programmes\MIRC\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped G:\Files\Programmes\MIRC\mirc616.exe mIRC: infected - 1 skipped G:\Files\Programmes\MIRC\mirc621.exe/stream/data0008 Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped G:\Files\Programmes\MIRC\mirc621.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped G:\Files\Programmes\MIRC\mirc621.exe NSIS: infected - 2 skipped G:\Files\Programmes\MSN\CEDP Stealer\MSN.CEDP.Stealer.2.zip/Setup.exe/data0002 Infected: Trojan-Dropper.Win32.VB.av skipped G:\Files\Programmes\MSN\CEDP Stealer\MSN.CEDP.Stealer.2.zip/Setup.exe Infected: Trojan-Dropper.Win32.VB.av skipped G:\Files\Programmes\MSN\CEDP Stealer\MSN.CEDP.Stealer.2.zip ZIP: infected - 2 skipped G:\Files\Programmes\MSN\CEDP Stealer\Setup.exe/data0002 Infected: Trojan-Dropper.Win32.VB.av skipped G:\Files\Programmes\MSN\CEDP Stealer\Setup.exe NSIS: infected - 1 skipped G:\Files\Programmes\MSN\Messenger Discovery\DiscoveryX.exe/Stream/data0001 Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\DiscoveryX.exe/Stream/data0002 Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\DiscoveryX.exe/Stream Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\DiscoveryX.exe Inno: infected - 3 skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.1.exe/Stream/data0001 Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.1.exe/Stream Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.1.exe Inno: infected - 2 skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.2.exe/Stream/data0001 Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.2.exe/Stream Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.2.exe Inno: infected - 2 skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.exe/Stream/data0001 Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.exe/Stream Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.0.exe Inno: infected - 2 skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.1.001.exe/file01 Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.1.001.exe Inno: infected - 1 skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.1.exe/file01 Infected: not-a-virus:AdWare.Win32.VB.c skipped G:\Files\Programmes\MSN\Messenger Discovery\MDX_Install_2.1.exe Inno: infected - 1 skipped G:\Files\Programmes\MSN\Messenger Plus!\Plugins\Mood Changer\MSN-Mood2-Diplsay-Pictures.zip/Install.exe/stream/data0011 Infected: not-a-virus:AdWare.Win32.180Solutions skipped G:\Files\Programmes\MSN\Messenger Plus!\Plugins\Mood Changer\MSN-Mood2-Diplsay-Pictures.zip/Install.exe/stream Infected: not-a-virus:AdWare.Win32.180Solutions skipped G:\Files\Programmes\MSN\Messenger Plus!\Plugins\Mood Changer\MSN-Mood2-Diplsay-Pictures.zip/Install.exe Infected: not-a-virus:AdWare.Win32.180Solutions skipped G:\Files\Programmes\MSN\Messenger Plus!\Plugins\Mood Changer\MSN-Mood2-Diplsay-Pictures.zip ZIP: infected - 3 skipped G:\Files\Programmes\Nero\7\7.5.9.0a\Nero-7.5.9.0A_eng.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped G:\Files\Programmes\Nero\7\7.5.9.0a\Nero-7.5.9.0A_eng.exe RAR: infected - 1 skipped G:\Files\Programmes\Vista Transformation Pack\vtp6.zip/Vista Transformation Pack 6.0.exe/WISE0030.BIN Infected: not-a-virus:RiskTool.Win32.CloseApp.a skipped G:\Files\Programmes\Vista Transformation Pack\vtp6.zip/Vista Transformation Pack 6.0.exe/WISE0053.BIN/WISE0005.BIN Infected: not-a-virus:RiskTool.Win32.CloseApp.a skipped G:\Files\Programmes\Vista Transformation Pack\vtp6.zip/Vista Transformation Pack 6.0.exe/WISE0053.BIN Infected: not-a-virus:RiskTool.Win32.CloseApp.a skipped G:\Files\Programmes\Vista Transformation Pack\vtp6.zip/Vista Transformation Pack 6.0.exe Infected: not-a-virus:RiskTool.Win32.CloseApp.a skipped G:\Files\Programmes\Vista Transformation Pack\vtp6.zip ZIP: infected - 4 skipped G:\Files\Programmes\Winamp 5\in_tv.exe/data0005 Infected: not-a-virus:NetTool.Win32.PsKill.a skipped G:\Files\Programmes\Winamp 5\in_tv.exe NSIS: infected - 1 skipped G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped I:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped J:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped J:\SystemBackup.002 Object is locked skipped J:\SystemBackup.003 Object is locked skipped J:\SystemBackup.004 Object is locked skipped J:\SystemBackup.005 Object is locked skipped J:\SystemBackup.006 Object is locked skipped J:\SystemBackup.007 Object is locked skipped J:\SystemBackup.008 Object is locked skipped J:\SystemBackup.009 Object is locked skipped J:\SystemBackup.010 Object is locked skipped J:\SystemBackup.011 Object is locked skipped J:\SystemBackup.012 Object is locked skipped J:\SystemBackup.013 Object is locked skipped J:\SystemBackup.014 Object is locked skipped J:\SystemBackup.015 Object is locked skipped J:\SystemBackup.016 Object is locked skipped J:\SystemBackup.017 Object is locked skipped J:\SystemBackup.018 Object is locked skipped J:\SystemBackup.019 Object is locked skipped J:\SystemBackup.020 Object is locked skipped J:\SystemBackup.021 Object is locked skipped J:\SystemBackup.022 Object is locked skipped J:\SystemBackup.023 Object is locked skipped J:\SystemBackup.024 Object is locked skipped J:\SystemBackup.025 Object is locked skipped J:\SystemBackup.026 Object is locked skipped J:\SystemBackup.027 Object is locked skipped J:\SystemBackup.028 Object is locked skipped J:\SystemBackup.029 Object is locked skipped J:\SystemBackup.PQI Object is locked skipped K:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped Scan process completed.
Hi Almost like that, yes :) Empty these folders: C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\ C:\Documents and Settings\Mathieu\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar C:\Program Files\ESET\cache C:\Program Files\ESET\infected Delete these: C:\Mathieu\Sites\Kings of Chaos\Progs\KoCValues v1.21.exe C:\Mathieu\Sites\Kings of Chaos\Progs\KoCValues2.zip C:\WINDOWS\Downloaded Program Files\HDPlugin1101.dll G:\Files\Programmes\Edonkey\edonkey0.50.1fr.exe G:\Files\Programmes\MSN\CEDP Stealer\ G:\Files\Programmes\MSN\Messenger Plus!\Plugins\Mood Changer\MSN-Mood2-Diplsay-Pictures.zip Empty Recycle Bin Re-scan with kaspersky Post: - a fresh HijackThis log - kaspersky report
I am sorry, I have been extremely busy with work this week. I removed the said files and I never got IE Pop-Ups since I ran the ComboFix and VundoFix. Is it absolutely necessary to rerun the Kaspersky scan? Considering I'm satisfied with the results, that it takes more than 15 hours and that I already have an up-to-date antivirus?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI