Thank u for the help so far my computer is starting to work much better now
heres the reports u requested
New HJT Log::
Logfile of HijackThis v1.99.1
Scan saved at 9:57:23 PM, on 3/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\svchost.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Anubis\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Add To Compaq Organize… - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
new combo fix log::
ComboFix 08-03-10.1 - Anubis 2008-03-13 18:08:00.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Anubis\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\Fonts\apun.tmp
C:\WINDOWS\repair\blips.bak1
C:\WINDOWS\repair\blips.bak2
C:\WINDOWS\repair\blips.ini2
C:\WINDOWS\system32\cdgrymnb.ini
C:\WINDOWS\system32\clthuuit.ini
C:\WINDOWS\system32\draopbdk.ini
C:\WINDOWS\system32\eijbwxmk.ini
C:\WINDOWS\system32\iaguxmph.ini
C:\WINDOWS\system32\ovwkcwvl.ini
C:\WINDOWS\system32\qsbyoyaa.ini
C:\WINDOWS\system32\tnpanycr.ini
C:\WINDOWS\system32\wghmnstb.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Anubis\Application Data\inst.exe
C:\WINDOWS\Fonts\apun.tmp
C:\WINDOWS\repair\blips.bak1
C:\WINDOWS\repair\blips.bak2
C:\WINDOWS\repair\blips.ini2
C:\WINDOWS\system32\cdgrymnb.ini
C:\WINDOWS\system32\clthuuit.ini
C:\WINDOWS\system32\draopbdk.ini
C:\WINDOWS\system32\eijbwxmk.ini
C:\WINDOWS\system32\iaguxmph.ini
C:\WINDOWS\system32\ovwkcwvl.ini
C:\WINDOWS\system32\qsbyoyaa.ini
C:\WINDOWS\system32\tnpanycr.ini
C:\WINDOWS\system32\wghmnstb.ini
L:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-02-13 to 2008-03-13 )))))))))))))))))))))))))))))))
.
2008-03-12 22:50 . 2008-03-12 22:52 d——– C:\Program Files\Windows Live
2008-03-10 10:44 . 2008-03-10 10:44 16,384 –a—— C:\WINDOWS\~DFF829.tmp
2008-03-07 12:09 . 2008-03-07 12:16 d——– C:\Program Files\CA Yahoo! Anti-Spy
2008-02-28 00:41 . 2008-02-28 00:41 d——– C:\Documents and Settings\Anubis\Application Data\Malwarebytes
2008-02-28 00:40 . 2008-03-09 20:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-28 00:40 . 2008-02-28 00:40 d——– C:\Program Files\Common Files\Download Manager
2008-02-28 00:40 . 2008-02-28 00:40 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-28 00:00 . 2004-08-04 00:10 10,880 –a—— C:\WINDOWS\system32\drivers\NdisIP.sys
2008-02-28 00:00 . 2004-08-04 00:10 10,880 –a–c— C:\WINDOWS\system32\dllcache\ndisip.sys
2008-02-28 00:00 . 2004-08-03 23:58 5,504 –a—— C:\WINDOWS\system32\drivers\MSTEE.sys
2008-02-28 00:00 . 2004-08-03 23:58 5,504 –a–c— C:\WINDOWS\system32\dllcache\mstee.sys
2008-02-27 23:57 . 2004-08-04 01:56 90,624 –a—— C:\WINDOWS\system32\kswdmcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 90,624 –a–c— C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 61,952 –a—— C:\WINDOWS\system32\kstvtune.ax
2008-02-27 23:57 . 2004-08-04 01:56 61,952 –a–c— C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-02-27 23:57 . 2004-08-04 01:56 53,760 –a—— C:\WINDOWS\system32\vfwwdm32.dll
2008-02-27 23:57 . 2004-08-04 01:56 53,760 –a–c— C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-02-27 23:57 . 2004-08-04 01:56 43,008 –a—— C:\WINDOWS\system32\ksxbar.ax
2008-02-27 23:57 . 2004-08-04 01:56 43,008 –a–c— C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-02-27 23:57 . 2004-08-04 01:56 28,672 –a—— C:\WINDOWS\system32\vidcap.ax
2008-02-27 23:57 . 2004-08-04 01:56 28,672 –a–c— C:\WINDOWS\system32\dllcache\vidcap.ax
2008-02-27 23:49 . 2008-02-27 23:49 d——– C:\Program Files\PC Camer@
2008-02-27 23:49 . 2006-11-03 10:59 48,128 –a—— C:\WINDOWS\system32\Remove.exe
2008-02-27 23:49 . 2007-02-12 01:06 408 –a—— C:\WINDOWS\system32\Remover.ini
2008-02-27 13:20 . 2008-02-27 13:20 d—s—- C:\Documents and Settings\Guest.ANUBISZRO\UserData
2008-02-27 09:08 . 2008-03-13 15:07 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-27 09:08 . 2008-02-27 09:08 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-26 23:38 . 2008-02-26 23:38 d——– C:\Documents and Settings\Anubis\Application Data\ATI MMC
2008-02-24 15:14 . 2008-01-12 19:32 23,904 –a—— C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-02-24 15:14 . 2008-01-15 10:54 10,537 –a—— C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-24 15:14 . 2008-01-15 06:28 706 –a—— C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-02-24 15:04 . 2008-02-24 15:04 16 –a—— C:\WINDOWS\system32\coh.cache
2008-02-24 14:46 . 2008-02-24 15:02 123,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-24 14:46 . 2008-02-24 15:02 60,800 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-24 14:46 . 2008-02-24 15:02 10,740 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-24 14:46 . 2008-02-24 15:02 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-24 14:35 . 2008-02-24 14:35 d——– C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
2008-02-18 23:33 . 2004-08-03 23:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-02-18 23:33 . 2004-08-03 23:58 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-02-16 13:09 . 2008-02-16 13:09 230 –a—— C:\WINDOWS\system32\spupdsvc.inf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-13 22:12 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Azureus
2008-03-13 02:53 ——— d—–w C:\Program Files\MSN Messenger
2008-03-13 02:50 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-13 02:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-13 01:47 ——— d—–w C:\Program Files\Viewpoint
2008-03-13 01:47 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Viewpoint
2008-03-13 01:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-13 00:34 ——— d—–w C:\Documents and Settings\Anubis\Application Data\U3
2008-03-12 23:51 ——— d—–w C:\Documents and Settings\Anubis\Application Data\WeatherBug
2008-03-10 14:44 16,384 —-a-w C:\WINDOWS\~DFF829.tmp
2008-03-10 00:21 ——— d—–w C:\Program Files\Java
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Vso
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\vlc
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Symantec
2008-03-09 06:23 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Sonic
2008-03-09 06:20 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Intervideo
2008-03-09 06:20 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Apple Computer
2008-03-07 03:22 ——— d—–w C:\Program Files\Azureus
2008-02-28 22:14 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Symantec
2008-02-28 05:19 ——— d—–w C:\Program Files\Yahoo!
2008-02-28 05:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-02-28 03:49 ——— d—–w C:\Program Files\Common Files\PAC207
2008-02-27 17:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-27 17:16 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Yahoo!
2008-02-27 13:07 ——— d—–w C:\Program Files\iTunes
2008-02-27 13:07 ——— d—–w C:\Program Files\iPod
2008-02-27 13:04 ——— d—–w C:\Program Files\QuickTime
2008-02-27 03:38 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2008-02-24 19:02 ——— d—–w C:\Program Files\Symantec
2008-02-24 18:53 ——— d—–w C:\Program Files\Norton 360
2008-02-13 06:31 ——— d—–w C:\Program Files\AIM6
2008-02-13 06:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-13 06:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-02-12 18:47 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-12 16:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-12 04:47 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-12 04:10 ——— d—–w C:\Program Files\YourWare Solutions
2008-02-09 01:55 68,160 —-a-w C:\WINDOWS\system32\keihglax.dll
2008-02-08 17:03 ——— d—–w C:\Documents and Settings\Anubis\Application Data\LimeWire
2008-02-05 03:12 68,672 —-a-w C:\WINDOWS\system32\fypduxfc.dll
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\MySpace
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\Logitech
2008-01-30 03:55 ——— d—–w C:\Documents and Settings\Guest.ANUBISZRO\Application Data\ATI
2008-01-27 22:16 8,587 —-a-w C:\WINDOWS\system32\hvmoelbd.dll
2008-01-26 22:09 68,160 —-a-w C:\WINDOWS\system32\ncnttkey.dll
2008-01-24 21:47 8,587 —-a-w C:\WINDOWS\system32\tmhvwkif.dll
2008-01-23 21:41 68,672 —-a-w C:\WINDOWS\system32\qrfpulxo.dll
2008-01-20 02:32 69,696 —-a-w C:\WINDOWS\system32\frtvqggc.dll
2008-01-19 02:19 69,696 —-a-w C:\WINDOWS\system32\jjuixibv.dll
2008-01-19 02:16 43,435 —-a-w C:\WINDOWS\system32\ewhicggk.dll
2008-01-16 16:31 8,587 —-a-w C:\WINDOWS\system32\bgcrwdwj.dll
2008-01-14 02:11 ——— d—–w C:\Documents and Settings\Anubis\Application Data\Yahoo!
2008-01-11 03:58 65,215 —-a-w C:\WINDOWS\system32\ilehnjit.dll
2007-12-28 21:40 1,031,259 –sha-w C:\WINDOWS\system32\sskdwgxk.tmp
2007-12-16 06:13 47,360 —-a-w C:\Documents and Settings\Anubis\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((( snapshot@2008-03-12_23.18.09.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-02-14 14:19:45 12,288 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-03-13 15:16:11 12,288 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-02-14 14:19:45 135,168 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-03-13 15:16:11 135,168 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-02-14 14:19:45 11,264 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-03-13 15:16:11 11,264 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-02-14 14:19:45 27,136 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-03-13 15:16:11 27,136 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-02-14 14:19:45 4,096 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-03-13 15:16:11 4,096 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-02-14 14:19:45 794,624 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-03-13 15:16:11 794,624 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-02-14 14:19:45 249,856 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-03-13 15:16:11 249,856 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-02-14 14:19:46 23,040 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-03-13 15:16:11 23,040 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-02-14 14:19:45 286,720 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-03-13 15:16:11 286,720 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-02-14 14:19:45 409,600 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-03-13 15:16:10 409,600 —-a-r C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-02-04 23:09:46 18,214,008 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2008-03-05 16:30:54 19,148,408 —-a-w C:\WINDOWS\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 17:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 12:15 50528]
"ATI Launchpad"="" []
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 18:43 4670704]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 03:33 8720384]
"FreeRAM XP"="C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 01:13 1591808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 11:01 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-22 01:31 180269]
"Home Theater SchSvr"="C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2004-09-23 13:22 106496]
"WINREMOTE"="C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" [2004-10-01 03:18 192512]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 23:43 233472]
"VTTimer"="VTTimer.exe" []
"SoundMan"="SOUNDMAN.EXE" [2004-07-29 03:40 77824 C:\WINDOWS\SOUNDMAN.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13 98304]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-29 04:34 2551808 C:\WINDOWS\ALCWZRD.EXE]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 00:54 253952]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 22:10 339968]
"ATI DeviceDetect"="C:\Program Files\ATI Multimedia\main\ATIDtct.EXE" [2004-06-15 23:17 69705]
"HydraVisionDesktopManager"="C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 22:00 270336]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 19:30 517768]
"LWBKEYBOARD"="C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe" [2004-05-26 22:37 392704]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 16:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 16:01 169264]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 01:59 115816]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 03:33 8720384]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-30 14:54:09 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
R0 iteraid;ITERAID_Service_Install;C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-06-01 14:19]
R2 Maxtor Sync Service;Maxtor Service;"C:\Program Files\Maxtor\Sync\SyncServices.exe" [2007-07-13 16:02]
R3 PAC207;PC Camer@;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-06-12 12:39]
S3 cpqdiag;Compaq Diagnostics;C:\WINDOWS\system32\drivers\cpqdiag.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1bcc9a4-a4dd-11dc-aeec-0011d825a186}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-27 12:51:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-26 19:04:01 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-13 18:12:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-13 18:13:34
ComboFix-quarantined-files.txt 2008-03-13 22:13:30
ComboFix2.txt 2008-03-13 03:18:30
.
2008-03-13 15:17:29 — E O F —
Kaspersky report::
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, March 13, 2008 9:53:41 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 13/03/2008
Kaspersky Anti-Virus database records: 628423
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\
Scan Statistics:
Total number of scanned objects: 133183
Number of viruses found: 14
Number of infected objects: 175
Number of suspicious objects: 0
Duration of the scan process: 02:27:57
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b4e8e379a5fd6f8a3d49cac609cd7c6_de17b053-1a2f-4196-af5d-40229baf0926 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\56CB47A6.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\ABB24084.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\acccore\nss\cert8.db Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\acccore\nss\key3.db Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\Logs\MySpaceIM-20080313-183926.log Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\index2.dat Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\profile256.dbb Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\user1024.dbb Object is locked skipped
C:\Documents and Settings\Anubis\Application Data\MySpace\IM\SkypeCache\myspace#3afallengodres\user256.dbb Object is locked skipped
C:\Documents and Settings\Anubis\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\data\anubitron\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\data\fallengodres\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\data\purgatoryzro\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\AOL OCP\AIM\Storage\data\tronicx3\localStorage\common.cls Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_4204_A181_4A1_7895\dfsr.db Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_4204_A181_4A1_7895\fsr.log Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_4204_A181_4A1_7895\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_4204_A181_4A1_7895\tmp.edb Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\real\members.stg Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Mozilla\Firefox\Profiles\k33kcsh3.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Mozilla\Firefox\Profiles\k33kcsh3.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Mozilla\Firefox\Profiles\k33kcsh3.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Application Data\Mozilla\Firefox\Profiles\k33kcsh3.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\History\History.IE5\MSHist012008031320080314\index.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\Perflib_Perfdata_8c8.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\Perflib_Perfdata_d2c.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\Perflib_Perfdata_e90.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\Perflib_Perfdata_e98.dat Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DF4C11.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DF4C2C.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DF694C.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DF6985.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temp\~DFE6D3.tmp Object is locked skipped
C:\Documents and Settings\Anubis\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Anubis\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Anubis\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\97TFVK94\index[1].htm Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\InstallShield Installation Information\{639858DD-4966-40F3-A706-7C838BCF3A2B}\setup.ilg Object is locked skipped
C:\Program Files\Norton 360\Log\AutoProtect.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVContext.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVManual.log Object is locked skipped
C:\Program Files\Norton 360\Log\Backup.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetPageViewHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetSearchHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUWindowsTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\EmailScan.log Object is locked skipped
C:\Program Files\Norton 360\Log\InternetSecurity.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIntrusionPrevented.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIOTraffic.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISNewNetwork.log Object is locked skipped
C:\Program Files\Norton 360\Log\LiveUpdate.log Object is locked skipped
C:\Program Files\Norton 360\Log\NCO.log Object is locked skipped
C:\Program Files\Norton 360\Log\VABrowserSettings.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAIPAddresses.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAWeakPasswords.log Object is locked skipped
C:\Program Files\Norton 360\Log\WDFScanner.log Object is locked skipped
C:\Program Files\pspvideo9\settings.xml Object is locked skipped
C:\Program Files\VideoraiPodConverter\settings.xml Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\20060419005503.zip Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\.NetworkShare\LimeWirePackedJars4.10.0.7z Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\.NetworkShare\LimeWireWin4.10.0.exe Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\clink.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\commons-httpclient.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\commons-logging.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\commons-net.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\COPYING Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\daap.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\data.ser Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\donotremove.htm Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\GenericWindowsUtils.dll Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\hashes Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\i18n.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\icu4j.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\id3v2.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\install.log Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\jcraft.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\jl011.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\jmdns.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\language.prop Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire On Startup.lnk Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire.exe Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire.ico Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\LimeWire20.dll Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\log.txt Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\log4j.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\log4j.properties Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\logicrypto.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\looks.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\MessagesBundle.properties Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\MessagesBundles.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\mp3sp14.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\pmf.ico Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\ProgressTabs.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\badge.img Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\canHandle.img Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\limewire.gif Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\options.js Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\root\magnet10\silentdetect.js Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\SOURCE Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\spacer.gif Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\themes.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\tritonus.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\uninstall.exe Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\unpack.log Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\update.ver Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\vorbis.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\WindowsV5PlusUtils.dll Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\xerces.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\xml-apis.jar Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp\xml.war Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq53.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq55.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq57.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq58.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq59.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq60.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq61.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq62.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq63.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq64.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq65.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq66.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq67.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq68.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq69.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq70.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq71.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq72.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq73.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq74.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq75.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq76.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq77.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq78.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq79.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq80.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq81.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq82.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq83.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq84.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq85.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq86.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq87.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq88.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq89.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq90.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq91.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq92.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq93.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq94.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq95.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq96.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq97.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq98.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq99.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9A.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9B.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9C.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9D.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9E.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9F.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA0.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA1.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA2.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA3.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA4.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA5.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA6.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA7.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA8.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA9.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAA.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAB.tmp Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqdb.dat Object is locked skipped
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqsdb.dat Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\aabalpwd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\awxqigpo.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\cimmfwfi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\dmcgkrlt.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\fexgtiik.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\geuvpbky.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gwevrvnr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ikutnvvf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ipjoitxm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\iwsdvijd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\kvfivynu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\lxpulnmo.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mchynumc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mcrshphp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mfkneixp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\npsovohs.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\olgbfjph.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\otvhdgcc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\qhmjbtyq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\rotukqse.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\sdxojgfj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\serlaiqb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ixf skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tbxmgdob.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tnvlnqwn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tsypfqma.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tyujbpfb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\uylkiban.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vmbsqqqw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wfbdbydp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wjitgumn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ydjkprhx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\yvdqxjwf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc1.mp3 Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc10.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc11.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc12.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc13.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc14.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc15.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc16.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc17.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc18.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc19.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc2.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc20.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc21.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc22.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc23.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc24.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc25.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc26.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc27.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc28.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc29.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc3.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc30.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc31.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc32.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc33.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc34.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc35.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc36.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc37.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc38.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc39.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\001.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\002.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\003.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\004.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\005.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\006.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\007.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\008.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\009.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\010.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\011.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\012.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\013.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\014.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\015.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\016.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc4\leilene\Thumbs.db Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc40.rar Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc41.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc42.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc43.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc44.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc45.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc46.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\13825097_22509.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\2-2125134-5j.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\44928432_41487.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\45831737_39423.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\47579723_50591.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\50931872_95152.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\120x600-nsfw-2_data\piclist Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\2-2125134-2j.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\001.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\004.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\008.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\009.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\011.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\button_search_now_150_english.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\header.css Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\728x90-2_data\iframead_18_data\logo_195x40.gif Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\counter.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\head.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\help.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\logo.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\main.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\spacer.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\spacer_002.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\spacer_003.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\style.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\trans.htm Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc47.php_files\__utm.js Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc48.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc49.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Happy Birthday Mangahelpers!.png Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Kylara is in need!.png Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_01.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_02.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_03.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_04.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_05.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_06.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_07.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_08.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_09.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_10.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_11.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_12.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_13.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_14.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_15.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_16.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Naruto_378_17.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc5\Thumbs.db Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc50.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc51.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc52.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc53.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc54.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc55.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc6.exe Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc7.zip Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc8.torrent Object is locked skipped
C:\RECYCLER\S-1-5-21-3022673224-1995523515-2157904700-1009\Dc9.rar Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP49\A0019637.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP49\A0019679.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP49\A0019681.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP50\A0019709.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020294.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020296.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020297.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020301.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020302.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020303.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020304.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.is skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020305.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020306.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020307.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020308.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP55\A0020312.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP56\A0020542.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP58\A0020724.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP58\A0020925.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP58\A0021972.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP59\A0022041.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP59\A0022076.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP59\A0022204.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP60\A0022348.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.eby skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP60\A0022401.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP61\A0022521.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP62\A0022585.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.edw skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP63\A0022646.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP63\A0022701.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP63\A0022747.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP63\A0022749.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP64\A0022776.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP64\A0022777.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP64\A0022826.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022844.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022871.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.byl skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022873.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022874.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022875.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022876.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022877.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0022878.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0023848.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.byl skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP65\A0023853.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.byl skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP66\A0023904.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0024988.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025015.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025016.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025017.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025019.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP67\A0025102.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP68\A0025175.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP68\A0025178.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP68\A0025185.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP68\A0025259.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP69\A0025367.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP70\A0025502.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026585.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026586.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026587.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026588.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026589.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026590.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026595.DLL Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026596.EXE Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0026597.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ao skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027556.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027598.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027599.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027600.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027601.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027602.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027603.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027604.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027664.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027664.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027667.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP71\A0027668.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP73\A0028152.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP73\A0028170.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP73\A0028173.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP74\A0028437.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP75\A0028670.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP76\A0029726.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP76\A0029727.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP76\A0029759.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP77\A0029812.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP78\A0029881.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP79\A0029943.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ixe skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP79\A0030544.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bce skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP81\A0030595.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP81\A0030632.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP82\A0031032.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP85\A0032414.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP94\A0032952.exe Infected: not-a-virus:Downloader.Win32.Keylogger.a skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP94\A0032980.EXE/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP94\A0032980.EXE WiseSFX: infected - 1 skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP94\A0032980.EXE WiseSFXDropper: infected - 1 skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033074.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033075.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033076.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033077.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033078.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033079.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033080.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033081.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033082.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033083.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033084.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033085.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033086.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033087.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033088.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033089.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033090.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033091.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033092.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033093.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033094.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033095.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ixf skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033096.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033097.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033098.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033099.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033100.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033101.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033102.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033103.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033104.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP97\A0033105.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP99\change.log Object is locked skipped
C:\USERDATA\Application Data\Symantec\Cleanup\cuUser.cfg Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{9850296E-CA74-4AC1-B6C4-BFC5C97BA9C8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\bgcrwdwj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\ewhicggk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\frtvqggc.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\fypduxfc.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hvmoelbd.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.kp skipped
C:\WINDOWS\system32\ilehnjit.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\jjuixibv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\keihglax.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\ncnttkey.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\qrfpulxo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\tmhvwkif.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\cc1A.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1B.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1C.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1D.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1E.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc1F.tmp Object is locked skipped
C:\WINDOWS\TEMP\cc20.tmp Object is locked skipped
C:\WINDOWS\TEMP\JET713F.tmp Object is locked skipped
C:\WINDOWS\TEMP\JET721A.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP99\change.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP99\change.log Object is locked skipped
L:\0\0\Lost Files\Recovered_JPEG_327.jpg Infected: Trojan-Downloader.Win32.Agent.gwe skipped
L:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
L:\System Volume Information\_restore{36EC0028-8B85-4538-BB29-A461B426C5A6}\RP99\change.log Object is locked skipped
Scan process completed.
scan reults for the 2 files::
C:\Documents and Settings\Anubis\Application Data\inst.exe
Scanner results
Scan taken on 13 Mar 2008 21:42:58 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
C:\WINDOWS\Fonts\apun.tmp
Scanner results
Scan taken on 13 Mar 2008 21:56:28 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing