nycste Posted September 12, 2007 Author Posted September 12, 2007 Logfile of Spyware Terminator v2.0.0.194 (db:1.0.924.684)Scan Time: 9/12/2007 12:37:57 AM length: 2540 sPlatform: Windows XP Service Pack 2 (WINNT 5.1.2600)User: AdminBoot Mode: NormalScan type: Full_Spyware_ScanScanned Objects: 160910 (Critical:0)Filter: No System items, No Safe items, No Invalid itemsRunning Processes : nvsvc32.exe [NVIDIA Corporation] : C:\WINDOWS\system32\nvsvc32.exepidgin.exe [The Pidgin developer community] : C:\Program Files\Pidgin\pidgin.exeConvertXtoDvd.exe [VSO Software SARL] : C:\Program Files\vso\ConvertXtoDVD\ConvertXtoDvd.exeSpybotSD.exe [safer Networking Limited] : C:\Program Files\Spybot - Search & Destroy\SpybotSD.exeInternet SettingsR - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=homeR - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htmR - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htmR - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain = R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName = BHO02 - BHO: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - [Orbitdownloader.com] : C:\Program Files\Orbitdownloader\orbitcth.dllStartUps04 - HKLM\System\CurrentControlSet\Control\Session Manager, BootExecute : : C:\WINDOWS\system32\UDBDEF.EXEShell Extensions7-Zip Shell Extension - {23170F69-40C1-278A-1000-000100020000} - [igor Pavlov] : C:\Program Files\7-Zip\7-zip.dllAlcoholShellEx - {32020A01-506E-484D-A2A8-BE3CF17601C3} - [Alcohol Soft Development Team] : C:\Program Files\Alcohol Soft\Alcohol 120\AXShlEx.dllMicrosoft Office Outlook - {00020D75-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Program Files\Microsoft Office\OFFICE11\MLSHEXT.DLLOutlook File Icon Extension - {0006F045-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Program Files\Microsoft Office\OFFICE11\OLKFSTUB.DLL - {42042206-2D85-11D3-8CFF-005004838597} - [Microsoft Corporation] : C:\Program Files\Microsoft Office\OFFICE11\msohev.dllWinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} - : C:\Program Files\WinRAR\rarext.dllUnlockerShellExtension - {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} - : C:\Program Files\Unlocker\UnlockerCOM.dllDesktop Manager - {709C6E11-538F-4759-86AC-6ACB302AA0DE} - : C:\WINDOWS\system32\msvdm.dllShell Extension for Malware scanning - {45AC2688-0253-4ED8-97DE-B5370FA7D48A} - [Avira GmbH] : C:\Program Files\Avira\AntiVir PersonalEdition Premium\shlext.dllDesktop Explorer - {1CDB2949-8F65-4355-8456-263E7C208A5D} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll - {1E9B04FB-F9E5-4718-997B-B8DA88302A47} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dllnView Desktop Context Menu - {1E9B04FB-F9E5-4718-997B-B8DA88302A48} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dllAVG7 Shell Extension Class - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dllAVG7 Find Extension Class - {9F97547E-460A-42C5-AE0C-81C61FFAEBC3} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dllProtocol Filters - {807553E5-5146-11D5-A672-00B0D022E945} - [Microsoft Corporation] : C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLLProtocol HandlerData Page Pluggable Protocol mso-offdap Handler - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - [Microsoft Corporation] : C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLLData Page Plugable Protocal mso-offdap11 Handler - {32505114-5902-49B2-880A-1F7738E5A384} - [Microsoft Corporation] : C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLLIEProtocolHandler Class - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - [skype Technologies] : C:\Program Files\Common Files\Skype\Skype4COM.dllWinsock 2 [Avira GmbH] : C:\WINDOWS\system32\avsda.dll [Avira GmbH] : C:\WINDOWS\system32\avsda.dll [Avira GmbH] : C:\WINDOWS\system32\avsda.dllServices23 - : C:\WINDOWS\system32\DRIVERS\a347bus.sys23 - : C:\WINDOWS\system32\Drivers\a347scsi.sys23 - : C:\Program Files\GRISOFT\AVG ANTI-SPYWARE 7.5\GUARD.SYS23 - : C:\Program Files\GRISOFT\AVG ANTI-SPYWARE 7.5\GUARD.SYS23 - : C:\Program Files\GRISOFT\AVG ANTI-SPYWARE 7.5\GUARD.SYS23 - : C:\Program Files\GRISOFT\AVG ANTI-SPYWARE 7.5\GUARD.SYS23 - : C:\Program Files\GRISOFT\AVG ANTI-SPYWARE 7.5\GUARD.SYS23 - [GRISOFT, s.r.o.] : C:\WINDOWS\system32\DRIVERS\AvgAsCln.sys23 - [GRISOFT, s.r.o.] : C:\WINDOWS\system32\DRIVERS\AvgAsCln.sys23 - [GRISOFT, s.r.o.] : C:\WINDOWS\system32\DRIVERS\AvgAsCln.sys23 - [Elaborate Bytes AG] : C:\WINDOWS\system32\Drivers\ElbyCDIO.sys23 - : C:\WINDOWS\system32\giveio.sys23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\RtkHDAud.sys23 - [Kensington Technology Group] : C:\WINDOWS\system32\drivers\KID_SYS.sys23 - [Kensington Technology Group] : C:\WINDOWS\system32\drivers\ntxpusb.sys23 - [NVIDIA Corporation] : C:\WINDOWS\system32\nvsvc32.exe23 - : C:\WINDOWS\system32\DRIVERS\OREANS32.SYS23 - [VSO Software] : C:\WINDOWS\system32\Drivers\pcouffin.sys23 - [Elaborate Bytes] : C:\WINDOWS\system32\Drivers\RegKill.sys23 - : C:\Program Files\SUPERANTISPYWARE\SASDIFSV.SYS23 - : C:\Program Files\SUPERANTISPYWARE\SASKUTIL.SYS23 - [Windows ® 2000 DDK provider] : C:\WINDOWS\system32\speedfan.sys23 - [sygate Technologies, Inc.] : C:\WINDOWS\system32\Drivers\Teefer.sys23 - [sygate Technologies, Inc.] : C:\WINDOWS\system32\Drivers\wg3n.sys23 - [sygate Technologies, Inc.] : C:\WINDOWS\system32\Drivers\wg4n.sys23 - [sygate Technologies, Inc.] : C:\WINDOWS\system32\Drivers\wg5n.sys23 - [sygate Technologies, Inc.] : C:\WINDOWS\system32\Drivers\wg6n.sys23 - [sygate Technologies, Inc.] : C:\WINDOWS\system32\DRIVERS\WPSDRVNT.SYS23 - [Marvell] : C:\WINDOWS\system32\DRIVERS\yk51x86.sys23 - [EnTech Taiwan] : C:\WINDOWS\system32\DRIVERS\TVICHW32.SYSWinlogon NotifyHKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon, DLLName : [sUPERAntiSpyware.com] : C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
nycste Posted September 12, 2007 Author Posted September 12, 2007 humm program GodZBSY.exe is running for some reason and google shows up nothing
Tarun Posted September 12, 2007 Posted September 12, 2007 Do all of the scans from the sticky list posted in this thread in Safe Mode. Then boot back into Normal Mode, run HijackThis and post a log.
nycste Posted September 12, 2007 Author Posted September 12, 2007 Do all of the scans from the sticky link posted in this thread in Safe Mode. Then boot back into Normal Mode, run HijackThis and post a log.will do later thanks.[q]Originally posted by: JohnUpload it to virustotal.com to see if it's detected.[/q]i cant find the file on my computer but it said it was running weird.and something turned on my system restore even though ive always had it off.installed a program prevx. and it found 3 issues ill update lata
nycste Posted September 12, 2007 Author Posted September 12, 2007 (edited) ok this is hijack log after doing some more cleanup on my own. ill run the following Do all of the scans from the sticky list posted in this thread in Safe Mode. Then boot back into Normal Mode, run HijackThis and post a log. Edit: Removed text taken from the wiki at Lunarsoft. Edited September 12, 2007 by Tarun Removed copied wiki text.
nycste Posted September 12, 2007 Author Posted September 12, 2007 and here is hijack log 1. before another safemode scan and fix.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 4:42:13 PM, on 9/12/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Sygate\SPF\smc.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exeC:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Prevx2\PXAgent.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exeC:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exeC:\Documents and Settings\user\Desktop\HiJackThis v.200b.exeC:\WINDOWS\system32\wuauclt.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)O4 - HKLM\..\Run: [smcService] "C:\PROGRA~1\Sygate\SPF\smc.exe" -startguiO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /minO4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exeO9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exeO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO16 - DPF: {49E71DB9-E803-43BA-AF81-1CAF61A6C4CB} (F-Secure Online Scanner 3.2) - http://support.f-secure.com/ols/beta/fscax.cabO16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/v1/cabs/ascstubie.cabO16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cabO16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dllO23 - Service: a-squared Anti-Dialer Service (a2AntiDialer) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Dialer\a2service.exeO23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exeO23 - Service: AntiVir PersonalEdition Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exeO23 - Service: AntiVir PersonalEdition Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exeO23 - Service: AntiVir PersonalEdition Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exeO23 - Service: AntiVir PersonalEdition Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PREVXAgent - Prevx - C:\Program Files\Prevx2\PXAgent.exeO23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007\Win32\RpcDataSrv.exeO23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007\RpcSandraSrv.exeO23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exeO23 - Service: Windows Live OneCare (winss) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\winss.exe (file missing)--End of file - 7372 bytes
nycste Posted September 13, 2007 Author Posted September 13, 2007 http://support.microsoft.com/default.aspx?...kb;en-us;555130Menu bar/Toolbar Missing in Windows Explorer and/or Internet ExplorerView products that this article applies to.Author: Doug Knox MVPCommunity Solutions Content DisclaimerArticle ID : 555130Last Review : July 28, 2005Revision : 1.0SUMMARYThe Menu bar and/or Toolbar may be missing when you open Windows Explorer and/or Internet Explorer.Back to the topSYMPTOMSWhen you open Windows Explorer or Internet Explorer you may find that your Menu bar and/or Toolbar is missing. Back to the topCAUSEFor Windows Explorer and Internet Explorer, this behavior is caused by one or more corrupt values in the Windows RegistryBack to the topRESOLUTIONWARNING: If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your own risk.To resolve this problem, edit the registry to remove the corrupt value(s).Close all open Internet Explorer and Windows Explorer windows. Start the Registry Editor (Click Start, Run and enter REGEDIT.EXE).Go to the following Registry key:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\ToolbarFor Windows Explorer: In the right pane, locate the Explorer sub-key and open it. In the right pane, locate the ITBarLayout value. Right click this value and select Delete.For Internet Explorer: In the right pane, locate the WebBrowser sub-key and open it. In the right pane, locate the ITBarLayout value. Right click this value and select Delete.Quit Registry Editor.Open the affected program (Windows Explorer or Internet Explorer) and verify that you're Menu bar/Toolbar has been restored. If not, close all open Windows Explorer and Internet Explorer Windows and repeat the above step. Then locate the ShellBrowser sub-key, open it and delete the ITBarLayout value there. Back to the topMORE INFORMATIONNotes: Any Toolbar layout customizations will be undone, and the affected Toolbar will be reset to its default configuration. For Windows Explorer, in Windows XP Home Edition, it may be necessary to re-enable the Address bar in Windows Explorer. To do this open Windows Explorer. Then right click a blank area of the Toolbar or Menu bar and select the Address bar item.IMPORTANT: This article contains information about modifying the registry. Before you modify the registry, make sure to back it up and make sure that you understand how to restore the registry if a problem occurs. For information about how to back up, restore, and edit the registry, click the following article number to view the article in the Microsoft Knowledge Base: 256986 Description of the Microsoft Windows Registry
nycste Posted September 13, 2007 Author Posted September 13, 2007 the file ITBarLayout doesnt exist in my registry. soo problemo.this is all i got. Windows Registry Editor Version 5.00[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]"LinksFolderName"="Links""Locked"=dword:00000001"ShowDiscussionButton"="Yes"[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Explorer][HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]"{01E04581-4EEE-11D0-BFE9-00AA005B4383}"=hex:81,45,e0,01,ee,4e,d0,11,bf,e9,00,\ aa,00,5b,43,83,10,00,00,00,00,00,00,00,01,e0,32,f4,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]"{01E04581-4EEE-11D0-BFE9-00AA005B4383}"=hex:81,45,e0,01,ee,4e,d0,11,bf,e9,00,\ aa,00,5b,43,83,10,00,00,00,00,00,00,00,01,e0,32,f4,01,00,00,00"{0E5CBF21-D15F-11D0-8301-00AA005B4383}"=hex:21,bf,5c,0e,5f,d1,d0,11,83,01,00,\ aa,00,5b,43,83,22,00,1c,00,08,00,00,00,06,00,00,00,01,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,4c,00,00,00,01,14,02,00,00,00,00,00,c0,00,00,00,00,\ 00,00,46,81,00,00,00,10,20,00,00,b6,cb,53,42,c5,dc,c6,01,5c,0f,66,75,69,dc,\ c6,01,5c,0f,66,75,69,dc,c6,01,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,4b,01,14,00,1f,50,e0,4f,d0,20,ea,3a,69,10,a2,d8,\ 08,00,2b,30,30,9d,19,00,2f,43,3a,5c,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,5c,00,31,00,00,00,00,00,24,37,a4,1e,10,20,44,4f,43,55,4d,\ 45,7e,31,00,00,44,00,03,00,04,00,ef,be,34,35,17,55,24,37,a4,1e,14,00,00,00,\ 44,00,6f,00,63,00,75,00,6d,00,65,00,6e,00,74,00,73,00,20,00,61,00,6e,00,64,\ 00,20,00,53,00,65,00,74,00,74,00,69,00,6e,00,67,00,73,00,00,00,18,00,34,00,\ 31,00,00,00,00,00,24,37,6f,81,10,20,75,73,65,72,00,00,20,00,03,00,04,00,ef,\ be,34,35,52,77,24,37,6f,81,14,00,00,00,75,00,73,00,65,00,72,00,00,00,14,00,\ 56,00,31,00,00,00,00,00,34,35,31,20,11,20,46,41,56,4f,52,49,7e,31,00,00,3e,\ 00,03,00,04,00,ef,be,34,35,52,77,34,35,31,20,14,00,28,00,46,00,61,00,76,00,\ 6f,00,72,00,69,00,74,00,65,00,73,00,00,00,40,73,68,65,6c,6c,33,32,2e,64,6c,\ 6c,2c,2d,31,32,36,39,33,00,18,00,36,00,31,00,00,00,00,00,34,35,31,20,10,20,\ 4c,69,6e,6b,73,00,22,00,03,00,04,00,ef,be,34,35,55,77,34,35,31,20,14,00,00,\ 00,4c,00,69,00,6e,00,6b,00,73,00,00,00,14,00,00,00,60,00,00,00,03,00,00,a0,\ 58,00,00,00,00,00,00,00,6e,65,77,62,69,65,00,00,00,00,00,00,00,00,00,00,8a,\ 60,c4,a9,2a,da,fc,43,8a,f7,47,d3,fc,d3,87,e7,e4,9f,91,72,57,48,db,11,9f,4a,\ 00,16,e6,80,e2,8d,8a,60,c4,a9,2a,da,fc,43,8a,f7,47,d3,fc,d3,87,e7,e4,9f,91,\ 72,57,48,db,11,9f,4a,00,16,e6,80,e2,8d,00,00,00,00"{F4D76F09-7896-458A-890F-E1F05C46069F}"=hex:09,6f,d7,f4,96,78,8a,45,89,0f,e1,\ f0,5c,46,06,9f
nycste Posted September 13, 2007 Author Posted September 13, 2007 current hijack log. run hijackthis and post the logfor sure brotha Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:47:10 AM, on 9/13/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Sygate\SPF\smc.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exeC:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Prevx2\PXAgent.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exeC:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exeC:\Program Files\Pidgin\pidgin.exeC:\Program Files\Outlook Express\msimn.exeC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\WINDOWS\regedit.exeC:\Documents and Settings\user\Desktop\HiJackThis v.200b.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)O4 - HKLM\..\Run: [smcService] "C:\PROGRA~1\Sygate\SPF\smc.exe" -startguiO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /minO4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exeO9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exeO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO16 - DPF: {49E71DB9-E803-43BA-AF81-1CAF61A6C4CB} (F-Secure Online Scanner 3.2) - http://support.f-secure.com/ols/beta/fscax.cabO16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/v1/cabs/ascstubie.cabO16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cabO16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dllO23 - Service: a-squared Anti-Dialer Service (a2AntiDialer) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Dialer\a2service.exeO23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exeO23 - Service: AntiVir PersonalEdition Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exeO23 - Service: AntiVir PersonalEdition Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exeO23 - Service: AntiVir PersonalEdition Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exeO23 - Service: AntiVir PersonalEdition Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PREVXAgent - Prevx - C:\Program Files\Prevx2\PXAgent.exeO23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007\Win32\RpcDataSrv.exeO23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007\RpcSandraSrv.exeO23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exeO23 - Service: Windows Live OneCare (winss) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\winss.exe (file missing)--End of file - 7477 bytesO3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exethose two things i dont like look of otherwise everything i am familiar with.just checked bdoscandel.exe is the uninstaller for BitDefender Online Scanner. It is located at %WinDir% directory. This is a non-essential program. You can safely remove it.
nycste Posted September 17, 2007 Author Posted September 17, 2007 Sophos Anti-VirusVersion 4.21.0Virus data version 4.21E, September 2007Includes detection for 291211 viruses, trojans and wormsCopyright © 1989-2007 Sophos Plc, www.sophos.comSystem time 14:11:09, System date 17 September 2007Command line qualifiers are: -f -extensive -all -nc -nb -remove -archive -cab -loopback -mime -oe -tnef -pua -mbr -macFull ScanningPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer10.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer10.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer10.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer11.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer11.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer11.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer12.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer12.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer12.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer13.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer13.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer13.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer14.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer14.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer14.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer5.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer5.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer5.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer6.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer6.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer6.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer7.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer7.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer7.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer8.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer8.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer8.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer9.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer9.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer9.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusOverride.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusOverride.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusOverride.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer10.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer10.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer10.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer11.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer11.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer11.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer12.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer12.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer12.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer13.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer13.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer13.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer4.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer4.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer4.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer5.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer5.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer5.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer6.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer6.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer6.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer7.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer7.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer7.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer8.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer8.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer8.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer9.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer9.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer9.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows1.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows1.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows1.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows2.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows2.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows2.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK1.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK1.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK1.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK10.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK10.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK10.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK11.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK11.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK11.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK12.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK12.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK12.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK13.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK13.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK13.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK14.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK14.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK14.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK15.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK15.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK15.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK16.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK16.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK16.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK17.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK17.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK17.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK18.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK18.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK18.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK19.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK19.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK19.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK2.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK2.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK2.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK20.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK20.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK20.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK21.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK21.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK21.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK3.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK3.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK3.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK4.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK4.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK4.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK5.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK5.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK5.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK6.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK6.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK6.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK7.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK7.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK7.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK8.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK8.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK8.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK9.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK9.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK9.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith1.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith1.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith1.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith10.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith10.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith10.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith11.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith11.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith11.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith12.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith12.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith12.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith13.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith13.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith13.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith2.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith2.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith2.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith3.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith3.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith3.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith4.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith4.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith4.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith5.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith5.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith5.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith6.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith6.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith6.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith7.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith7.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith7.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith8.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith8.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith8.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith9.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith9.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith9.zip\commentPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterAntiVirusOverride.zip\sbRecovery.regPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterAntiVirusOverride.zip\sbRecovery.iniPassword protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterAntiVirusOverride.zip\commentCould not open C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.datCould not open C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOGCould not check C:\Documents and Settings\NetworkService\Local Settings\Application Data\Mozilla\Firefox\Profiles\s5pfrjjr.default\CacheAFB9CCFd01\Gzip (corrupt)>>> Virus 'Mal/Dorf-A' found in file C:\Documents and Settings\user\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Documents and Settings\user\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exeRemoval successfulPassword protected file C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 09-10-2007 - 17-49-17.SBU\{2098F008-8CFE-4491-B2DD-B87774FF4B09}Password protected file C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 09-10-2007 - 17-49-17.SBU\{28220B1F-237F-474A-9922-3BD112494632}Password protected file C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 09-10-2007 - 17-49-17.SBU\backup.dbPassword protected file C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 09-12-2007 - 16-00-13.SBU\{63A246B4-3B17-43F2-8E27-9F4EA0F61ECC}Password protected file C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 09-12-2007 - 16-00-13.SBU\backup.dbPassword protected file C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 09-12-2007 - 22-35-49.SBU\backup.dbCould not open C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.datCould not open C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG>>> Virus 'Mal/Dorf-A' found in file C:\Documents and Settings\user\Local Settings\Apps\2.0\JHWCEDC8.09RHQC76CR.LYK\wowa..tion_4d89fb8d52541cc9_0001.0009_0cd1b5f8e4698fd6\WowAceUpdater.exeRemoval successfulCould not open C:\Documents and Settings\user\Local Settings\Temp\Perflib_Perfdata_5f0.datCould not open C:\Documents and Settings\user\Local Settings\Temp\Perflib_Perfdata_704.dat>>> Virus 'Mal/HckPk-A' found in file C:\hbwpb.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\AC3Filter\dialog_patch.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Ahead\Nero Wave Editor\DXEnum.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\AIM\Patcher.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\AIM\SendFile.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\AIM\ShareFile.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\AIM\Sysfiles\AolOnDesktop.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmcdlg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Avira\AntiVir PersonalEdition Premium\guardgui.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Avira\AntiVir PersonalEdition Premium\licmgr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Avira\AntiVir PersonalEdition Premium\preupd.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\DVD Decrypter\DVDDecrypter.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\FDRLab\YouTube Downloader\ffmpeg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\FixVTS.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\GIGABYTE\ET5Pro\ETcall.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Gravis\Xperience\Setup\grxp4exe.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Gravis\Xperience\Setup\xp_run.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\GRETECH\GomPlayer\GrLauncher.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\GRETECH\GomPlayer\KillGom.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\GRETECH\GomPlayer\srt2smi.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\Helexis\Drive Health\dhreport.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\ImgBurn\ImgBurn.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\InfraRecorder\ckEffects.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\InstallShield Installation Information\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}\Battlefield 1942_uninst.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Internet Explorer\Connection Wizard\isignup.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\IrfanView\iv_uninstall.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\IrfanView\Plugins\Slideshow.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Java\jre1.6.0_02\bin\ktab.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Java\jre1.6.0_02\bin\orbd.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Java\jre1.6.0_02\bin\pack200.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Java\jre1.6.0_02\bin\policytool.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Java\jre1.6.0_02\bin\rmid.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Java\jre1.6.0_02\bin\rmiregistry.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Java\jre1.6.0_02\bin\servertool.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Java\jre1.6.0_02\bin\tnameserv.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\jv16 PowerTools 2007\Backups013E9\PXL.exeRemoval successfulPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\Ad-Aware SE Default.sknPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\arrow1.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\arrow2.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bck1.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt11.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt12.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt13.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt21.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt22.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt23.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt31.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt32.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt33.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt41.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt42.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt43.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt51.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt52.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt53.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt61.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt62.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox1.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox2.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox3.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox4.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn1.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn2.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn3.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph1.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph2.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph3.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph4.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph5.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph6.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph7.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\main.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\preview.bmpPassword protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\sprite1.bmp>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\NetMeeting\cb32.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\nLite\7z.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\gengal.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\msfontextract.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\nsplugin.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\odbcconfig.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\pkgchk.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\quickstart.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\scalc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\senddoc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\setofficelang.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\swriter.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\uno.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\OpenOffice.org 2.3\program\unopkg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Outlook Express\msimn.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Outlook Express\oemig50.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Outlook Express\wabmig.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\PeaZip\peazip.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\PeaZip\res\gwrap.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\PeaZip\res\pea.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\PeaZip\res\unace\unace.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\PeaZip\res\upx\strip.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\PeaZip\res\upx\upx.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Pmcc\Baku\sdelete.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\PowerISO\dvdburn.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\PowerISO\piso.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\RaimaRadio\lame.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Realtek\InstallShield\SoundMan.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\Replay Converter\ffmpeg2theora.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Replay Converter\RegSvr32.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Replay Converter\ReplayConverterv20_Crack.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\SUPERAntiSpyware\BootSafe.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Teamspeak2_RC2\client_sdk\tsControl.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Unlocker\UnlockerAssistant.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\VistaCodecPack\filters\ac3config.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Winamp\Plugins\reporter.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Winamp\WampEnq.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\Windows Media Player\mplayer2.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\Program Files\WinRAR\patch.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\WinRAR\RarExtLoader.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\Program Files\WinRAR\Uninstall.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\WINDOWS\erdnt\subs\ERDNT.EXERemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\hh.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\msistub.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\System32\Macromed\Shockwave 10\SwInit.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{103906AD-C60E-4E65-BC84-CE980D19CE41}\ARPPRODUCTICON.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}\icon.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{50E125D1-88E5-48CE-80AE-98EC9698E639}\DTIcon.ECFEE69D_DA66_4F00_ABE5_54E931059C01.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{716E0306-8318-4364-8B8F-0CC4E9376BAC}\icon.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{7CCEBC24-62DB-4280-A8EC-BFA49F167920}\places.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\IconE9F814234.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\IconE9F814236.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}\ffdshowraw_F9FD80CE04484D4F8BCD77FC514C3F99.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}\Haali_F9FD80CE04484D4F8BCD77FC514C3F99.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Installer\{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}\QuickTime_F9FD80CE04484D4F8BCD77FC514C3F99.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\SoftwareDistribution\Download0f4dcdbcc87699e75212b885cb6bebf\sp2qfe\iedw.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\SoundMan.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\actmovie.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\ahui.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\alg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\asr_fmt.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\asr_ldm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\at.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\atmadm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\auditusr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\bootcfg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\bootok.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\cipher.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\comp.exeRemoval successfulCould not open C:\WINDOWS\system32\config\system.LOG>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\alg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\arp.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\asr_fmt.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\asr_ldm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\asr_pfu.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\at.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\atmadm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\compact.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\comrepl.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\comrereg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\convlog.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\davcdata.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\dcomcnfg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\defrag.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\dllhost.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\drvqry.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\dumprep.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\dvdupgrd.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\esentutl.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\evcreate.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\eventvwr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\expand.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\extrac32.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\fc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\find.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\findstr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\flattemp.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\fltmc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\gpupdate.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\grpconv.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\help.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\hh.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\hostname.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\hrtzzm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\icwtutor.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\ie4uinit.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\iedw.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\iexplore.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\iisreset.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\iisrstas.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\iissync.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\inetmgr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\inetwiz.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\ipconfig.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\ipsec6.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\ipv6.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\ipxroute.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\isignup.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\label.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\lights.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\lodctr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\logman.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\logoff.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\logon.scrRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\lpq.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\lpr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\lsass.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\migload.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\migregdb.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\mofcomp.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\mountvol.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\mqbkup.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\mqsvc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\mrinfo.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\msdtc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\msg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\mshta.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\msiexec.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\msimn.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\msiregmv.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\msoobe.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\mstinit.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\nbtstat.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\nddeapir.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\net.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\netsh.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\nppagent.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\query.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\rasautou.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\regsvr32.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\regwiz.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\relog.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\rundll32.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\runonce.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\rvsezm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\rwinsta.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\sapisvr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\savedump.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\sc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\scrcons.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\scrnsave.scrRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\secedit.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\ssmypics.scrRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\ssmyst.scrRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\ssstars.scrRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\stimon.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\subst.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\svchost.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\sysinfo.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\taskkill.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\tasklist.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\taskman.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dllcache\tcmsetup.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dmremote.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\dplaysvr.exeRemoval successfulCould not open C:\WINDOWS\system32\drivers\sptd.sys>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\fltmc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\fontview.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\getmac.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\grpconv.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\ie4uinit.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\Macromed\Shockwave 10\SwInit.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\mrinfo.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\msdtc.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\msiexec.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\mstinit.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\nddeapir.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\netsh.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\netstat.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\npp\nppagent.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\nslookup.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\odbcconf.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\oobe\msoobe.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\oobe\oobebaln.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\openfiles.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\pathping.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\pentnt.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\perfmon.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\ping.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\ping6.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\WINDOWS\system32\pipmon.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\powercfg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\progman.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\qprocess.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\rasphone.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\rcp.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\rdpclip.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\rdsaddin.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\reg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\regedt32.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\regini.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\regsvr32.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\rsnotify.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\rsopprov.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\spoolsv.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\ssbezier.scrRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\ssmarque.scrRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\ssmypics.scrRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\ssmyst.scrRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\WINDOWS\system32\swreg.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\taskkill.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\taskman.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\telnet.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\tlntsvr.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\tracert6.exeRemoval successful>>> Virus 'Mal/HckPk-A' found in file C:\WINDOWS\system32\udefrag.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\w32tm.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\wbem\mofcomp.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\winhlp32.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\winver.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\wpabaln.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\wpnpinst.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\wscntfy.exeRemoval successfulCould not open C:\WINDOWS\system32\xpdx.sys>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\system32\xp_run.exeRemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\TASKMAN.EXERemoval successful>>> Virus 'Mal/Dorf-A' found in file C:\WINDOWS\twunk_32.exeRemoval successfulMemory was swept.Registry was swept.2 master boot records swept.35702 files swept in 3 hours, 26 minutes and 12 seconds.309 errors were encountered.290 viruses were discovered.No PUAs were discovered.290 files out of 35702 were infected.Please send infected samples to Sophos for analysis.For advice consult www.sophos.com, email support@sophos.comor telephone +44 1235 559933299 encrypted files were not checked.Ending Sophos Anti-Virus.
cluberti Posted September 18, 2007 Posted September 18, 2007 Wow, that box should not be considered safe for use .
nycste Posted September 18, 2007 Author Posted September 18, 2007 Wow, that box should not be considered safe for use .tru that. but its still going ! haha. outlook express wont work grrrrr so far my biggest problemi reinstalled 1by1 to get music going and reinstalled AV program notepad doesnt even work gahh haha using alt free program.
nycste Posted September 18, 2007 Author Posted September 18, 2007 just sharing a current scan.http://img183.imageshack.us/my.php?image=v...scannerswm3.jpg
nycste Posted September 18, 2007 Author Posted September 18, 2007 Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:36:34 PM, on 9/17/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\RUNDLL32.EXEC:\Program Files\Comodo\Firewall\CPF.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\Comodo\Firewall\cmdagent.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Pidgin\pidgin.exeC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\Documents and Settings\user\Desktop\HiJackThis v.200b.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - (no file)O2 - BHO: Editor plugin - {6C8DE14D-EF92-492f-BBF7-B61F1405F328} - smuhdd.dll (file missing)O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /backgroundO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXEO4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exeO9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exeO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO16 - DPF: {49E71DB9-E803-43BA-AF81-1CAF61A6C4CB} (F-Secure Online Scanner 3.2) - http://support.f-secure.com/ols/beta/fscax.cabO16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/v1/cabs/ascstubie.cabO16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} - http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cabO16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://www.driveragent.com/files/driveragent.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dllO23 - Service: a-squared Anti-Dialer Service (a2AntiDialer) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Dialer\a2service.exeO23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exeO23 - Service: Application Layer Gateway Service (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exeO23 - Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\WINDOWS\system32\msdtc.exe (file missing)O23 - Service: Windows Installer (MSIServer) - Unknown owner - C:\WINDOWS\system32\msiexec.exe (file missing)O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007\Win32\RpcDataSrv.exeO23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007\RpcSandraSrv.exeO23 - Service: Sygate Personal Firewall Pro (SmcService) - Unknown owner - C:\Program Files\Sygate\SPF\smc.exe (file missing)O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exeO23 - Service: Telnet (TlntSvr) - Unknown owner - C:\WINDOWS\system32\tlntsvr.exe (file missing)O23 - Service: Windows Live OneCare (winss) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\winss.exe (file missing)--End of file - 6976 bytes
nycste Posted September 19, 2007 Author Posted September 19, 2007 well just to update everyone.my computer got totally screwed up it was fine for a week or so. then files started getting corrupted and other stuff. i tried fixing things but nothing worked so i gaveup and reformated.things to note.1. learn how to setup an admin account and only use limited user account (gotta figure that out)2. antivirus programs and spyware scanners only find 70-90percent of issues out today dont rely on them3. when in doubt reformat much faster then i did cuz i think the virus thing started corrupting my other harddrive files. im worried about that now its my data drive and im trying to see howmany files are messed up. the thing started changing all my exe files and then my AV would delete it. soo yea stinks.anyways just wnated to update ya all
Recommended Posts
Please sign in to comment
You will be able to leave a comment after signing in
Sign In Now