Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected Computer


  • Please log in to reply
19 replies to this topic

#1 td323i

td323i

  • Members
  • 122 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 11 August 2007 - 07:01 PM

Hi All,
Can you please have a look at my Hijackthis log? My computer is really slow and i know at one point it was infected with many viruses.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:58:53 PM, on 8/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Entriq\MediaSphere\Bin1\EntriqMediaServer.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Registry Cleaner Trial\RegClean.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\explorer.exe
C:\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {013A653B-49A6-4f76-8B68-E4875EA6BA54} - C:\WINDOWS\system32\utocijsq.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {64d4956a-e503-434d-a471-358c88fa79eb} - (no file)
O2 - BHO: (no name) - {9FE3F429-77F7-4342-B913-3855CFDBC463} - C:\WINDOWS\system32\pvrglxvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [EntriqMediaTray] "C:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\RegClean.exe"
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...arch.jhtml?p=ZS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imagesrvr.com
O15 - Trusted Zone: http://scanner.sysprotect.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted Zone: http://www.winantivirus.com
O15 - Trusted Zone: http://www.winantiviruspro.com
O15 - Trusted Zone: http://download.cdn.winsoftware.com
O15 - Trusted IP range: http://202.67.220.225
O15 - Trusted IP range: http://59.148.220.121
O15 - Trusted IP range: http://62.4.84.53
O15 - Trusted IP range: http://82.98.235.58
O15 - Trusted IP range: http://85.12.25.90
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u...pdate_1-0-0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://evideo.ufc.com/ufc/UFCMediaManager_3_3_1_20.cab
O20 - Winlogon Notify: DMDVCS - DMDVCS.dll (file missing)
O20 - Winlogon Notify: opoawgqr - C:\WINDOWS\SYSTEM32\opoawgqr.dll
O20 - Winlogon Notify: xmvxrchw - C:\WINDOWS\SYSTEM32\xmvxrchw.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

--
End of file - 9441 bytes


Any help will be greatly appreciated

Thanks,
Td

BC AdBot (Login to Remove)

 


#2 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:02:23 AM

Posted 11 August 2007 - 07:23 PM

Hello there and welcome to Bleeping Computer's security forum.
My name is David, I will be helping you with your log today.

It is a good idea to print off these instructions. There is a possibility some of the instructions will need to be carried out where internet access is not available. It is important that you complete the instructions in the right order, and that you don't miss out any steps.

Please set your system to show all files.
Click Start, open My Computer, select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.

Click on start, then control panel, and then double-click on add/remove programs.
From within add/remove program uninstall the following if they exist by double-clicking on the following entries:

VSAdd-in
VSToolbar
WinAntiVirus Pro 2006


Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present:

O2 - BHO: (no name) - {013A653B-49A6-4f76-8B68-E4875EA6BA54} - C:\WINDOWS\system32\utocijsq.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {64d4956a-e503-434d-a471-358c88fa79eb} - (no file)
O2 - BHO: (no name) - {9FE3F429-77F7-4342-B913-3855CFDBC463} - C:\WINDOWS\system32\pvrglxvc.dll
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...arch.jhtml?p=ZS
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imagesrvr.com
O15 - Trusted Zone: http://scanner.sysprotect.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted Zone: http://www.winantivirus.com
O15 - Trusted Zone: http://www.winantiviruspro.com
O15 - Trusted Zone: http://download.cdn.winsoftware.com
O15 - Trusted IP range: http://202.67.220.225
O15 - Trusted IP range: http://59.148.220.121
O15 - Trusted IP range: http://62.4.84.53
O15 - Trusted IP range: http://82.98.235.58
O15 - Trusted IP range: http://85.12.25.90
O20 - Winlogon Notify: DMDVCS - DMDVCS.dll (file missing)
O20 - Winlogon Notify: opoawgqr - C:\WINDOWS\SYSTEM32\opoawgqr.dll
O20 - Winlogon Notify: xmvxrchw - C:\WINDOWS\SYSTEM32\xmvxrchw.dll
O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe (file missing)

Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Now reboot into Safe Mode.
This can be done tapping the F8 key as soon as you start your computer
You will be brought to a menu where you can choose to boot into safe mode.
Make sure you choose the option without networking support.

Using Windows Explorer, please locate the following files/folders, and delete them if still present:

C:\Program Files\VSAdd-in <--the folders may have already been deleted.
C:\Program Files\VSToolbar
C:\Program Files\WinAntiVirus Pro 2006

I want you to clean your cache and cookies from your internet explorer.
There are a few infected files which need to be removed from your system.

° Close all instances of Internet Explorer .
° Go to your control panel and open "Internet Options".
° Click on the "General" tab.
° Click the "Delete Cookies" button, then the "Delete Files" button.
° If prompted, place a tick in the "Delete all offline content" box and click OK.

Also, please clean other Temporary files and Empty the Recycle Bin

° Go to start and click on the "run" button.
° Type the following in the box --> cleanmgr and click ok.
° Let it scan your system for files to remove.
° Make sure only Temporary Files, Temporary Internet Files, and Recycle Bin are checked.
° Press OK to remove them.

Reboot back into normal mode.

Please click on start > run > and type: sc delete FWSvc
Hit enter and let the DOS windows open and close. This is normal.

Download: DelDomains.inf
Locate DelDomains.inf right-click and select: Install
Note: you will not see any on-screen action ...
This will remove all entries in the Trusted, Restricted,and Enhanced Security Configuration Zones.
Note once you do this, any previous restricted zone hacks (spywareblaster, ie-spyad, etc) will need to be reapplyed.

Please download Combofix to your desktop.
Doubleclick combofix.exe to launch the application.

Follow the prompts that will be displayed on the screen.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.

#3 td323i

td323i
  • Topic Starter

  • Members
  • 122 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 11 August 2007 - 08:11 PM

Hi David,
Thank you for your help
ComboFix 07-08-09.3 - "Cea" 2007-08-11 20:59:26.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.248 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006
C:\DOCUME~1\Cea\APPLIC~1.\macromedia\Flash Player\#SharedObjects\BFCA6KQ5\www.broadcaster.com
C:\DOCUME~1\Cea\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\Cea\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\DOCUME~1\Cea\APPLIC~1.\searchtoolbarcorp
C:\DOCUME~1\Cea\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\DOCUME~1\Cea\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\DOCUME~1\Cea\APPLIC~1\..\err.log
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\companion wizard\WapCHK.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{03DCA7C5-4595-4E33-A842-726AA32A716E}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{03DCA7C5-4595-4E33-A842-726AA32A716E}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{101344C0-2E3A-4ED4-9EEC-9E0D57A6BBFC}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{101344C0-2E3A-4ED4-9EEC-9E0D57A6BBFC}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{1358B96B-595E-427C-B709-963A811D208F}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{1358B96B-595E-427C-B709-963A811D208F}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{50971E8E-1B30-40B8-AB3B-937CCE43842B}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{50971E8E-1B30-40B8-AB3B-937CCE43842B}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{E01C10EE-FD11-4B90-BEDE-B5331E575AA7}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{E01C10EE-FD11-4B90-BEDE-B5331E575AA7}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{F2333FB6-BC18-40FB-9734-F612FF15E117}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{F2333FB6-BC18-40FB-9734-F612FF15E117}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{F3EB0DB7-8782-4A05-9733-DC80E4D9F6F0}.dll
C:\Program Files\Common Files\companion wizard\WapCHK{F3EB0DB7-8782-4A05-9733-DC80E4D9F6F0}.dll
C:\WINDOWS\DOWNLO~1\USYP_0002_N91M1708NetInstaller.exe
C:\WINDOWS\system32\ashrtytd.dll
C:\WINDOWS\system32\av.cpl
C:\WINDOWS\system32\bhtdhjrf.dll
C:\WINDOWS\system32\clslbnom.dll
C:\WINDOWS\system32\ddayy.dll
C:\WINDOWS\system32\exibitpa.dll
C:\WINDOWS\system32\hxdpbrki.dll
C:\WINDOWS\system32\jmlkrsin.dll
C:\WINDOWS\system32\kyotbwvj.dll
C:\WINDOWS\system32\ljjigfg.dll
C:\WINDOWS\system32\mpkxtcqr.dll
C:\WINDOWS\system32\nfhllhnd.dll
C:\WINDOWS\system32\pvrglxvc.dll
C:\WINDOWS\system32\stera.exe
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\tqkrrwxg.dll
C:\WINDOWS\system32\ubwgfslf.dll
C:\WINDOWS\system32\umkinywj.dll
C:\WINDOWS\system32\utocijsq.dll
C:\WINDOWS\system32\vtsqrpm.dll
C:\WINDOWS\system32\xmidrduk.dll
C:\WINDOWS\SYSTEM32\yyadd.bak1
C:\WINDOWS\SYSTEM32\yyadd.ini


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_FOPN
-------\LEGACY_VSPF
-------\LEGACY_VSPF_HK
-------\ApiMon
-------\FOPN
-------\vspf
-------\vspf_hk


((((((((((((((((((((((((( Files Created from 2007-07-12 to 2007-08-12 )))))))))))))))))))))))))))))))


2007-08-11 20:58 51,200 --a------ C:\WINDOWS\nircmd.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-11 20:50 --------- d-------- C:\Program Files\Spyware Doctor
2007-05-16 11:12 86528 --------- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 --------- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 --------- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 --------- C:\WINDOWS\system32\dllcache\msoe.dll
2006-11-21 07:58:54 692,244 --sh--w C:\WINDOWS\SYSTEM\mxlabk.dll
2005-10-27 03:37:35 28,173 --sh--w C:\WINDOWS\SYSTEM32\mljgh.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 15:33]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 22:15]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 18:54]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 03:01]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 03:05]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2004-12-28 00:51]
"Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-06-18 11:30]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]
"EntriqMediaTray"="C:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe" [2006-07-25 15:55]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-26 21:01]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-01-19 12:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-21 18:39]
"Registry Cleaner"="C:\Program Files\Registry Cleaner Trial\RegClean.exe" [2005-08-22 17:20]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=

C:\Documents and Settings\Cea\Start Menu\Programs\Startup\
DESKTOP.INI [2004-08-10 15:04:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2004-08-10 15:04:12]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opoawgqr]
opoawgqr.dll 2006-07-28 06:30 188948 C:\WINDOWS\SYSTEM32\opoawgqr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xmvxrchw]
xmvxrchw.dll 2006-11-02 22:00 188948 C:\WINDOWS\SYSTEM32\xmvxrchw.dll

R3 IntelC51;IntelC51;C:\WINDOWS\system32\DRIVERS\IntelC51.sys
R3 IntelC52;IntelC52;C:\WINDOWS\system32\DRIVERS\IntelC52.sys
R3 IntelC53;IntelC53;C:\WINDOWS\system32\DRIVERS\IntelC53.sys
R3 mohfilt;mohfilt;C:\WINDOWS\system32\DRIVERS\mohfilt.sys
R3 senfilt;senfilt;C:\WINDOWS\system32\drivers\senfilt.sys
S2 DP1112;DP1112;\??\C:\WINDOWS\system32\Drivers\DP.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 21:03:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-11 21:04:42 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-11 21:04

--- E O F ---



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:11:12 PM, on 8/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Registry Cleaner Trial\RegClean.exe
C:\Program Files\Entriq\MediaSphere\Bin1\EntriqMediaServer.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [EntriqMediaTray] "C:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\RegClean.exe"
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u...pdate_1-0-0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://evideo.ufc.com/ufc/UFCMediaManager_3_3_1_20.cab
O20 - Winlogon Notify: opoawgqr - C:\WINDOWS\SYSTEM32\opoawgqr.dll
O20 - Winlogon Notify: xmvxrchw - C:\WINDOWS\SYSTEM32\xmvxrchw.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

--
End of file - 7832 bytes

#4 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:02:23 AM

Posted 12 August 2007 - 02:58 AM

Good work! Let's continue... :thumbsup:

It is a good idea to print off these instructions. There is a possibility some of the instructions will need to be carried out where internet access is not available. It is important that you complete the instructions in the right order, and that you don't miss out any steps.

Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present:

O20 - Winlogon Notify: opoawgqr - C:\WINDOWS\SYSTEM32\opoawgqr.dll
O20 - Winlogon Notify: xmvxrchw - C:\WINDOWS\SYSTEM32\xmvxrchw.dll

Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Click start -> Run -> type cmd -> Click OK
Type or paste sc stop DP1112 at the command prompt and hit enter.
Type or paste sc delete DP1112 at the command prompt and hit enter.

Close the command prompt window

Click start > run and type: notepad, then hit enter.

File::
C:\WINDOWS\SYSTEM32\xmvxrchw.dll
C:\WINDOWS\SYSTEM32\opoawgqr.dll
C:\WINDOWS\SYSTEM\mxlabk.dll
C:\WINDOWS\SYSTEM32\mljgh.dll
C:\WINDOWS\system32\Drivers\DP.sys

Click File > Save and call it "ComboFix-Do.txt" (without quotes).
Save it to your desktop.
Posted Image
Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe
Combofix will run, and a text file will open. Please post it back here.

Please download VundoFix.exe to your desktop
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.

When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove.
VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button".

#5 td323i

td323i
  • Topic Starter

  • Members
  • 122 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 19 August 2007 - 05:14 PM

Hi David,
Sorry for the delay. I hadn't been to my sister in laws house since your last post. The computer is now in worse shape.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:07:31 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Q2Vh\command.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Online Services\hosycat22011.exe
C:\Program Files\Entriq\MediaSphere\Bin1\EntriqMediaServer.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\retadpu77.exe
C:\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasdc.exe
C:\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasers.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\svhost.exe
C:\Program Files\WinAntiSpyware 2007\was7.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Registry Cleaner Trial\RegClean.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WinAntiSpyware 2007\unins000.exe
C:\DOCUME~1\Cea\LOCALS~1\Temp\_iu14D2N.tmp
C:\Program Files\WinAntiSpyware 2007\was7.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [EntriqMediaTray] "C:\Program Files\Entriq\MediaSphere\EntriqMediaTray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [hosycat] C:\Program Files\Online Services\hosycat22011.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\nwinrmdt.exe CHD003
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [DC6_Check] "C:\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasdc.exe"
O4 - HKLM\..\Run: [ERS_Check] "C:\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasers.exe"
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
O4 - HKLM\..\Run: [uwas7cw] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe" -c
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\RunOnce: [RemoveInstallPath] cmd.exe C:\WINDOWS\system32\cmd.exe /c rmdir /S /Q "C:\PROGRA~1\WinPop" > nul
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\RegClean.exe"
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\lqdsrngo.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\nwinrmdt.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u...pdate_1-0-0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} (MediaControl Class) - http://evideo.ufc.com/ufc/UFCMediaManager_3_3_1_20.cab
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Q2Vh\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\progyrt.html

--
End of file - 8703 bytes

#6 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:02:23 AM

Posted 19 August 2007 - 05:31 PM

Ok, we need to get this machine patched up before we continue.
If we don't, you will simply be reinfected over and over again...

You are missing one important program on that computer - an antivirus!
This is somewhat suicidal in today's digital world.
You need to install an antivirus program as soon as you can and run a complete scan of the computer.
AVG and Avast are excellent, free antivirus programs..
Never install more than one antivirus on your system - several together can cause problems and decrease performance.

You are also missing a firewall, which is another essential piece of computer software.
I would certainly recommend you install one, but it is perhaps not as important as an antivirus.
Zonealarm, and Kerio are also good, free firewalls.
You can read this tutorial for more infomation:
Understanding and using firewalls.

After installing both of them, please re-run combofix and post the log it creates.

Also, Run HijackThis.
On the first menu, click Open the Misc Tools Section
Click Open Uninstall Manager
Click Save List - Save it anywhere.
A notepad will pop-up after it's saved, please copy everything in that Notepad and paste it here.

#7 td323i

td323i
  • Topic Starter

  • Members
  • 122 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 19 August 2007 - 06:27 PM

Hi David,
Thanks for the quick reply
ComboFix 07-08-09.3 - "Cea" 2007-08-19 18:44:18.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.114 [GMT -4:00]


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\DOCUME~1\Cea\APPLIC~1.\sstem~1
C:\DOCUME~1\Cea\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\Cea\APPLIC~1.\winantispyware 2007\Logs\update.log
C:\DOCUME~1\Cea\APPLIC~1\..\err.log
C:\DOCUME~1\Cea\APPLIC~1\WinAntiSpyware 2006
C:\DOCUME~1\Cea\APPLIC~1\WinAntiSpyware 2006\Logs\update.log
C:\DOCUME~1\Cea\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\DOCUME~1\Cea\Desktop\WinAntiSpyware 2007.lnk
C:\DOCUME~1\Cea\MYDOCU~1.\icroso~1.net
C:\Program Files\Common Files\progyrt.html
C:\Program Files\Common Files\racle~1
C:\Program Files\Common Files\WinAntiSpyware 2006 Free
C:\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasdc.exe
C:\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasers.exe
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\inetget2\stub109_4_0_4_0.exe
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\svhost
C:\Program Files\svhost\wr-1-0000077.exe
C:\Program Files\winantispyware 2006 free
C:\Program Files\winantispyware 2006 free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_inf_iereset.inf\#data
C:\Program Files\WinAntiSpyware 2006 Free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_inf_iereset.inf\#data
C:\Program Files\winantispyware 2006 free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_inf_iereset.inf\#name
C:\Program Files\WinAntiSpyware 2006 Free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_inf_iereset.inf\#name
C:\Program Files\WinAntiSpyware 2006 Free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_system.ini\#data
C:\Program Files\winantispyware 2006 free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_system.ini\#data
C:\Program Files\WinAntiSpyware 2006 Free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_system.ini\#name
C:\Program Files\winantispyware 2006 free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_system.ini\#name
C:\Program Files\winantispyware 2006 free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_SYSTEM32_drivers_etc_hosts\#data
C:\Program Files\WinAntiSpyware 2006 Free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_SYSTEM32_drivers_etc_hosts\#data
C:\Program Files\winantispyware 2006 free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_SYSTEM32_drivers_etc_hosts\#name
C:\Program Files\WinAntiSpyware 2006 Free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_SYSTEM32_drivers_etc_hosts\#name
C:\Program Files\winantispyware 2006 free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_win.ini\#data
C:\Program Files\WinAntiSpyware 2006 Free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_win.ini\#data
C:\Program Files\winantispyware 2006 free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_win.ini\#name
C:\Program Files\WinAntiSpyware 2006 Free\database\RTMonitor.dat\#monitors\FileMonitor\C__WINDOWS_win.ini\#name
C:\Program Files\winantispyware 2007
C:\Program Files\WinAntiSpyware 2007\Activate.dat
C:\Program Files\winantispyware 2007\Activate.dat
C:\Program Files\winantispyware 2007\appupdate.dat
C:\Program Files\WinAntiSpyware 2007\appupdate.dat
C:\Program Files\WinAntiSpyware 2007\AsAgents.dll
C:\Program Files\winantispyware 2007\AsAgents.dll
C:\Program Files\winantispyware 2007\AsAgents.xml
C:\Program Files\WinAntiSpyware 2007\AsAgents.xml
C:\Program Files\winantispyware 2007\atl71.dll
C:\Program Files\WinAntiSpyware 2007\atl71.dll
C:\Program Files\winantispyware 2007\AutoProcess.dat
C:\Program Files\WinAntiSpyware 2007\AutoProcess.dat
C:\Program Files\winantispyware 2007\bnlink.dat
C:\Program Files\WinAntiSpyware 2007\bnlink.dat
C:\Program Files\WinAntiSpyware 2007\database\enemies.dat
C:\Program Files\winantispyware 2007\database\enemies.dat
C:\Program Files\winantispyware 2007\database\knownfiles.dat
C:\Program Files\WinAntiSpyware 2007\database\knownfiles.dat
C:\Program Files\WinAntiSpyware 2007\database\TEBase.dat
C:\Program Files\winantispyware 2007\database\TEBase.dat
C:\Program Files\WinAntiSpyware 2007\database\vbpv.dat
C:\Program Files\winantispyware 2007\database\vbpv.dat
C:\Program Files\winantispyware 2007\dbupdate.dat
C:\Program Files\WinAntiSpyware 2007\dbupdate.dat
C:\Program Files\winantispyware 2007\fopnl.dll
C:\Program Files\WinAntiSpyware 2007\fopnl.dll
C:\Program Files\winantispyware 2007\InstHelp.exe
C:\Program Files\WinAntiSpyware 2007\InstHelp.exe
C:\Program Files\winantispyware 2007\InstUp.exe
C:\Program Files\WinAntiSpyware 2007\InstUp.exe
C:\Program Files\winantispyware 2007\lapv.dat
C:\Program Files\WinAntiSpyware 2007\lapv.dat
C:\Program Files\winantispyware 2007\license.rtf
C:\Program Files\WinAntiSpyware 2007\license.rtf
C:\Program Files\winantispyware 2007\manual.pdf
C:\Program Files\WinAntiSpyware 2007\manual.pdf
C:\Program Files\winantispyware 2007\manual.url
C:\Program Files\WinAntiSpyware 2007\manual.url
C:\Program Files\WinAntiSpyware 2007\mfc71.dll
C:\Program Files\winantispyware 2007\mfc71.dll
C:\Program Files\WinAntiSpyware 2007\monstate.dat
C:\Program Files\winantispyware 2007\monstate.dat
C:\Program Files\winantispyware 2007\msvcp71.dll
C:\Program Files\WinAntiSpyware 2007\msvcp71.dll
C:\Program Files\WinAntiSpyware 2007\msvcr71.dll
C:\Program Files\winantispyware 2007\msvcr71.dll
C:\Program Files\WinAntiSpyware 2007\ps.dat
C:\Program Files\winantispyware 2007\ps.dat
C:\Program Files\winantispyware 2007\pv.dat
C:\Program Files\WinAntiSpyware 2007\pv.dat
C:\Program Files\winantispyware 2007\quaratine.dat\#post_quarantine
C:\Program Files\WinAntiSpyware 2007\quaratine.dat\#post_quarantine
C:\Program Files\WinAntiSpyware 2007\readme.rtf
C:\Program Files\winantispyware 2007\readme.rtf
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0069d01bfe624e70bb18179f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0069d01bfe624e70bb18179f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0069d01bfe624e70bb18179f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0069d01bfe624e70bb18179f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0069d01bfe624e70bb18179f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0069d01bfe624e70bb18179f\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\008361f70a734a0e5064b4aa\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\008361f70a734a0e5064b4aa\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\008361f70a734a0e5064b4aa\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\008361f70a734a0e5064b4aa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\008361f70a734a0e5064b4aa\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\008361f70a734a0e5064b4aa\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\008361f70a734a0e5064b4aa\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\008361f70a734a0e5064b4aa\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\03b2ab794ef64db6396e1db5\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\03b2ab794ef64db6396e1db5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\03b2ab794ef64db6396e1db5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\03b2ab794ef64db6396e1db5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\03b2ab794ef64db6396e1db5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\03b2ab794ef64db6396e1db5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\03b2ab794ef64db6396e1db5\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\03b2ab794ef64db6396e1db5\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0c2fe4ee382a4a6d60fdcf89\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0c2fe4ee382a4a6d60fdcf89\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0c2fe4ee382a4a6d60fdcf89\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0c2fe4ee382a4a6d60fdcf89\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0c2fe4ee382a4a6d60fdcf89\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0c2fe4ee382a4a6d60fdcf89\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0c2fe4ee382a4a6d60fdcf89\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\0c2fe4ee382a4a6d60fdcf89\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1388a76e438d45db8b8e999a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1388a76e438d45db8b8e999a\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1388a76e438d45db8b8e999a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1388a76e438d45db8b8e999a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1388a76e438d45db8b8e999a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1388a76e438d45db8b8e999a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1464956fa9a44894d0e8e2a4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1464956fa9a44894d0e8e2a4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1464956fa9a44894d0e8e2a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1464956fa9a44894d0e8e2a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1464956fa9a44894d0e8e2a4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1464956fa9a44894d0e8e2a4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\16f8e8aeded4485a2e8e3a94\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\16f8e8aeded4485a2e8e3a94\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\16f8e8aeded4485a2e8e3a94\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\16f8e8aeded4485a2e8e3a94\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\16f8e8aeded4485a2e8e3a94\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\16f8e8aeded4485a2e8e3a94\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\16f8e8aeded4485a2e8e3a94\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\16f8e8aeded4485a2e8e3a94\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1700900033e14a662d7bbe85\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1700900033e14a662d7bbe85\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1700900033e14a662d7bbe85\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1700900033e14a662d7bbe85\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1700900033e14a662d7bbe85\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1700900033e14a662d7bbe85\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1700900033e14a662d7bbe85\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1700900033e14a662d7bbe85\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\180c56dc45284ad15de6788a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\180c56dc45284ad15de6788a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\180c56dc45284ad15de6788a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\180c56dc45284ad15de6788a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\180c56dc45284ad15de6788a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\180c56dc45284ad15de6788a\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1c401186fc00464213caefa7\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1c401186fc00464213caefa7\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1c401186fc00464213caefa7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1c401186fc00464213caefa7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1c401186fc00464213caefa7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1c401186fc00464213caefa7\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1ca2ccbf819f4cd8a2b48ab0\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1ca2ccbf819f4cd8a2b48ab0\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1ca2ccbf819f4cd8a2b48ab0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1ca2ccbf819f4cd8a2b48ab0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1ca2ccbf819f4cd8a2b48ab0\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1ca2ccbf819f4cd8a2b48ab0\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1f098282ec0342c7fc5754a4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1f098282ec0342c7fc5754a4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1f098282ec0342c7fc5754a4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1f098282ec0342c7fc5754a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1f098282ec0342c7fc5754a4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\1f098282ec0342c7fc5754a4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\31ca9bdcec6b46973f428787\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\31ca9bdcec6b46973f428787\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\31ca9bdcec6b46973f428787\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\31ca9bdcec6b46973f428787\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\31ca9bdcec6b46973f428787\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\31ca9bdcec6b46973f428787\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\31ca9bdcec6b46973f428787\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\31ca9bdcec6b46973f428787\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\362590a3540a4f109b2b77af\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\362590a3540a4f109b2b77af\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\362590a3540a4f109b2b77af\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\362590a3540a4f109b2b77af\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\362590a3540a4f109b2b77af\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\362590a3540a4f109b2b77af\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\362590a3540a4f109b2b77af\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\362590a3540a4f109b2b77af\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\38c6c02631424d7abd30508e\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\38c6c02631424d7abd30508e\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\38c6c02631424d7abd30508e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\38c6c02631424d7abd30508e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\38c6c02631424d7abd30508e\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\38c6c02631424d7abd30508e\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\3d317142063b488f1c4b0cb4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\3d317142063b488f1c4b0cb4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\3d317142063b488f1c4b0cb4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\3d317142063b488f1c4b0cb4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\3d317142063b488f1c4b0cb4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\3d317142063b488f1c4b0cb4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\3d317142063b488f1c4b0cb4\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\3d317142063b488f1c4b0cb4\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\42dbc2470a5e4a7ffa4c028f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\42dbc2470a5e4a7ffa4c028f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\42dbc2470a5e4a7ffa4c028f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\42dbc2470a5e4a7ffa4c028f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\42dbc2470a5e4a7ffa4c028f\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\42dbc2470a5e4a7ffa4c028f\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\43fcda6f85a14f105cd42d93\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\43fcda6f85a14f105cd42d93\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\43fcda6f85a14f105cd42d93\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\43fcda6f85a14f105cd42d93\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\43fcda6f85a14f105cd42d93\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\43fcda6f85a14f105cd42d93\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4403b67465a94a5c48a969a9\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4403b67465a94a5c48a969a9\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4403b67465a94a5c48a969a9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4403b67465a94a5c48a969a9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4403b67465a94a5c48a969a9\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4403b67465a94a5c48a969a9\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4403b67465a94a5c48a969a9\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4403b67465a94a5c48a969a9\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47b2bc5680f94c472cfc69a4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47b2bc5680f94c472cfc69a4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47b2bc5680f94c472cfc69a4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47b2bc5680f94c472cfc69a4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47b2bc5680f94c472cfc69a4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47b2bc5680f94c472cfc69a4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47f78459a6684f4dff3a1195\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47f78459a6684f4dff3a1195\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47f78459a6684f4dff3a1195\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47f78459a6684f4dff3a1195\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47f78459a6684f4dff3a1195\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\47f78459a6684f4dff3a1195\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\48a8d34e2ec6421c248f50b8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\48a8d34e2ec6421c248f50b8\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\48a8d34e2ec6421c248f50b8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\48a8d34e2ec6421c248f50b8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\48a8d34e2ec6421c248f50b8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\48a8d34e2ec6421c248f50b8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4b3e6fcde834453243f479a7\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4b3e6fcde834453243f479a7\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4b3e6fcde834453243f479a7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4b3e6fcde834453243f479a7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4b3e6fcde834453243f479a7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4b3e6fcde834453243f479a7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4b3e6fcde834453243f479a7\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4b3e6fcde834453243f479a7\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4db9652b8c8d47a4da7fcb97\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4db9652b8c8d47a4da7fcb97\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4db9652b8c8d47a4da7fcb97\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4db9652b8c8d47a4da7fcb97\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4db9652b8c8d47a4da7fcb97\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4db9652b8c8d47a4da7fcb97\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4dfe63230e4f4671db3435af\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4dfe63230e4f4671db3435af\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4dfe63230e4f4671db3435af\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4dfe63230e4f4671db3435af\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4dfe63230e4f4671db3435af\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\4dfe63230e4f4671db3435af\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\50c0f169ec1c4276fa9e108f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\50c0f169ec1c4276fa9e108f\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\50c0f169ec1c4276fa9e108f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\50c0f169ec1c4276fa9e108f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\50c0f169ec1c4276fa9e108f\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\50c0f169ec1c4276fa9e108f\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\558be12a665c42761b85b2b5\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\558be12a665c42761b85b2b5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\558be12a665c42761b85b2b5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\558be12a665c42761b85b2b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\558be12a665c42761b85b2b5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\558be12a665c42761b85b2b5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\65a24726cf2241e6d2a721ba\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\65a24726cf2241e6d2a721ba\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\65a24726cf2241e6d2a721ba\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\65a24726cf2241e6d2a721ba\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\65a24726cf2241e6d2a721ba\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\65a24726cf2241e6d2a721ba\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6b1ba0d6d2a84123e57c7fa2\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6b1ba0d6d2a84123e57c7fa2\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6b1ba0d6d2a84123e57c7fa2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6b1ba0d6d2a84123e57c7fa2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6b1ba0d6d2a84123e57c7fa2\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6b1ba0d6d2a84123e57c7fa2\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6c37ac63461f4c02980ec9bc\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6c37ac63461f4c02980ec9bc\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6c37ac63461f4c02980ec9bc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6c37ac63461f4c02980ec9bc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6c37ac63461f4c02980ec9bc\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\6c37ac63461f4c02980ec9bc\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\7c65412908aa4070630336bf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\7c65412908aa4070630336bf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\7c65412908aa4070630336bf\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\7c65412908aa4070630336bf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\7c65412908aa4070630336bf\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\7c65412908aa4070630336bf\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\7c65412908aa4070630336bf\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\7c65412908aa4070630336bf\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8180b46fed5a452a3f6e5a83\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8180b46fed5a452a3f6e5a83\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8180b46fed5a452a3f6e5a83\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8180b46fed5a452a3f6e5a83\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8180b46fed5a452a3f6e5a83\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8180b46fed5a452a3f6e5a83\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8180b46fed5a452a3f6e5a83\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8180b46fed5a452a3f6e5a83\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8411b3cfc170422556c0c88f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8411b3cfc170422556c0c88f\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8411b3cfc170422556c0c88f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8411b3cfc170422556c0c88f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8411b3cfc170422556c0c88f\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8411b3cfc170422556c0c88f\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8411b3cfc170422556c0c88f\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8411b3cfc170422556c0c88f\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\85a521c669234a71dd0f70af\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\85a521c669234a71dd0f70af\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\85a521c669234a71dd0f70af\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\85a521c669234a71dd0f70af\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\85a521c669234a71dd0f70af\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\85a521c669234a71dd0f70af\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8e68093c807a4ac149f702ba\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8e68093c807a4ac149f702ba\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8e68093c807a4ac149f702ba\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8e68093c807a4ac149f702ba\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8e68093c807a4ac149f702ba\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\8e68093c807a4ac149f702ba\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\91a47e987808436457271a91\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\91a47e987808436457271a91\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\91a47e987808436457271a91\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\91a47e987808436457271a91\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\91a47e987808436457271a91\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\91a47e987808436457271a91\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\92b025c02f1241566a051f94\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\92b025c02f1241566a051f94\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\92b025c02f1241566a051f94\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\92b025c02f1241566a051f94\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\92b025c02f1241566a051f94\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\92b025c02f1241566a051f94\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\937a87e5b2b043678cc239b8\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\937a87e5b2b043678cc239b8\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\937a87e5b2b043678cc239b8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\937a87e5b2b043678cc239b8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\937a87e5b2b043678cc239b8\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\937a87e5b2b043678cc239b8\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\937a87e5b2b043678cc239b8\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\937a87e5b2b043678cc239b8\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\940dceafceb14bea4f1ab0ac\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\940dceafceb14bea4f1ab0ac\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\940dceafceb14bea4f1ab0ac\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\940dceafceb14bea4f1ab0ac\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\940dceafceb14bea4f1ab0ac\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\940dceafceb14bea4f1ab0ac\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9b6ca40a2378429c44c8d081\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9b6ca40a2378429c44c8d081\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9b6ca40a2378429c44c8d081\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9b6ca40a2378429c44c8d081\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9b6ca40a2378429c44c8d081\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9b6ca40a2378429c44c8d081\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9b6ca40a2378429c44c8d081\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9b6ca40a2378429c44c8d081\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9ca74a3fe82e4bbeff382894\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9ca74a3fe82e4bbeff382894\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9ca74a3fe82e4bbeff382894\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9ca74a3fe82e4bbeff382894\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9ca74a3fe82e4bbeff382894\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\9ca74a3fe82e4bbeff382894\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a39926b4e23c4a6f463d45b4\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a39926b4e23c4a6f463d45b4\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a39926b4e23c4a6f463d45b4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a39926b4e23c4a6f463d45b4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a39926b4e23c4a6f463d45b4\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a39926b4e23c4a6f463d45b4\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a39926b4e23c4a6f463d45b4\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a39926b4e23c4a6f463d45b4\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a7bb3aa56ce146232b916cbe\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a7bb3aa56ce146232b916cbe\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a7bb3aa56ce146232b916cbe\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a7bb3aa56ce146232b916cbe\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a7bb3aa56ce146232b916cbe\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\a7bb3aa56ce146232b916cbe\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aab92bdf6b71492293d617b5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aab92bdf6b71492293d617b5\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aab92bdf6b71492293d617b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aab92bdf6b71492293d617b5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aab92bdf6b71492293d617b5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aab92bdf6b71492293d617b5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aab92bdf6b71492293d617b5\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aab92bdf6b71492293d617b5\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ae58a82911b2410177cc57ac\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ae58a82911b2410177cc57ac\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ae58a82911b2410177cc57ac\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ae58a82911b2410177cc57ac\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ae58a82911b2410177cc57ac\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ae58a82911b2410177cc57ac\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ae58a82911b2410177cc57ac\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ae58a82911b2410177cc57ac\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aed7c0ab381d44d2bc6dac9d\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aed7c0ab381d44d2bc6dac9d\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aed7c0ab381d44d2bc6dac9d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aed7c0ab381d44d2bc6dac9d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aed7c0ab381d44d2bc6dac9d\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aed7c0ab381d44d2bc6dac9d\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aef8da45a32140ea5cb0f3af\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aef8da45a32140ea5cb0f3af\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aef8da45a32140ea5cb0f3af\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aef8da45a32140ea5cb0f3af\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aef8da45a32140ea5cb0f3af\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\aef8da45a32140ea5cb0f3af\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b1a8eb1112d347a277a5cb94\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b1a8eb1112d347a277a5cb94\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b1a8eb1112d347a277a5cb94\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b1a8eb1112d347a277a5cb94\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b1a8eb1112d347a277a5cb94\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b1a8eb1112d347a277a5cb94\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b59d02b191344f72c8fe7a8a\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b59d02b191344f72c8fe7a8a\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b59d02b191344f72c8fe7a8a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b59d02b191344f72c8fe7a8a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b59d02b191344f72c8fe7a8a\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b59d02b191344f72c8fe7a8a\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b59d02b191344f72c8fe7a8a\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b59d02b191344f72c8fe7a8a\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b72c4fae53274e9d06fde595\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b72c4fae53274e9d06fde595\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b72c4fae53274e9d06fde595\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b72c4fae53274e9d06fde595\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b72c4fae53274e9d06fde595\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\b72c4fae53274e9d06fde595\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\be4f1ad703c5436816c609a3\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\be4f1ad703c5436816c609a3\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\be4f1ad703c5436816c609a3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\be4f1ad703c5436816c609a3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\be4f1ad703c5436816c609a3\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\be4f1ad703c5436816c609a3\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\be4f1ad703c5436816c609a3\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\be4f1ad703c5436816c609a3\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\c1aa9c46301b479d93c21188\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\c1aa9c46301b479d93c21188\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\c1aa9c46301b479d93c21188\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\c1aa9c46301b479d93c21188\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\c1aa9c46301b479d93c21188\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\c1aa9c46301b479d93c21188\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d210fe5330b1415ac6a74ea9\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d210fe5330b1415ac6a74ea9\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d210fe5330b1415ac6a74ea9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d210fe5330b1415ac6a74ea9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d210fe5330b1415ac6a74ea9\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d210fe5330b1415ac6a74ea9\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d70e27e356474b48e9c630ac\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d70e27e356474b48e9c630ac\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d70e27e356474b48e9c630ac\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d70e27e356474b48e9c630ac\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d70e27e356474b48e9c630ac\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d70e27e356474b48e9c630ac\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d8ce486446a64c93852224a3\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d8ce486446a64c93852224a3\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d8ce486446a64c93852224a3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d8ce486446a64c93852224a3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d8ce486446a64c93852224a3\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d8ce486446a64c93852224a3\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d8ce486446a64c93852224a3\Cea
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\d8ce486446a64c93852224a3\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\db4ecbefda3b4dc2ef6f7996\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\db4ecbefda3b4dc2ef6f7996\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\db4ecbefda3b4dc2ef6f7996\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\db4ecbefda3b4dc2ef6f7996\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\db4ecbefda3b4dc2ef6f7996\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\db4ecbefda3b4dc2ef6f7996\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\db4ecbefda3b4dc2ef6f7996\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\db4ecbefda3b4dc2ef6f7996\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e22fdc9ea0634ea5c9914dad\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e22fdc9ea0634ea5c9914dad\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e22fdc9ea0634ea5c9914dad\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e22fdc9ea0634ea5c9914dad\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e22fdc9ea0634ea5c9914dad\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e22fdc9ea0634ea5c9914dad\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e728ef2270244c817f0da990\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e728ef2270244c817f0da990\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e728ef2270244c817f0da990\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e728ef2270244c817f0da990\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e728ef2270244c817f0da990\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e728ef2270244c817f0da990\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e728ef2270244c817f0da990\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\e728ef2270244c817f0da990\Cea
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ef468724ec9e45a9b6b865b5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ef468724ec9e45a9b6b865b5\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ef468724ec9e45a9b6b865b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ef468724ec9e45a9b6b865b5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ef468724ec9e45a9b6b865b5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\ef468724ec9e45a9b6b865b5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\efb71bca5bbf4d567890c487\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\efb71bca5bbf4d567890c487\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\efb71bca5bbf4d567890c487\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\efb71bca5bbf4d567890c487\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\efb71bca5bbf4d567890c487\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\efb71bca5bbf4d567890c487\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\f603c23d693c42e25431f4b3\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\f603c23d693c42e25431f4b3\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\f603c23d693c42e25431f4b3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\f603c23d693c42e25431f4b3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\f603c23d693c42e25431f4b3\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\f603c23d693c42e25431f4b3\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb7f640168674fe0969b709e\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb7f640168674fe0969b709e\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb7f640168674fe0969b709e\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb7f640168674fe0969b709e\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb7f640168674fe0969b709e\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb7f640168674fe0969b709e\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb81f19c9e1f407d61d10695\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb81f19c9e1f407d61d10695\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb81f19c9e1f407d61d10695\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb81f19c9e1f407d61d10695\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb81f19c9e1f407d61d10695\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fb81f19c9e1f407d61d10695\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fd56d05e752a4957d20b819d\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fd56d05e752a4957d20b819d\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fd56d05e752a4957d20b819d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fd56d05e752a4957d20b819d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fd56d05e752a4957d20b819d\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fd56d05e752a4957d20b819d\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fe4a277c3dbe402366377fb5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fe4a277c3dbe402366377fb5\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fe4a277c3dbe402366377fb5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fe4a277c3dbe402366377fb5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fe4a277c3dbe402366377fb5\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\584b6d67bc494a9666002793\fe4a277c3dbe402366377fb5\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\30fb696972de4e7c59c1f2b7\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\30fb696972de4e7c59c1f2b7\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\30fb696972de4e7c59c1f2b7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\30fb696972de4e7c59c1f2b7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\30fb696972de4e7c59c1f2b7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\30fb696972de4e7c59c1f2b7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\3243ac2aec1047e1e6e5b09d\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\3243ac2aec1047e1e6e5b09d\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\3243ac2aec1047e1e6e5b09d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\3243ac2aec1047e1e6e5b09d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\3243ac2aec1047e1e6e5b09d\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\3243ac2aec1047e1e6e5b09d\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\840c06dd7b914dc1815c87b7\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\840c06dd7b914dc1815c87b7\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\840c06dd7b914dc1815c87b7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\840c06dd7b914dc1815c87b7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\840c06dd7b914dc1815c87b7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\98ea68fa1dfe463b383a1393\840c06dd7b914dc1815c87b7\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\3947ca3c718b4a0879d0ddbf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\3947ca3c718b4a0879d0ddbf\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\3947ca3c718b4a0879d0ddbf\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\3947ca3c718b4a0879d0ddbf\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\3947ca3c718b4a0879d0ddbf\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\3947ca3c718b4a0879d0ddbf\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\47366fe0c15149e5ec372895\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\47366fe0c15149e5ec372895\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\47366fe0c15149e5ec372895\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\47366fe0c15149e5ec372895\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\47366fe0c15149e5ec372895\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\47366fe0c15149e5ec372895\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\7c3e56c7277f4079b3630581\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\7c3e56c7277f4079b3630581\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\7c3e56c7277f4079b3630581\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\7c3e56c7277f4079b3630581\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\7c3e56c7277f4079b3630581\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\7c3e56c7277f4079b3630581\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\ce285c044d164510f06fa183\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\ce285c044d164510f06fa183\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\ce285c044d164510f06fa183\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\ce285c044d164510f06fa183\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\ce285c044d164510f06fa183\#name
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\52dd320ce2434406db605cb0\b9c03929b4b84a5745c0aa87\ce285c044d164510f06fa183\#name
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\00148b88c4114b5008fb869b\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\00148b88c4114b5008fb869b\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\00148b88c4114b5008fb869b\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\00148b88c4114b5008fb869b\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\00148b88c4114b5008fb869b\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\00148b88c4114b5008fb869b\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\02e10b45783b4fd3d4f1039c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\02e10b45783b4fd3d4f1039c\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\02e10b45783b4fd3d4f1039c\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\02e10b45783b4fd3d4f1039c\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\14050c2070654e4e4f93dca0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\14050c2070654e4e4f93dca0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\14050c2070654e4e4f93dca0\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\14050c2070654e4e4f93dca0\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\176e06c23aae4c85efa6298d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\176e06c23aae4c85efa6298d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\176e06c23aae4c85efa6298d\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\176e06c23aae4c85efa6298d\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\211039e526d94f958e798ba9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\211039e526d94f958e798ba9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\211039e526d94f958e798ba9\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\211039e526d94f958e798ba9\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\2bc7f0a2572c4062b83d67a2\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\2bc7f0a2572c4062b83d67a2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\2bc7f0a2572c4062b83d67a2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\2bc7f0a2572c4062b83d67a2\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\2d795ae1ee434e1fa4fd8aae\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\2d795ae1ee434e1fa4fd8aae\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\2d795ae1ee434e1fa4fd8aae\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\2d795ae1ee434e1fa4fd8aae\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\38e40bd16683449a220d77b0\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\38e40bd16683449a220d77b0\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\38e40bd16683449a220d77b0\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\38e40bd16683449a220d77b0\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\3cf9c497bd1b4ff84bdd60aa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\3cf9c497bd1b4ff84bdd60aa\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\3cf9c497bd1b4ff84bdd60aa\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\3cf9c497bd1b4ff84bdd60aa\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\3e74797b16df48f335d1e583\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\3e74797b16df48f335d1e583\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\3e74797b16df48f335d1e583\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\3e74797b16df48f335d1e583\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\4d1f4a144f6b4e3a18f0219f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\4d1f4a144f6b4e3a18f0219f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\4d1f4a144f6b4e3a18f0219f\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\4d1f4a144f6b4e3a18f0219f\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\4ee7f321f0944b83e29762a7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\4ee7f321f0944b83e29762a7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\4ee7f321f0944b83e29762a7\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\4ee7f321f0944b83e29762a7\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\503f6cc73d9d486d3f4875a5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\503f6cc73d9d486d3f4875a5\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\503f6cc73d9d486d3f4875a5\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\503f6cc73d9d486d3f4875a5\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5255f3a0b69341b5f707f7a1\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5255f3a0b69341b5f707f7a1\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5255f3a0b69341b5f707f7a1\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5255f3a0b69341b5f707f7a1\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\562e4d8e758a42df2a3c48b1\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\562e4d8e758a42df2a3c48b1\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\562e4d8e758a42df2a3c48b1\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\562e4d8e758a42df2a3c48b1\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5a542802d0a24139617f9db4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5a542802d0a24139617f9db4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5a542802d0a24139617f9db4\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5a542802d0a24139617f9db4\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5cb799e12deb4baaab16d393\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5cb799e12deb4baaab16d393\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5cb799e12deb4baaab16d393\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5cb799e12deb4baaab16d393\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5f9f643fca3b4fe1d7378087\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5f9f643fca3b4fe1d7378087\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5f9f643fca3b4fe1d7378087\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\5f9f643fca3b4fe1d7378087\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6174670d19cd423ad8ea98aa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6174670d19cd423ad8ea98aa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6174670d19cd423ad8ea98aa\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6174670d19cd423ad8ea98aa\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6175ed154bf840dba0fd908a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6175ed154bf840dba0fd908a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6175ed154bf840dba0fd908a\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6175ed154bf840dba0fd908a\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\68291d9d51c444429039629d\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\68291d9d51c444429039629d\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\68291d9d51c444429039629d\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\68291d9d51c444429039629d\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\68de55e9e06644e238799cbb\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\68de55e9e06644e238799cbb\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\68de55e9e06644e238799cbb\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\68de55e9e06644e238799cbb\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6b8e0cd2d4c7499a7f541a9b\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6b8e0cd2d4c7499a7f541a9b\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6b8e0cd2d4c7499a7f541a9b\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6b8e0cd2d4c7499a7f541a9b\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6c3d90ce3d6141dd5b89a0bc\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6c3d90ce3d6141dd5b89a0bc\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6c3d90ce3d6141dd5b89a0bc\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6c3d90ce3d6141dd5b89a0bc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6c3d90ce3d6141dd5b89a0bc\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6c3d90ce3d6141dd5b89a0bc\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6efd5500552b41c86b9ea997\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6efd5500552b41c86b9ea997\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6efd5500552b41c86b9ea997\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\6efd5500552b41c86b9ea997\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\73a76833c6f04a5545d024bc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\73a76833c6f04a5545d024bc\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\73a76833c6f04a5545d024bc\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\73a76833c6f04a5545d024bc\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7466862e0c9d45bbcf292dbc\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7466862e0c9d45bbcf292dbc\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7466862e0c9d45bbcf292dbc\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7466862e0c9d45bbcf292dbc\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7607292fa89c427dd88dbcb4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7607292fa89c427dd88dbcb4\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7607292fa89c427dd88dbcb4\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7607292fa89c427dd88dbcb4\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7fed20a882ea459afc2042b4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7fed20a882ea459afc2042b4\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7fed20a882ea459afc2042b4\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\7fed20a882ea459afc2042b4\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\82d7e259f9514c071c729298\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\82d7e259f9514c071c729298\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\82d7e259f9514c071c729298\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\82d7e259f9514c071c729298\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\8350254965764be641d82a9f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\8350254965764be641d82a9f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\8350254965764be641d82a9f\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\8350254965764be641d82a9f\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\8a4ccc576a4c4f1b22a50682\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\8a4ccc576a4c4f1b22a50682\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\8a4ccc576a4c4f1b22a50682\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\8a4ccc576a4c4f1b22a50682\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\97c765fa08cd42bed0650bb9\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\97c765fa08cd42bed0650bb9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\97c765fa08cd42bed0650bb9\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\97c765fa08cd42bed0650bb9\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\9ddf4ad5dad640edcce7f6af\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\9ddf4ad5dad640edcce7f6af\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\9ddf4ad5dad640edcce7f6af\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\9ddf4ad5dad640edcce7f6af\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\aee541af7588410f7073b2a3\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\aee541af7588410f7073b2a3\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\aee541af7588410f7073b2a3\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\aee541af7588410f7073b2a3\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b1bb78edd6da42450f4b1dbc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b1bb78edd6da42450f4b1dbc\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b1bb78edd6da42450f4b1dbc\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b1bb78edd6da42450f4b1dbc\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b303cfef7389418d4014eead\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b303cfef7389418d4014eead\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b303cfef7389418d4014eead\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b303cfef7389418d4014eead\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b4916595c7054d9b0de71aaa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b4916595c7054d9b0de71aaa\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b4916595c7054d9b0de71aaa\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b4916595c7054d9b0de71aaa\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b5d1f9b1c4b54beacf1d678a\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b5d1f9b1c4b54beacf1d678a\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b5d1f9b1c4b54beacf1d678a\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\b5d1f9b1c4b54beacf1d678a\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\c7a2d5f9468945fc3804e5ab\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\c7a2d5f9468945fc3804e5ab\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\c7a2d5f9468945fc3804e5ab\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\c7a2d5f9468945fc3804e5ab\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\cc18b093a7d94757fc015ea1\#data
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\cc18b093a7d94757fc015ea1\#data
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\cc18b093a7d94757fc015ea1\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\cc18b093a7d94757fc015ea1\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\cc18b093a7d94757fc015ea1\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\cc18b093a7d94757fc015ea1\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\ccb10dd39151423e6b09099f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\ccb10dd39151423e6b09099f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\ccb10dd39151423e6b09099f\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\ccb10dd39151423e6b09099f\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\ce9cfae5f0b94cb5752d48a2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\ce9cfae5f0b94cb5752d48a2\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\ce9cfae5f0b94cb5752d48a2\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\ce9cfae5f0b94cb5752d48a2\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\d83057b7a13f468a524117a8\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\d83057b7a13f468a524117a8\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\d83057b7a13f468a524117a8\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\d83057b7a13f468a524117a8\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\dfced775203b47aca85a3186\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\dfced775203b47aca85a3186\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\dfced775203b47aca85a3186\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\dfced775203b47aca85a3186\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\e66b51d54c17411aa48948b7\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\e66b51d54c17411aa48948b7\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\e66b51d54c17411aa48948b7\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\e66b51d54c17411aa48948b7\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f3528d29203041219750eb8f\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f3528d29203041219750eb8f\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f3528d29203041219750eb8f\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f3528d29203041219750eb8f\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f604f58053564987e7049cb9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f604f58053564987e7049cb9\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f604f58053564987e7049cb9\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f604f58053564987e7049cb9\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f6fe3db7508c42007040e3b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f6fe3db7508c42007040e3b5\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f6fe3db7508c42007040e3b5\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\f6fe3db7508c42007040e3b5\#startup
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\fcbef812a4db4ef10b4110b6\#internal
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\fcbef812a4db4ef10b4110b6\#internal
C:\Program Files\WinAntiSpyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\fcbef812a4db4ef10b4110b6\#startup
C:\Program Files\winantispyware 2007\RTMonitor.dat\722db612b7cd4da8b00472b8\fcbef812a4db4ef10b4110b6\#startup
C:\Program Files\winantispyware 2007\scanlog.xml
C:\Program Files\WinAntiSpyware 2007\scanlog.xml
C:\Program Files\winantispyware 2007\settings.ini
C:\Program Files\WinAntiSpyware 2007\settings.ini
C:\Program Files\winantispyware 2007\shellext.dll
C:\Program Files\WinAntiSpyware 2007\shellext.dll
C:\Program Files\winantispyware 2007\shellext.xml
C:\Program Files\WinAntiSpyware 2007\shellext.xml
C:\Program Files\WinAntiSpyware 2007\sr.log
C:\Program Files\winantispyware 2007\sr.log
C:\Program Files\WinAntiSpyware 2007\Summary.dat
C:\Program Files\winantispyware 2007\Summary.dat
C:\Program Files\WinAntiSpyware 2007\support.url
C:\Program Files\winantispyware 2007\support.url
C:\Program Files\WinAntiSpyware 2007\tasks.dat
C:\Program Files\winantispyware 2007\tasks.dat
C:\Program Files\WinAntiSpyware 2007\threatnet.dat
C:\Program Files\winantispyware 2007\threatnet.dat
C:\Program Files\winantispyware 2007\threatnet.ini
C:\Program Files\WinAntiSpyware 2007\threatnet.ini
C:\Program Files\winantispyware 2007\unins000.dat
C:\Program Files\WinAntiSpyware 2007\unins000.dat
C:\Program Files\winantispyware 2007\unins000.exe
C:\Program Files\WinAntiSpyware 2007\unins000.exe
C:\Program Files\winantispyware 2007\uninstall.ico
C:\Program Files\WinAntiSpyware 2007\uninstall.ico
C:\Program Files\winantispyware 2007\UnWizard.exe
C:\Program Files\WinAntiSpyware 2007\UnWizard.exe
C:\Program Files\winantispyware 2007\unwizard.xml
C:\Program Files\WinAntiSpyware 2007\unwizard.xml
C:\Program Files\winantispyware 2007\up.dat
C:\Program Files\WinAntiSpyware 2007\up.dat
C:\Program Files\WinAntiSpyware 2007\updater.dat
C:\Program Files\winantispyware 2007\updater.dat
C:\Program Files\WinAntiSpyware 2007\was7.exe
C:\Program Files\winantispyware 2007\was7.exe
C:\Program Files\winantispyware 2007\WAS7.url
C:\Program Files\WinAntiSpyware 2007\WAS7.url
C:\Program Files\winantispyware 2007\WAS7.xml
C:\Program Files\WinAntiSpyware 2007\WAS7.xml
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\b103.exe
C:\WINDOWS\b104.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b128.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\DOWNLO~1\UWA7P_0001_N91M0809NetInstaller.exe
C:\WINDOWS\Q2Vh\asappsrv.dll
C:\WINDOWS\Q2Vh\command.exe
C:\WINDOWS\retadpu1000106.exe
C:\WINDOWS\retadpu77.exe
C:\WINDOWS\svhost.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\byxwvwx.dll
C:\WINDOWS\system32\drivers\ApiMon.sys
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\f10WtR\f10WtR1099.exe
C:\WINDOWS\system32\jkklk.dll
C:\WINDOWS\SYSTEM32\klkkj.bak1
C:\WINDOWS\SYSTEM32\klkkj.bak2
C:\WINDOWS\SYSTEM32\klkkj.ini
C:\WINDOWS\SYSTEM32\klkkj.tmp
C:\WINDOWS\system32\ljjghhi.dll
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\stera.exe
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\X1
C:\WINDOWS\system32\X1\x22011.exe
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\tk58.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\wr.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_CMDSERVICE
-------\LEGACY_FOPN
-------\ApiMon
-------\cmdService
-------\fopn


((((((((((((((((((((((((( Files Created from 2007-07-19 to 2007-08-19 )))))))))))))))))))))))))))))))


2007-08-18 21:53 70,144 --a------ C:\Program Files\Common Files\lawug376.dll
2007-08-18 19:05 43,542 --a------ C:\WINDOWS\SYSTEM32\cbxvtrp.dll
2007-08-16 19:44 43,542 --a------ C:\WINDOWS\SYSTEM32\opnoljh.dll
2007-08-16 17:09 70,144 --a------ C:\Program Files\Common Files\lawug190.dll
2007-08-16 04:12 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
2007-08-16 03:14 70,144 --a------ C:\Program Files\Common Files\lawug4.dll
2007-08-15 22:54 <DIR> d--hs---- C:\WINDOWS\Q2Vh
2007-08-15 22:54 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon
2007-08-15 13:23 43,542 --a------ C:\WINDOWS\SYSTEM32\awtssqp.dll
2007-08-14 20:20 70,144 --a------ C:\Program Files\Common Files\lawug589.dll
2007-08-14 15:07 70,208 --a------ C:\WINDOWS\SYSTEM32\qdipgpie.dll
2007-08-14 13:03 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-14 13:02 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-08-13 15:54 31,254 --a------ C:\WINDOWS\SYSTEM32\tuvwtst.dll
2007-08-13 15:48 11,776 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\uwasfsd.sys
2007-08-13 15:08 70,144 --a------ C:\Program Files\Common Files\lawug521.dll
2007-08-13 15:06 70,208 --a------ C:\WINDOWS\SYSTEM32\spcdpdic.dll
2007-08-13 15:00 70,144 --a------ C:\Program Files\Common Files\lawug342.dll
2007-08-13 15:00 52,768 --a------ C:\WINDOWS\SYSTEM32\lqdsrngo.exe
2007-08-13 14:58 52,750 --a------ C:\WINDOWS\SYSTEM32\dwdsrngt.exe
2007-08-13 14:58 192,581 --a------ C:\WINDOWS\SYSTEM32\nwinrmdt.exe
2007-08-13 14:58 <DIR> d-------- C:\WINDOWS\SYSTEM32\checkdll
2007-08-11 20:58 51,200 --a------ C:\WINDOWS\nircmd.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-19 18:31 246 --a------ C:\Program Files\Common Files\lawug769
2007-08-14 20:20 246 --a------ C:\Program Files\Common Files\lawug521
2007-08-13 14:58 --------- d-------- C:\Program Files\Online Services
2007-08-11 20:50 --------- d-------- C:\Program Files\Spyware Doctor
2007-06-26 11:13 851968 --------- C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:35 665600 --------- C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 --------- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 --------- C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-15 04:12 96256 --------- C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-15 04:12 616960 --------- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-15 04:12 55808 --------- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-15 04:12 532480 --------- C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-15 04:12 474112 --------- C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-15 04:12 449024 --------- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-15 04:12 39424 --------- C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-15 04:12 357888 --------- C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-15 04:12 3064320 --------- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-15 04:12 251904 --------- C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-15 04:12 205824 --------- C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-15 04:12 16384 --------- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-15 04:12 151040 --------- C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-15 04:12 1498112 --------- C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-15 04:12 146432 --------- C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-15 04:12 1054208 --------- C:\WINDOWS\system32\dllcache\danim.dll
2007-06-15 04:12 1022976 --------- C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 06:32 18432 --------- C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 --------- C:\WINDOWS\system32\dllcache\explorer.exe
2005-07-29 20:24:26 472 --sha-r C:\WINDOWS\Q2Vh\kZp1.vbs


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{44218730-94E0-4b24-BBF0-C3D8B2BCE2C3}]
C:\WINDOWS\system32\nbepivpi.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6B058DC2-4924-405E-AABE-5C0E0F94ED90}]
C:\Program Files\Common Files\lawug769.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 15:33]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 22:15]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 18:54]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 03:01]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 03:05]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2004-12-28 00:51]
"Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-06-18 11:30]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-26 21:01]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-01-19 12:06]
"hosycat"="C:\Program Files\Online Services\hosycat22011.exe" [2007-08-07 16:30]
"svhost"="C:\WINDOWS\svhost.exe" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-19 18:38]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-21 18:39]
"Registry Cleaner"="C:\Program Files\Registry Cleaner Trial\RegClean.exe" [2005-08-22 17:20]
"wuok"="C:\Program Files\InetGet2\stub109_4_0_4_0.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Documents and Settings\Cea\Start Menu\Programs\Startup\
DESKTOP.INI [2004-08-10 15:04:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2004-08-10 15:04:12]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Common Files\progyrt.html
FriendlyName=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4567AB12-B980-44A5-B259-9B09EBEA6331}"= C:\Program Files\WinAntiSpyware 2007\shellext.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opoawgqr]
opoawgqr.dll 2006-07-28 06:30 188948 C:\WINDOWS\SYSTEM32\opoawgqr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrpopo]
rqrpopo.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xmvxrchw]
xmvxrchw.dll 2006-11-02 22:00 188948 C:\WINDOWS\SYSTEM32\xmvxrchw.dll

R0 uwasfsd;uwasfsd;C:\WINDOWS\system32\drivers\uwasfsd.sys
R3 IntelC51;IntelC51;C:\WINDOWS\system32\DRIVERS\IntelC51.sys
R3 IntelC52;IntelC52;C:\WINDOWS\system32\DRIVERS\IntelC52.sys
R3 IntelC53;IntelC53;C:\WINDOWS\system32\DRIVERS\IntelC53.sys
R3 mohfilt;mohfilt;C:\WINDOWS\system32\DRIVERS\mohfilt.sys
R3 senfilt;senfilt;C:\WINDOWS\system32\drivers\senfilt.sys
S2 DP1112;DP1112;\??\C:\WINDOWS\system32\Drivers\DP.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-19 19:21:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-19 19:23:53 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-19 19:23
C:\ComboFix2.txt ... 2007-08-11 21:04

--- E O F ---


ABBYY FineReader 5.0 Sprint Plus
Ad-Aware SE Personal
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 9
Adobe Reader 6.0.1
AVG 7.5
CCleaner (remove only)
Creative Jukebox Driver
Creative MediaSource
Creative MediaSource
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Media Experience
Dell Photo AIO Printer 922
Dell Picture Studio v3.0
Dell Support 5.0.0 (630)
Google Toolbar for Internet Explorer
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB926239)
Intel® 537EP V9x DF PCI Modem
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet for Wired Connections
Internet Explorer Default Page
iPod for Windows 2006-03-23
iTunes
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro 8 Dell Edition
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Musicmatch for Windows Media Player
Musicmatch® Jukebox
OIN
Panda ActiveScan
PowerDVD 5.3
Qualxserve Service Agreement
QuickTime
RealPlayer Basic
Registry Cleaner
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
SoundMAX
Spyware Doctor 4.0
Uninstall Property-Casualty Concepts Exam Review
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Verizon Online
WinAntiSpyware 2007 4.0.193.0
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Yahoo! Toolbar
YSIGet
Zen Micro Media Explorer







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:27:38 PM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Online Services\hosycat22011.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Registry Cleaner Trial\RegClean.exe
C:\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {44218730-94E0-4b24-BBF0-C3D8B2BCE2C3} - C:\WINDOWS\system32\nbepivpi.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: 0 - {6B058DC2-4924-405E-AABE-5C0E0F94ED90} - C:\Program Files\Common Files\lawug769.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [hosycat] C:\Program Files\Online Services\hosycat22011.exe
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\RegClean.exe"
O4 - HKCU\..\Run: [wuok] C:\Program Files\InetGet2\stub109_4_0_4_0.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u...pdate_1-0-0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: opoawgqr - C:\WINDOWS\SYSTEM32\opoawgqr.dll
O20 - Winlogon Notify: rqrpopo - rqrpopo.dll (file missing)
O20 - Winlogon Notify: xmvxrchw - C:\WINDOWS\SYSTEM32\xmvxrchw.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\progyrt.html

--
End of file - 8739 bytes

#8 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:02:23 AM

Posted 19 August 2007 - 06:57 PM

Good work! Let's continue.. :thumbsup: It's amazing how many infected files have infiltrated your PC.

It is a good idea to print off these instructions. There is a possibility some of the instructions will need to be carried out where internet access is not available. It is important that you complete the instructions in the right order, and that you don't miss out any steps.

Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {44218730-94E0-4b24-BBF0-C3D8B2BCE2C3} - C:\WINDOWS\system32\nbepivpi.dll (file missing)
O2 - BHO: 0 - {6B058DC2-4924-405E-AABE-5C0E0F94ED90} - C:\Program Files\Common Files\lawug769.dll (file missing)
O4 - HKLM\..\Run: [hosycat] C:\Program Files\Online Services\hosycat22011.exe
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKCU\..\Run: [wuok] C:\Program Files\InetGet2\stub109_4_0_4_0.exe
O20 - Winlogon Notify: opoawgqr - C:\WINDOWS\SYSTEM32\opoawgqr.dll
O20 - Winlogon Notify: rqrpopo - rqrpopo.dll (file missing)
O20 - Winlogon Notify: xmvxrchw - C:\WINDOWS\SYSTEM32\xmvxrchw.dll
O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\progyrt.html

Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Click on start, then control panel, and then double-click on add/remove programs.
From within add/remove program uninstall the following if they exist by double-clicking on the following entries:

Internet Explorer Default Page
OIN
WinAntiSpyware 2007 4.0.193.0


Please click on start > run > and type: sc stop DP1112
Hit enter and let the DOS windows open and close. This is normal.

Do the same for this command: sc delete DP1112

Click start > run and type: notepad, then hit enter.

File::
C:\Program Files\Common Files\lawug376.dll
C:\WINDOWS\SYSTEM32\cbxvtrp.dll
C:\WINDOWS\SYSTEM32\opnoljh.dll
C:\Program Files\Common Files\lawug190.dll
C:\Program Files\Common Files\lawug4.dll
C:\WINDOWS\SYSTEM32\awtssqp.dll
C:\Program Files\Common Files\lawug589.dll
C:\WINDOWS\SYSTEM32\qdipgpie.dll
C:\WINDOWS\SYSTEM32\tuvwtst.dll
C:\WINDOWS\SYSTEM32\DRIVERS\uwasfsd.sys
C:\Program Files\Common Files\lawug521.dll
C:\WINDOWS\SYSTEM32\spcdpdic.dll
C:\Program Files\Common Files\lawug342.dll
C:\WINDOWS\SYSTEM32\lqdsrngo.exe
C:\WINDOWS\SYSTEM32\dwdsrngt.exe
C:\WINDOWS\SYSTEM32\nwinrmdt.exe
C:\WINDOWS\system32\nbepivpi.dll
C:\Program Files\Common Files\lawug769.dll
C:\Program Files\Online Services\hosycat22011.exe
C:\WINDOWS\svhost.exe
C:\Program Files\Common Files\progyrt.html
C:\WINDOWS\SYSTEM32\opoawgqr.dll
C:\WINDOWS\SYSTEM32\xmvxrchw.dll

Folder::
C:\WINDOWS\Q2Vh
C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
C:\WINDOWS\SYSTEM32\checkdll
C:\Program Files\Common Files\lawug769
C:\Program Files\Common Files\lawug521
C:\Program Files\InetGet2
C:\Program Files\WinAntiSpyware 2007
C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon

Click File > Save and call it "ComboFix-Do.txt" (without quotes).
Save it to your desktop.
Posted Image
Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe
Combofix will run, and a text file will open. Please post it back here.

Also post a new Hijackthis log.

#9 td323i

td323i
  • Topic Starter

  • Members
  • 122 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 21 August 2007 - 05:34 PM

Hello,
When i drag ComboFix-Do.txt onto combofix.exe i receive the following errer;
Were you trying to run a CFScript? The name CFScript appears to be incorrectly spelt


Thanks,
Tony

#10 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:02:23 AM

Posted 21 August 2007 - 05:44 PM

Ahh I see. This is my fault; I went on holiday for a few weeks and they changed the format of the tool. :thumbsup:
Please rename the text file to "CFScript" instead and please retry the dragging onto the Combofix icon.

#11 td323i

td323i
  • Topic Starter

  • Members
  • 122 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 21 August 2007 - 05:55 PM

Hi David,
Thanks for the help.

ComboFix 07-08-09.3 - "Cea" 2007-08-21 18:43:12.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.207 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Cea\Desktop\AV Stuff\CFScript.txt
* Created a new restore point

FILE::
C:\Program Files\Common Files\lawug376.dll
C:\WINDOWS\SYSTEM32\cbxvtrp.dll
C:\WINDOWS\SYSTEM32\opnoljh.dll
C:\Program Files\Common Files\lawug190.dll
C:\Program Files\Common Files\lawug4.dll
C:\WINDOWS\SYSTEM32\awtssqp.dll
C:\Program Files\Common Files\lawug589.dll
C:\WINDOWS\SYSTEM32\qdipgpie.dll
C:\WINDOWS\SYSTEM32\tuvwtst.dll
C:\WINDOWS\SYSTEM32\DRIVERS\uwasfsd.sys
C:\Program Files\Common Files\lawug521.dll
C:\WINDOWS\SYSTEM32\spcdpdic.dll
C:\Program Files\Common Files\lawug342.dll
C:\WINDOWS\SYSTEM32\lqdsrngo.exe
C:\WINDOWS\SYSTEM32\dwdsrngt.exe
C:\WINDOWS\SYSTEM32\nwinrmdt.exe
C:\WINDOWS\system32\nbepivpi.dll
C:\Program Files\Common Files\lawug769.dll
C:\Program Files\Online Services\hosycat22011.exe
C:\WINDOWS\svhost.exe
C:\Program Files\Common Files\progyrt.html
C:\WINDOWS\SYSTEM32\opoawgqr.dll
C:\WINDOWS\SYSTEM32\xmvxrchw.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon
C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon\log.txt
C:\Program Files\Common Files\lawug190.dll
C:\Program Files\Common Files\lawug4.dll
C:\Program Files\Common Files\lawug521.dll
C:\Program Files\Common Files\lawug521\
C:\Program Files\Common Files\lawug589.dll
C:\Program Files\Common Files\lawug769\
C:\Program Files\Online Services\hosycat22011.exe
C:\WINDOWS\Q2Vh
C:\WINDOWS\Q2Vh\kZp1.vbs
C:\WINDOWS\SYSTEM32\awtssqp.dll
C:\WINDOWS\SYSTEM32\cbxvtrp.dll
C:\WINDOWS\SYSTEM32\checkdll
C:\WINDOWS\SYSTEM32\checkdll\d77012.exe
C:\WINDOWS\SYSTEM32\DRIVERS\uwasfsd.sys
C:\WINDOWS\SYSTEM32\dwdsrngt.exe
C:\WINDOWS\SYSTEM32\lqdsrngo.exe
C:\WINDOWS\SYSTEM32\nwinrmdt.exe
C:\WINDOWS\SYSTEM32\opnoljh.dll
C:\WINDOWS\SYSTEM32\opoawgqr.dll
C:\WINDOWS\SYSTEM32\qdipgpie.dll
C:\WINDOWS\SYSTEM32\spcdpdic.dll
C:\WINDOWS\SYSTEM32\tuvwtst.dll
C:\WINDOWS\SYSTEM32\xmvxrchw.dll


((((((((((((((((((((((((( Files Created from 2007-07-21 to 2007-08-21 )))))))))))))))))))))))))))))))


2007-08-16 04:12 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
2007-08-14 13:02 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-08-11 20:58 51,200 --a------ C:\WINDOWS\nircmd.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-21 18:45 --------- d-------- C:\Program Files\Online Services
2007-08-19 18:31 246 --a------ C:\Program Files\Common Files\lawug769
2007-08-14 20:20 246 --a------ C:\Program Files\Common Files\lawug521
2007-08-11 20:50 --------- d-------- C:\Program Files\Spyware Doctor
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
2007-06-26 11:13 851968 --------- C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:35 665600 --------- C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 --------- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 --------- C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-15 04:12 96256 --------- C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-15 04:12 616960 --------- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-15 04:12 55808 --------- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-15 04:12 532480 --------- C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-15 04:12 474112 --------- C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-15 04:12 449024 --------- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-15 04:12 39424 --------- C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-15 04:12 357888 --------- C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-15 04:12 3064320 --------- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-15 04:12 251904 --------- C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-15 04:12 205824 --------- C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-15 04:12 16384 --------- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-15 04:12 151040 --------- C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-15 04:12 1498112 --------- C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-15 04:12 146432 --------- C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-15 04:12 1054208 --------- C:\WINDOWS\system32\dllcache\danim.dll
2007-06-15 04:12 1022976 --------- C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 06:32 18432 --------- C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 --------- C:\WINDOWS\system32\dllcache\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 15:33]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 22:15]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 18:54]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 03:01]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-13 03:05]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2004-12-28 00:51]
"Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-06-18 11:30]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-26 21:01]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-01-19 12:06]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-19 18:38]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23]
"Registry Cleaner"="C:\Program Files\Registry Cleaner Trial\RegClean.exe" [2005-08-22 17:20]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Documents and Settings\Cea\Start Menu\Programs\Startup\
DESKTOP.INI [2004-08-10 15:04:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2004-08-10 15:04:12]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4567AB12-B980-44A5-B259-9B09EBEA6331}"= C:\Program Files\WinAntiSpyware 2007\shellext.dll [ ]

R3 IntelC51;IntelC51;C:\WINDOWS\system32\DRIVERS\IntelC51.sys
R3 IntelC52;IntelC52;C:\WINDOWS\system32\DRIVERS\IntelC52.sys
R3 IntelC53;IntelC53;C:\WINDOWS\system32\DRIVERS\IntelC53.sys
R3 mohfilt;mohfilt;C:\WINDOWS\system32\DRIVERS\mohfilt.sys
R3 senfilt;senfilt;C:\WINDOWS\system32\drivers\senfilt.sys
S0 uwasfsd;uwasfsd;C:\WINDOWS\system32\drivers\uwasfsd.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-21 18:47:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-21 18:49:32 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-21 18:49
C:\ComboFix2.txt ... 2007-08-19 19:23
C:\ComboFix3.txt ... 2007-08-11 21:04

--- E O F ---

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:55:01 PM, on 8/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Registry Cleaner Trial\RegClean.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\RegClean.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u...pdate_1-0-0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

--
End of file - 7726 bytes

#12 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:02:23 AM

Posted 22 August 2007 - 05:59 AM

Ok, good stuff. Just a few more things to do.

It is a good idea to print off these instructions. There is a possibility some of the instructions will need to be carried out where internet access is not available. It is important that you complete the instructions in the right order, and that you don't miss out any steps.

Please set your system to show all files.
Click Start, open My Computer, select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.

Open hijackthis, click 'config' (bottom right) Choose the tab 'misc Tools' on top.
Choose 'delete a file on reboot'. In the field, copy and paste the filepath a few lines below.
Click open. Hijackthis will tell you that this file will be deleted on next reboot and if you want to reboot now.
When asked if you want to reboot now, say Yes:
C:\WINDOWS\system32\drivers\uwasfsd.sys

Allow the PC to reboot, if it doesn't do it automatically, please reboot manually.

Now reboot into Safe Mode.
This can be done tapping the F8 key as soon as you start your computer
You will be brought to a menu where you can choose to boot into safe mode.
Make sure you choose the option without networking support.

Using Windows Explorer, please locate the following files/folders, and delete them if still present:

C:\Program Files\Common Files\lawug769
C:\Program Files\Common Files\lawug521
C:\Program Files\WinAntiSpyware 2007

Boot back into normal mode.

Please open notepad and and copy and paste next bold in it:
(don't forget to copy and paste REGEDIT4)

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4567AB12-B980-44A5-B259-9B09EBEA6331}"=-

Save this as "fix.reg" Choose to save as *all files and place it on your desktop.
It should look like this: Posted Image
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.

Please click on start > run > and type: sc stop "uwasfsd"
Hit enter and let the DOS windows open and close. This is normal.

Do the same for this command --> sc delete "uwasfsd"

Reboot again and post a new Hijackthis log.
Also let me know how the system is running! :thumbsup:

#13 td323i

td323i
  • Topic Starter

  • Members
  • 122 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 22 August 2007 - 09:37 PM

Hi Dave,
The computer seems to be running better.. Hopefully after a few more removals it will be 100%


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:24 PM, on 8/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Registry Cleaner Trial\RegClean.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\RegClean.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u...pdate_1-0-0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

--
End of file - 7823 bytes

#14 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:02:23 AM

Posted 23 August 2007 - 05:37 AM

Things are looking a lot better!

Please perform this online scan: Kaspersky Webscan
Note that this scanner will only work on Internet Explorer, so please use this browser for the scan.
Read the Requirements and Privacy statement, then select "Accept"
A dialogue box will appearing asking "Do you want to install this software?" Name: kavwebscan_unicode.cab
Select "Install" to download the ActiveX controls that allows ActiveScan to run.

When the download is complete it will say ready, click "Next"
Select a target to scan: Click on "My Computer"
When the scan is complete choose to save the results as "Save as Text"
Post the Kaspersky scan results in your next reply, along with a new Hijackthis log.

#15 td323i

td323i
  • Topic Starter

  • Members
  • 122 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 23 August 2007 - 08:17 PM

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, August 23, 2007 9:14:23 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 24/08/2007
Kaspersky Anti-Virus database records: 388398
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 51792
Number of viruses found: 35
Number of infected objects: 357
Number of suspicious objects: 0
Duration of the scan process: 00:53:34

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped
C:\Documents and Settings\Cea\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Temp\JETC042.tmp Object is locked skipped
C:\Documents and Settings\Cea\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cea\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Cea\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Hijackthis\backups\backup-20070811-204836-726.dll Object is locked skipped
C:\Hijackthis\backups\backup-20070811-204837-216.dll Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\Hijackthis\backups\backup-20070811-204837-922.dll Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard\WapCHK.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard\WapCHK{03DCA7C5-4595-4E33-A842-726AA32A716E}.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard\WapCHK{101344C0-2E3A-4ED4-9EEC-9E0D57A6BBFC}.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard\WapCHK{1358B96B-595E-427C-B709-963A811D208F}.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard\WapCHK{50971E8E-1B30-40B8-AB3B-937CCE43842B}.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard\WapCHK{E01C10EE-FD11-4B90-BEDE-B5331E575AA7}.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard\WapCHK{F2333FB6-BC18-40FB-9734-F612FF15E117}.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Companion Wizard\WapCHK{F3EB0DB7-8782-4A05-9733-DC80E4D9F6F0}.dll.vir Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\lawug190.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\lawug4.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\lawug521.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\lawug589.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasdc.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\WinAntiSpyware 2006 Free\uwasers.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1122OinAdmin.exe.vir Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\QooBox\Quarantine\C\Program Files\InetGet2\stub109_4_0_4_0.exe.vir Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
C:\QooBox\Quarantine\C\Program Files\Network Monitor\netmon.exe.vir Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\QooBox\Quarantine\C\Program Files\Online Services\hosycat22011.exe.vir Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\QooBox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\QooBox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir Inno: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\b104.exe.vir/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\QooBox\Quarantine\C\WINDOWS\b104.exe.vir/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\QooBox\Quarantine\C\WINDOWS\b104.exe.vir/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\QooBox\Quarantine\C\WINDOWS\b104.exe.vir NSIS: infected - 3 skipped
C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\QooBox\Quarantine\C\WINDOWS\b128.exe.vir/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\QooBox\Quarantine\C\WINDOWS\b128.exe.vir/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\QooBox\Quarantine\C\WINDOWS\b128.exe.vir/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\QooBox\Quarantine\C\WINDOWS\b128.exe.vir/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\QooBox\Quarantine\C\WINDOWS\b128.exe.vir NSIS: infected - 4 skipped
C:\QooBox\Quarantine\C\WINDOWS\b138.exe.vir Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\QooBox\Quarantine\C\WINDOWS\DOWNLO~1\USYP_0002_N91M1708NetInstaller.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\QooBox\Quarantine\C\WINDOWS\DOWNLO~1\UWA7P_0001_N91M0809NetInstaller.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\QooBox\Quarantine\C\WINDOWS\Q2Vh\asappsrv.dll.vir Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\QooBox\Quarantine\C\WINDOWS\Q2Vh\command.exe.vir Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\QooBox\Quarantine\C\WINDOWS\retadpu1000106.exe.vir Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\QooBox\Quarantine\C\WINDOWS\retadpu77.exe.vir Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\QooBox\Quarantine\C\WINDOWS\svhost.exe.vir Infected: Trojan-Proxy.Win32.VB.x skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ashrtytd.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\awtssqp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\bhtdhjrf.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\byxwvwx.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\cbxvtrp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\checkdll\d77012.exe.vir Infected: Virus.Win32.Virut.i skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\clslbnom.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ddayy.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\dwdsrngt.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\exibitpa.dll.vir Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\f02WtR\f02WtR1065.exe.vir Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\f10WtR\f10WtR1099.exe.vir Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hxdpbrki.dll.vir Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jmlkrsin.dll.vir Infected: Trojan.Win32.BHO.g skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\kyotbwvj.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ljjghhi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ljjigfg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bo skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\lqdsrngo.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\mpkxtcqr.dll.vir Infected: Trojan.Win32.BHO.g skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\nfhllhnd.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\nwinrmdt.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.r skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\opnoljh.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\opoawgqr.dll.vir Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\pvrglxvc.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\tqkrrwxg.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\tuvwtst.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ubwgfslf.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\umkinywj.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\utocijsq.dll.vir Infected: Trojan.Win32.BHO.o skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\vtsqrpm.dll.vir Infected: Trojan-Downloader.Win32.ConHook.ab skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\X1\x22011.exe.vir/data0004 Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\X1\x22011.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\xmidrduk.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\xmvxrchw.dll.vir Infected: Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\tk58.exe.vir Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP651\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP651\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP652\A0163985.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP652\A0163986.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP652\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP652\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\A0164002.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\A0164003.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\A0164013.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\A0164014.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\A0164024.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\A0164025.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\A0164035.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\A0164036.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP653\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP654\A0164048.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP654\A0164049.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP654\A0164059.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP654\A0164060.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP654\A0164070.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP654\A0164071.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP654\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP654\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP655\A0164084.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP655\A0164085.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP655\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP655\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0164098.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0164099.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0164106.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0164107.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0164118.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\A0164119.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP656\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP657\A0164132.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP657\A0164133.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP657\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP657\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP658\A0164146.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP658\A0164147.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP658\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP658\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP659\A0164160.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP659\A0164161.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP659\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP659\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP660\A0164171.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP660\A0164172.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP660\A0164182.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP660\A0164183.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP660\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP660\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP661\A0165182.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP661\A0165183.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP661\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP661\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP662\A0165195.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP662\A0165196.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP662\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP662\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP663\A0165209.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP663\A0165210.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP663\A0165220.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP663\A0165221.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP663\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP663\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP664\A0165235.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP664\A0165236.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP664\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP664\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP665\A0165249.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP665\A0165250.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP665\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP665\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP666\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP666\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP667\A0165273.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP667\A0165274.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP667\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP667\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP668\A0165287.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP668\A0165288.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP668\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP668\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP669\A0165354.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP669\A0165355.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP669\A0165375.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP669\A0165376.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP669\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP669\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP670\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP670\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP671\A0165393.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP671\A0165394.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP671\A0165404.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP671\A0165405.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP671\A0165415.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP671\A0165416.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP671\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP671\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP672\A0165429.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP672\A0165430.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP672\A0165440.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP672\A0165441.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP672\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP672\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP673\A0165454.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP673\A0165455.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP673\A0165465.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP673\A0165466.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP673\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP673\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP674\A0165479.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP674\A0165480.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP674\A0165490.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP674\A0165491.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP674\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP674\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP675\A0165518.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP675\A0165519.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP675\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP675\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP676\A0165545.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP676\A0165546.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP676\A0165561.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP676\A0165562.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP676\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP676\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP677\A0165575.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP677\A0165576.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP677\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP677\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP678\A0165589.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP678\A0165590.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP678\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP678\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\A0165603.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\A0165604.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\A0165614.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\A0165615.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\A0165625.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\A0165626.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\A0165636.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\A0165637.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP679\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0165650.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0165651.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0165661.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0165662.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0165672.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0165673.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0165684.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\A0165685.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP680\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP681\A0165698.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP681\A0165699.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP681\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP681\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP682\A0165711.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP682\A0165712.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP682\A0165722.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP682\A0165723.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP682\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP682\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP683\A0165735.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP683\A0165736.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP683\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP683\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP684\A0165749.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP684\A0165750.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP684\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP684\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP685\A0165765.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP685\A0165766.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP685\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP685\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP686\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP686\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP687\A0165784.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP687\A0165785.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP687\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP687\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP688\A0165799.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP688\A0165800.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP688\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP688\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP689\A0165810.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP689\A0165811.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP689\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP689\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\A0165873.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\A0165874.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\A0165892.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\A0165893.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\A0165903.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\A0165904.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\A0165914.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\A0165915.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP690\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP691\A0165930.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP691\A0165931.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP691\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP691\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP692\A0165942.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP692\A0165943.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP692\A0165953.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP692\A0165954.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP692\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP692\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP693\A0165968.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP693\A0165969.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP693\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP693\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP694\A0165988.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP694\A0165989.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP694\A0165999.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP694\A0166000.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP694\A0166010.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP694\A0166011.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP694\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP694\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP695\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP695\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP696\A0166024.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP696\A0166025.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP696\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP696\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP697\A0166038.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP697\A0166039.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP697\A0166048.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP697\A0166049.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP697\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP697\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP698\A0166061.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP698\A0166062.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP698\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP698\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP699\A0166077.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP699\A0166078.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP699\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP699\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP700\A0166093.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP700\A0166094.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP700\A0166103.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP700\A0166104.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP700\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP700\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP701\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP701\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP702\A0166121.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP702\A0166122.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP702\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP702\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP703\A0166135.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP703\A0166136.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP703\A0166146.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP703\A0166147.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP703\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP703\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP704\A0166160.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP704\A0166161.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP704\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP704\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP705\A0166176.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP705\A0166177.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP705\A0166187.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP705\A0166188.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP705\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP705\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP706\A0166202.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP706\A0166203.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP706\A0166216.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP706\A0166217.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP706\A0166227.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP706\A0166228.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP706\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP706\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP707\A0166246.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP707\A0166247.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP707\A0166257.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP707\A0166258.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP707\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP707\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP708\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP708\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP709\A0166280.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP709\A0166281.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP709\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP709\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP710\A0166292.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP710\A0166293.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP710\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP710\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP711\A0166306.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP711\A0166307.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP711\A0166317.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP711\A0166318.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP711\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP711\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP712\A0166330.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP712\A0166331.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP712\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP712\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP713\A0166344.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP713\A0166345.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP713\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP713\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP714\A0166359.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP714\A0166360.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP714\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP714\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP715\A0166377.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP715\A0166378.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP715\A0166389.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP715\A0166390.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP715\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP715\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP716\A0166405.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP716\A0166406.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP716\A0166416.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP716\A0166417.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP716\A0166425.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP716\A0166426.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP716\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP716\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166440.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166441.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166452.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166453.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166467.dll Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166469.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166470.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166484.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\A0166485.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP717\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166513.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166514.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166515.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166516.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166517.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166518.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166519.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166520.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166521.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bo skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166522.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166523.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166524.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166525.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166526.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166527.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166528.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166529.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166530.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166532.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166533.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166534.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166535.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166536.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166537.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166538.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166539.dll Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166548.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166549.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166645.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166646.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166656.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\A0166657.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP718\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166666.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166667.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166678.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166679.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166687.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166692.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166693.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166703.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166706.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0166709.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0167692.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\A0167693.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP719\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0167718.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0167719.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0167729.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0167736.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0167737.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0167746.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0167756.exe Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0168742.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0168754.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0168756.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\A0168758.exe Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP720\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0168815.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0168816.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0168844.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0169815.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0169816.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0169825.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\A0169828.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP721\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP722\A0169833.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP722\A0169834.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP722\A0169843.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP722\A0169845.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP722\A0169850.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP722\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP722\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\A0169858.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\A0169859.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\A0169868.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\A0169869.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\A0169876.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\A0169878.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\A0169879.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\A0169890.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP723\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170878.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170879.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170889.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170897.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170898.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170899.exe Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170900.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170901.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\A0170903.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP724\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170931.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170932.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170936.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170937.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170938.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170939.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170940.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170941.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170942.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170943.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170944.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170945.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170946.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170947.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170948.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170949.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170950.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170951.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170952.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170953.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170954.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170955.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170956.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170957.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170958.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170959.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170960.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170961.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170962.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170963.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170964.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170965.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170966.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170967.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170968.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170969.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170974.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170977.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170978.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170981.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170982.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170982.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170982.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170982.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170983.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170984.exe/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170984.exe/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170984.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170984.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170984.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170985.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170986.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170987.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170988.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170989.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170990.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170991.exe Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170992.exe Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170993.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0170994.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171000.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171000.exe Inno: infected - 1 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171007.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171011.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171012.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171013.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171014.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171015.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171016.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171017.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171018.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171019.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171020.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171021.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171022.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171023.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171024.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171025.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171026.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171027.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171028.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171029.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171030.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171031.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171032.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171033.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171034.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171036.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171041.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171144.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\A0171146.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\snapshot\MFEX-1.DAT Infected: Trojan-Proxy.Win32.Agent.jz skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP725\snapshot\MFEX-2.DAT Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171187.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171191.exe Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171192.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171193.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171194.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171195.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171196.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171197.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171198.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171199.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171201.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171202.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171203.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171204.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171205.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.r skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171206.exe Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171207.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP726\A0171208.dll Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP727\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\aiammcns.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\akxbdful.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\aoctulqu.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\apktirdt.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\aqvelwgi.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\aqxxpeep.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\aswjhcnb.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\atfsjvvj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.am skipped
C:\WINDOWS\SYSTEM32\auknyspy.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\aumnubqs.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\axdsiiau.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\aytytipl.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\bcicxner.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\bkecrphf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\bkigyhif.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\bnvxcjtr.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\bpmmjvmr.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\bqoagvrp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\brkkouwr.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\bryadrhi.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\caxminpk.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\cupjjlit.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\cwipqnlf.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\cyguphxa.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\cypjbjtn.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\dcckuthp.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\deuqeehi.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\dipgehqo.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\diptqvml.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\dkjpvxro.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ebihjnux.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\efjofvmd.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\elbkveun.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\enexaxrf.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\enupmguj.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\esltqgfq.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\etiwgrgx.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\exbjdylt.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\fbouqgly.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\fdbktmnl.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\fjoopsot.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\fjyroypt.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\fkmcytvg.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\fkplbwyk.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\fmebfcmo.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\fvuylcwo.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\fwcrqykq.dll Infected: not-a-virus:AdWare.Win32.BHO.v skipped
C:\WINDOWS\SYSTEM32\fxptnkmi.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\fyigmvuq.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\fykvqevf.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\gcnxaarp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\gdkgwuse.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\gftcqjbh.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ggyieuut.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\gjpvxtrv.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\grtksrsu.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\gsepthig.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\gttoveno.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\guunasol.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\gxuwxjfd.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\gytmooya.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\haojougd.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\hckbjmyc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\hfgegggf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\hilxlqot.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\hkhfiprd.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\hklhdpim.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\hlsdecnt.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\hmtcjytm.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\hoyregnr.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\hqymbqph.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\htgkpjpy.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\hxkpnjyi.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\hyokheak.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ibloxhsu.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ijmebbit.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\ijvquwgu.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\isvlgkwq.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\iwprtotm.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\ixclnuwi.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\iykqdxru.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\jbutvlwk.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\jgbvycjj.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\jkklm.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\jldkdvnu.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\jlvlpwvp.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\jnkyhwhx.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\jnxfpukd.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\jpsdmkuw.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\jpwutdat.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\jqyyuqdg.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\jrexwdne.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\jtbewicv.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\jurtxsnd.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\jvlslyac.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\jwcffgxm.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\jwnmcgyv.dll Infected: Packed.Win32.Klone.j skipped
C:\WINDOWS\SYSTEM32\jydvnvvl.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\kabhaidl.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kacftqte.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kawxohym.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kbapywjl.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\kcqfvvbb.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\kegbkjhc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\keruxrfv.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kesnbjji.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kgnhwbtl.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\khlsggyu.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\khrilpnw.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kjwgjuhg.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kntseslp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\knvlpgyb.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kpeyucys.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kpfixmsw.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\krtfjrgk.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\kyymycna.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\lapnfhvy.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\leapyiwn.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\lgpxvryt.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\lgthnnfr.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\lhtqobto.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\lhvvcubo.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\lirmaisa.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\liymhjue.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\llqmbpjc.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\lmaewhqy.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\lpuquojs.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\lsvamdbp.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\lvxdcxyc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\matfalhk.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mcipsdmq.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mdtqhxxe.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mexvldkf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mgdesxcp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mitxwamk.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mixydqfm.dll Infected: not-a-virus:AdWare.Win32.BHO.v skipped
C:\WINDOWS\SYSTEM32\mkagvsuk.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mkwscytm.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\mmjgqhem.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\moadgtgf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mqkitnxw.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mqvhcqqm.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\mrnkitlb.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\msemrrsw.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\mvyslgud.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\naiwxmci.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ncqdewnm.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ndarngbn.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\nfoouefw.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\nfxngked.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ngeegawx.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\nifheaaw.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\noxfwxbi.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\npcahpee.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\nqgfxvwm.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\nscfaojj.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\oafqioqa.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\obqytswq.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\ogjxrouw.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\ogpiliqb.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ohfewlom.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\ohqjlbmm.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\okhebjix.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\omueaxgy.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\oodnntvo.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\oosyaclo.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\ooupgdtw.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\otgrnwau.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\otgwovbm.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\otormoxk.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\otvpthdr.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ovhykpkv.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\owkoxtlt.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\pabdyfkd.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\pcekjwya.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\peoflhqq.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\pikaxdef.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\pimhfaaj.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\piuxyjah.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\pkieersm.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\pkpmsayb.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\prssgucc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ptthdqpq.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\pucmdkny.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\pvcpovdv.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\pxrreeua.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\pyaltmtx.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qbqbeyrh.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qcujrgom.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qeqgkhlm.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qescldwe.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\qfthpymi.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qhoprfsf.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\qiuchhex.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qkoxvnag.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\qlhumtoy.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qlilfmpq.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\qlqmoqfp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qthprauf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qucjyrwt.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qwbxgcxd.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\qxrdufln.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\qymyxbxa.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\rcviwvre.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\rddqrdhs.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\rdgpenlf.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\rdpwflvo.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\reybjlda.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\rgejycbv.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\rigogsps.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\rjwcfyqp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\rpgyuyrm.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\rssgupls.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\rvusuqkc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\rywpkbfx.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\sbjxjjwq.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\sfeksywr.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\sfhnnbvj.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\sfmnfidi.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\sjhtclaf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\slohgpbl.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\snhltqlf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\socmunrr.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\soiqicee.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\srniimko.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\srxkvijx.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\stexxhjw.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\stmqlfoa.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\svkwrrqt.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\swivgmwr.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\sxxrcwfe.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\taclialy.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\tblnfytq.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\tbswjlce.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tcugwfir.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tdbacpsu.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tessnpsj.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tfbdwvgv.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\tfcprdbn.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\thvyxxly.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\tjxdqpng.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\tkheroco.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tkkcturh.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\tknhltdq.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tlmnrvxq.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tltlyosv.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tludlmkt.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tpcpryvh.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\trcnbutb.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\trswanie.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\ttfaoesv.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tvabvhkr.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\tvsiwpqv.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\uavftblb.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\ucdwqkwt.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ucvpraun.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.cq skipped
C:\WINDOWS\SYSTEM32\ugphhttd.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\uhfwkjaj.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ujycqljg.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\ukovnglc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\uppjehoe.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\upyeepri.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\uqayyrbw.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\uuveygus.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\uxkeltoj.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\uxkhbwby.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\uxraqbgk.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.b skipped
C:\WINDOWS\SYSTEM32\vanxoaxu.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vbdwdpqf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vcyeoskv.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\vfchvpby.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\vfhllese.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vkchhfch.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vlaijuah.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vmcsjrwb.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vopdinjk.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vsousprc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vtgcuqfc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vugxqrec.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\vuyivusc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vvllhyvp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\vvssnnqb.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\vxnkkdau.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\vxqqvqxl.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbfiiktu.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wdwsweah.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wfedndxp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wfkjjyah.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\whiguojv.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\whnbxary.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\wlyvrnho.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wqwepfko.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wrrfflut.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wrtnhcpp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wsmvtqbb.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\wtapftgp.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wtvtgxxy.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wuumkles.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wvbggwtg.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wvhxdxun.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wvpotxfg.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wvvlffpb.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wxhbqlqx.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\wyxpkbti.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\xblwoaah.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\xcrhtiqa.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\xdvbmtok.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\xmkykdap.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\xniwlawb.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\xnldqckv.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\xpexsqrc.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\xptmggsd.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\xrhaxqcj.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\xusirhao.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\xuvqymwb.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\xvuyrwjk.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\xvylumhb.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\xxqoniip.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\xxxgmxva.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\ybnggyja.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ychorvmh.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ydagcudg.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ydmxftcq.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ygoyfjai.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\ygvqomlo.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\yhngmslo.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\yissoxgw.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ykakqjyn.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ykiihxbs.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ymuvfdrk.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\yorpuhaa.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\ysxilhyg.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\yuusqeqf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\yvfxjovy.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\yvtokbej.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\SYSTEM32\yxdxpdky.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\yxgjspmf.dll Object is locked skipped
C:\WINDOWS\SYSTEM32\yyvmlsjg.dll Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:12 PM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Registry Cleaner Trial\RegClean.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\RegClean.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - http://download.verizon.net/sfp/Cabs/max_u...pdate_1-0-0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

--
End of file - 7893 bytes




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users