It took some time, but here is the kaspersky log. a bit long though, sorry ;-).
my pc is running fine, not slowing down or anything. and I dont get the alerts that smss.exe wants to access files. no weird popups or stuff either.
as for ths viruses kaspersky found, all the stuff seems to sit in ages old mails. i hope its just a bunch of false positives ;-)
thanks for looking this up.
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, February 20, 2008 7:42:49 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 20/02/2008
Kaspersky Anti-Virus database records: 573587
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan Statistics:
Total number of scanned objects: 472659
Number of viruses found: 5
Number of infected objects: 68
Number of suspicious objects: 0
Duration of the scan process: 04:53:44
Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Comodo\Firewall Pro\cfplogdb.sdb Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\cert8.db Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\flashgot.log Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\formhistory.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\history.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\key3.db Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\parent.lock Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\search.sqlite Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\urlclassifier2.sqlite Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 + … /[From "Strongest Strongest" <[removed]>][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Anwendungsdaten\Thunderbird\Profiles\fniz1bkl.default\Mail\Local Folders\9-AWA.sbd\Office Mail Berkeley mbox: infected - 8 skipped
C:\Dokumente und Einstellungen\Severus\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 + … /[From "Strongest Strongest" <[removed]>][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
C:\Dokumente und Einstellungen\Severus\Desktop\Mail\Local Folders\9-AWA.sbd\Office Mail Berkeley mbox: infected - 8 skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\Cache\_CACHE_001_ Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\Cache\_CACHE_002_ Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\Cache\_CACHE_003_ Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\5y96usga.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\Lokale Einstellungen\Verlauf\History.IE5\MSHist012008022020080221\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\Severus\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\Severus\NTUSER.DAT.LOG Object is locked skipped
C:\Programme\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Programme\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Programme\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Programme\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Programme\Cobian Backup 8\DB\log.txt Object is locked skipped
C:\Programme\Super Fast Shutdown\shutdown.exe Infected: not-a-virus:RiskTool.Win32.Shutdown.c skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_630.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
E:\lager\programme\burntools\nero_6009_+_serial_+_German___Nero6___Nero_Version_6009\Nero-6.6.1.15a.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\lager\programme\burntools\nero_6009_+_serial_+_German___Nero6___Nero_Version_6009\Nero-6.6.1.15a.exe RAR: infected - 1 skipped
E:\lager\programme\fp2006-final-3.00-setup.exe/file1626 Infected: not-virus:BadJoke.JS.RJump skipped
E:\lager\programme\fp2006-final-3.00-setup.exe Inno: infected - 1 skipped
E:\lager\programme\superfast.zip/setup.exe/file1 Infected: not-a-virus:RiskTool.Win32.Shutdown.c skipped
E:\lager\programme\superfast.zip/setup.exe Infected: not-a-virus:RiskTool.Win32.Shutdown.c skipped
E:\lager\programme\superfast.zip ZIP: infected - 2 skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>] … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 + … /[From "Strongest Strongest" <[removed]>][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
E:\RECYCLER\S-1-5-21-1614895754-1958367476-682003330-1004\De1\v9dtqdnq.default\Mail\Local Folders\9-AWA.sbd\Office Mail Berkeley mbox: infected - 8 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001447.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001448.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001449.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001450.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001451.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001452.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001453.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP29\A0001454.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001463.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001464.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001465.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001466.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001467.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001468.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001469.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001470.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001471.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001472.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001473.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001474.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001475.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001476.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001477.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001478.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001479.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001480.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001481.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001482.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001483.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001484.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP30\A0001485.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001493.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001494.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001495.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001496.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001497.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001498.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001499.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001500.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001501.ocx Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001502.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001503.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001504.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001505.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001506.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP31\A0001507.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001551.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001552.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001553.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001554.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001555.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001556.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001557.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001558.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001559.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001560.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001561.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001562.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001563.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001564.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001565.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001566.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001567.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001568.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001569.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001570.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001571.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001572.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001573.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001574.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001575.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001576.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001577.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001578.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001579.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001580.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001581.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001582.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001583.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001584.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001585.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001586.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001587.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001588.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001589.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001590.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001591.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001592.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001593.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001594.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001595.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001596.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001597.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001598.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001599.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001600.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001601.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001602.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001603.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001604.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001605.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001606.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP32\A0001607.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001616.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001617.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001618.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001619.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001620.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001621.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001622.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001623.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001624.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001625.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001626.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001627.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001628.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001629.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001630.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001631.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001632.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001633.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001634.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001635.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001636.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001637.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001638.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001639.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP33\A0001640.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001683.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001684.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001685.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001686.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001687.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001688.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001689.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001690.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001691.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001692.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001693.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001694.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001695.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001696.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001697.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001698.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001699.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001700.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001701.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001702.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001703.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001704.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001705.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001706.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001707.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001708.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001709.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001710.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP37\A0001711.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001718.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001719.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001720.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001721.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001722.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001723.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001724.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001725.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001726.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001727.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001728.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001729.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001730.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001731.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001732.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001733.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001734.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001735.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001736.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001737.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001738.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001739.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001740.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001741.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001742.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001743.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001744.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP38\A0001745.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001790.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001791.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001792.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001793.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001794.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001795.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001796.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001797.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001798.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001799.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001800.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001801.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001802.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001803.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001804.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001805.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001806.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001807.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001808.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001809.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001810.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001811.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP41\A0001812.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002600.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002601.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002602.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002603.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002604.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002605.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002606.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002607.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002608.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002609.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002610.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP48\A0002611.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP50\A0002906.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003619.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003620.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003621.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003622.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003623.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003624.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003625.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003626.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003627.ver Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003628.inf Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003629.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003630.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003631.cat Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003632.exe Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003633.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003634.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003635.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003636.dll Object is locked skipped
E:\System Volume Information\_restore{6E85B232-3A70-4269-A2C0-304E2C6E559D}\RP55\A0003637.cat Object is locked skipped
E:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
E:\trenzterratornado\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
E:\trenzterratornado\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
E:\Windrop\LamestBot.chan Object is locked skipped
E:\Windrop\LamestBot.notes Object is locked skipped
E:\Windrop\Lord_Voldebot.user Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{99ABE7E1-5A1B-4047-AAD3-1D3D1193AD6A}\RP176\change.log Object is locked skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" ][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-08 02;11;20.zip ZIP: infected - 9 skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" ][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-10 21;30;43.zip ZIP: infected - 9 skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Da … /Rechnung_Sign177138535545553187871.pdf.exe Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directl … /[From "Arkangel" <[removed]>][Date Tue, 24 Apr 2007 20:07:12 +0200]/Rechnung.zip Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 ( … /[From RBL: SORBS: sent directly from dynamic IP address * [[removed]][Date Sat, 20 Jan 2007 14:29:38 +0100]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" ][Date Thu, 05 Oct 2006 21:58:43 +0200]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text/[From "Cerberus" <[removed]>][Date Sun, 1 Oct 2006 19:51:17 +0200]/html Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc/[From [removed]#D4D0C8][Date Mon, 15 Aug 2005 22:46:33 +0200 (CEST)]/text Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:54:27 +0200]/ronnielw.doc Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office/[From "Mr Myers, AWA President" <[removed]>][Date Thu, 4 Aug 2005 00:43:51 +0200]/ronnielw.odt Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip/fniz1bkl.default/Mail/Local Folders/9-AWA.sbd/Office Infected: Trojan-Downloader.Win32.Nurech.bi skipped
G:\thunderbirdbackup\Profiles 2008-02-17 21;30;38.zip ZIP: infected - 9 skipped
Scan process completed.
—————————————————————
and here's the Hijack This logfile.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:44:45, on 20.02.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
C:\Programme\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Cobian Backup 8\cbInterface.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programme\Comodo\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Wallperizer\Wallperizer.exe
C:\Programme\a-squared Free\a2service.exe
C:\Programme\Comodo\Firewall\cmdagent.exe
C:\Programme\Cobian Backup 8\cbService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
C:\Programme\Alwil Software\Avast4\ashWebSv.exe
C:\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Programme\Cobian Backup 8\cbInterface.exe" -service
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Programme\Comodo\Firewall\cfp.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Wallperizer.lnk = C:\Wallperizer\Wallperizer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1193570037906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1195995401562
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programme\a-squared Free\a2service.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programme\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Programme\Comodo\Firewall\cmdagent.exe
O23 - Service: Cobian Backup 8 Service (CobBMService) - Luis Cobian - C:\Programme\Cobian Backup 8\cbService.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Programme\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
–
End of file - 5870 bytes