Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Alot Popups Of The Same Thing.


  • This topic is locked This topic is locked
16 replies to this topic

#1 Snake_death2

Snake_death2

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 18 June 2008 - 01:26 PM

As the title saids, I'm having alot popups of the same kind. I thought it was "adultfriendfinder" or something.
I already scanned with anti-malware or anti-virus, so this is the only way left I can think of.
Here's the log: (not done in windows safe mode)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:25:12, on 18-6-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
E:\Telemeter\Telemeter 3.0\telemeter3.exe
C:\WINDOWS\system32\mmrtkrnl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
E:\videotune preformance\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
E:\Alcohol 120%\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Telemeter 3.0] "E:\Telemeter\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [Realtime Audio Engine] "mmrtkrnl.exe" /i
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [8ce403d2] rundll32.exe "C:\WINDOWS\system32\ngvdglcw.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "E:\Alcohol 120%\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [mount.exe] E:\MoveOnBoot\mount.exe /z
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - E:\videotune preformance\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - C:\WINDOWS\

--
End of file - 6198 bytes
Hell was too full so I came back.

BC AdBot (Login to Remove)

 


m

#2 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 18 June 2008 - 03:58 PM

Hello there and welcome to BleepingComputer. My name is Charles and I will be dealing with your log today.
Using My Computer, navigate to where you have HijackThis saved.
Right-click on the HijackThis.exe file.
Select "Rename", call it fluffybunny and press enter.
Use fluffybunny.exe from now on.

Download Combofix to your Desktop.
Double click combofix.exe
Follow the prompts that are displayed.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt.

Post that in your next reply with a fresh HijackThis log.
Thanks,
Charles :thumbsup:

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image


#3 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 19 June 2008 - 12:45 AM

Alright, here are the logs: (btw, why change the name :thumbsup:)

ComboFix:
ComboFix 08-06-16.5 - GrimReaper 2008-06-19 7:32:00.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.2852 [GMT 2:00]
Gestart vanuit: C:\Documents and Settings\GrimReaper\Bureaublad\ComboFix.exe
* Nieuw herstelpunt werd aangemaakt
* Resident AV is active


WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\bnxmssle.dll
C:\WINDOWS\system32\dypkopkl.dll
C:\WINDOWS\system32\ivbvbaad.dll
C:\WINDOWS\system32\jkkjGAtT.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlJAttUK.dll
C:\WINDOWS\system32\pilqysgs.dll
C:\WINDOWS\system32\sgsyqlip.ini
C:\WINDOWS\system32\thcvjegy.dll
C:\WINDOWS\system32\tsvyxyay.ini
C:\WINDOWS\system32\tsvyxyay.ini2
C:\WINDOWS\system32\yayxyvst.dll

.
(((((((((((((((((((( Bestanden Gemaakt van 2008-05-19 to 2008-06-19 ))))))))))))))))))))))))))))))
.

2008-06-11 07:13 . 2008-04-14 17:54 272,640 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 07:13 . 2008-04-14 17:54 272,640 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 15:53 . 2007-07-11 11:11 888,832 --a------ C:\WINDOWS\system32\securenet.dll
2008-06-04 20:33 . 2008-06-04 20:33 <DIR> d-------- C:\STRIPOID
2008-06-02 20:58 . 2008-06-02 20:58 <DIR> d-a------ C:\WINDOWS\__MACOSX
2008-06-02 20:58 . 2005-11-26 11:34 113,408 --a------ C:\WINDOWS\Cloister Black Light.ttf
2008-06-02 20:58 . 2005-11-26 11:33 53,008 --a------ C:\WINDOWS\Cloister Black BT.ttf
2008-06-02 20:58 . 2005-11-26 11:35 50,244 --a------ C:\WINDOWS\Old London.ttf
2008-06-02 20:58 . 2005-11-26 11:35 49,388 --a------ C:\WINDOWS\Old English Five.ttf
2008-06-02 20:56 . 2008-06-02 20:56 148,824 --a------ C:\WINDOWS\DNFont.zip
2008-05-29 22:27 . 2008-05-29 22:27 <DIR> d-------- C:\Program Files\Electronic Arts
2008-05-29 21:44 . 2008-06-18 16:14 <DIR> d-------- C:\Documents and Settings\GrimReaper\Application Data\Desktopicon
2008-05-24 23:25 . 2008-05-24 23:25 <DIR> d-------- C:\Program Files\Common Files\DirectX

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 05:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-29 18:07 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-20 10:33 22,328 ----a-w C:\Documents and Settings\GrimReaper\Application Data\PnkBstrK.sys
2008-05-20 06:00 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-15 15:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-10 14:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 18:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-26 18:00 --------- d-----w C:\Program Files\EBP - PRGR
.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"AlcoholAutomount"="E:\Alcohol 120%\Alcohol 120\axcmd.exe" [2007-12-22 09:23 221568]
"mount.exe"="E:\MoveOnBoot\mount.exe" [2008-03-22 20:42 374272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-10 11:08 16342528 C:\WINDOWS\RTHDCPL.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 00:12 49152]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 09:21 1443072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-18 20:55 8523776]
"nwiz"="nwiz.exe" [2007-12-18 20:55 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-18 20:55 81920]
"Telemeter 3.0"="E:\Telemeter\Telemeter 3.0\telemeter3.exe" [2007-04-16 00:38 1441792]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"Realtime Audio Engine"="mmrtkrnl.exe" [2007-07-18 16:52 70144 C:\WINDOWS\system32\mmrtkrnl.exe]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 18:34 86960]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15:00 15360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"F:\\DeusEx\\System\\DeusEx.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"E:\\limewire\\LimeWire.exe"=
"F:\\Crysis\\Bin32\\Crysis.exe"=
"F:\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=

R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-12-21 09:21]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2008-01-19 18:14]
S3 PciCon;PciCon;D:\PciCon.sys []
S3 XDva032;XDva032;C:\WINDOWS\system32\XDva032.sys []

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-19 07:38:29
Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\rundll32.exe
E:\videotune preformance\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
E:\Alcohol 120%\Alcohol 120\StarWind\StarWindServiceAE.exe
.
**************************************************************************
.
Voltooingstijd: 2008-06-19 7:41:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-19 05:41:51

Pre-Run: 23,871,819,776 bytes beschikbaar
Post-Run: 25,109,938,176 bytes beschikbaar

134 --- E O F --- 2008-06-11 05:57:48

HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:43:40, on 19-6-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
E:\Telemeter\Telemeter 3.0\telemeter3.exe
C:\WINDOWS\system32\mmrtkrnl.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
E:\videotune preformance\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
E:\Alcohol 120%\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
E:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\Spybot\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Telemeter 3.0] "E:\Telemeter\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [Realtime Audio Engine] "mmrtkrnl.exe" /i
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "E:\Alcohol 120%\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [mount.exe] E:\MoveOnBoot\mount.exe /z
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - E:\videotune preformance\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - C:\WINDOWS\

--
End of file - 6513 bytes
Hell was too full so I came back.

#4 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 19 June 2008 - 04:42 PM

We change the name because malware hides from the HJT file, please rename it.

Before we begin, please visit the page below, scroll down to the part which says "How to install and use the Windows XP Recovery Console," and follow those instructions:

How to download and use ComboFix

Then please run another scan with Combofix and post back the new log, along with a HijackThis log
Thanks,
Charles

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image


#5 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 20 June 2008 - 12:34 AM

Recovery Console installed succesfully. And here are the logs:

ComboFix:
ComboFix 08-06-16.5 - GrimReaper 2008-06-20 7:28:25.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.2876 [GMT 2:00]
Gestart vanuit: C:\Documents and Settings\GrimReaper\Bureaublad\ComboFix.exe
Command switches used :: C:\Documents and Settings\GrimReaper\Bureaublad\WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
* Nieuw herstelpunt werd aangemaakt
* Resident AV is active

.

(((((((((((((((((((( Bestanden Gemaakt van 2008-05-20 to 2008-06-20 ))))))))))))))))))))))))))))))
.

2008-06-11 07:13 . 2008-04-14 17:54 272,640 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 07:13 . 2008-04-14 17:54 272,640 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 15:53 . 2007-07-11 11:11 888,832 --a------ C:\WINDOWS\system32\securenet.dll
2008-06-04 20:33 . 2008-06-04 20:33 <DIR> d-------- C:\STRIPOID
2008-06-02 20:58 . 2008-06-02 20:58 <DIR> d-a------ C:\WINDOWS\__MACOSX
2008-06-02 20:58 . 2005-11-26 11:34 113,408 --a------ C:\WINDOWS\Cloister Black Light.ttf
2008-06-02 20:58 . 2005-11-26 11:33 53,008 --a------ C:\WINDOWS\Cloister Black BT.ttf
2008-06-02 20:58 . 2005-11-26 11:35 50,244 --a------ C:\WINDOWS\Old London.ttf
2008-06-02 20:58 . 2005-11-26 11:35 49,388 --a------ C:\WINDOWS\Old English Five.ttf
2008-06-02 20:56 . 2008-06-02 20:56 148,824 --a------ C:\WINDOWS\DNFont.zip
2008-05-29 22:27 . 2008-05-29 22:27 <DIR> d-------- C:\Program Files\Electronic Arts
2008-05-29 21:44 . 2008-06-18 16:14 <DIR> d-------- C:\Documents and Settings\GrimReaper\Application Data\Desktopicon
2008-05-24 23:25 . 2008-05-24 23:25 <DIR> d-------- C:\Program Files\Common Files\DirectX

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 05:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-30 19:59 5,632 ----a-w C:\WINDOWS\system32\BReWErS.dll
2008-05-29 18:07 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-29 18:07 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-05-20 10:33 669,184 ----a-w C:\WINDOWS\system32\pbsvc.exe
2008-05-20 10:33 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-05-20 10:33 22,328 ----a-w C:\Documents and Settings\GrimReaper\Application Data\PnkBstrK.sys
2008-05-20 06:00 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-15 15:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-10 14:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:16 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-03 18:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-26 18:00 --------- d-----w C:\Program Files\EBP - PRGR
2008-04-23 04:22 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 183,072 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:10 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
.

((((((((((((((((((((((((((((( snapshot@2008-06-19_ 7.41.44.17 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-19 05:38:07 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-20 05:10:28 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-20 05:10:56 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1fc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:00 15360]
"AlcoholAutomount"="E:\Alcohol 120%\Alcohol 120\axcmd.exe" [2007-12-22 09:23 221568]
"mount.exe"="E:\MoveOnBoot\mount.exe" [2008-03-22 20:42 374272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-10 11:08 16342528 C:\WINDOWS\RTHDCPL.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 00:12 49152]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 09:21 1443072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-18 20:55 8523776]
"nwiz"="nwiz.exe" [2007-12-18 20:55 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-18 20:55 81920]
"Telemeter 3.0"="E:\Telemeter\Telemeter 3.0\telemeter3.exe" [2007-04-16 00:38 1441792]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"Realtime Audio Engine"="mmrtkrnl.exe" [2007-07-18 16:52 70144 C:\WINDOWS\system32\mmrtkrnl.exe]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 18:34 86960]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15:00 15360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"F:\\DeusEx\\System\\DeusEx.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"E:\\limewire\\LimeWire.exe"=
"F:\\Crysis\\Bin32\\Crysis.exe"=
"F:\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=

R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-12-21 09:21]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2008-01-19 18:14]
S3 PciCon;PciCon;D:\PciCon.sys []
S3 XDva032;XDva032;C:\WINDOWS\system32\XDva032.sys []

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-20 07:30:29
Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen ...

scannen van verborgen autostart items ...

scannen van verborgen bestanden ...

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
Voltooingstijd: 2008-06-20 7:31:49
ComboFix-quarantined-files.txt 2008-06-20 05:31:45
ComboFix2.txt 2008-06-19 05:41:55

Pre-Run: 24,593,424,384 bytes beschikbaar
Post-Run: 25,029,738,496 bytes beschikbaar

WindowsXP-KB310994-SP2-Home-BootDisk-NLD.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

129 --- E O F --- 2008-06-11 05:57:48


HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:33:55, on 20-6-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
E:\Telemeter\Telemeter 3.0\telemeter3.exe
C:\WINDOWS\system32\mmrtkrnl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
E:\videotune preformance\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
E:\Alcohol 120%\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\Spybot\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Telemeter 3.0] "E:\Telemeter\Telemeter 3.0\telemeter3.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [Realtime Audio Engine] "mmrtkrnl.exe" /i
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "E:\Alcohol 120%\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [mount.exe] E:\MoveOnBoot\mount.exe /z
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - E:\videotune preformance\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - C:\WINDOWS\

--
End of file - 6424 bytes
Hell was too full so I came back.

#6 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 20 June 2008 - 02:53 PM

Please run a scan with Kaspersky Online Scanner.
You will be promted to install an ActiveX component from Kaspersky, click Yes.
The program will launch and then begin downloading the latest definition files.
Once the files have been downloaded click on Next.
Select a target to scan; click on My Computer.
The scan will take a while so be patient and let it run.
Once the scan is complete choose the option to Save as Text; they will be needed in your next reply.

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image


#7 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 20 June 2008 - 05:24 PM

The link didn't work so I downloaded and installed the latest trail version of it.
I'm not sure if this report will be the same as the one from the link you gave.

Here is the log:

Full Scan: completed 20-6-2008 23:34:17 (events: 351, objects: 339782, time: 1:12:27)
20-6-2008 23:34:17 Task completed
20-6-2008 23:34:16 Detected: Multi.Packed F:\Rome Total War - Gold Edition\pdrtw15t.rar/pztrain.exe/PE_Patch
20-6-2008 23:34:16 Untreated: Multi.Packed F:\Rome Total War - Gold Edition\pdrtw15t.rar/pztrain.exe/PE_Patch/MewBundle Skipped by user
20-6-2008 23:34:16 Detected: Multi.Packed F:\Rome Total War - Gold Edition\pdrtw15t.rar/pztrain.exe/PE_Patch/MewBundle
20-6-2008 23:34:16 Deleted: Trojan-PSW.Win32.Gadu.r c:\Documents and Settings\GrimReaper\Mijn documenten\JuegaNodBF.rar/JuegaNodBF\JuegaNodBF.exe
20-6-2008 23:34:16 Detected: Trojan-PSW.Win32.Gadu.r c:\Documents and Settings\GrimReaper\Mijn documenten\JuegaNodBF.rar/JuegaNodBF\JuegaNodBF.exe/PE_Patch.UPX/UPX
20-6-2008 23:34:14 Untreated: not-a-virus:AdWare.Win32.Altnet.o F:\System Volume Information\_restore{78393027-A9F8-48BA-BA5B-FAE0B3D21772}\RP31\A0001262.exe/data0014 Skipped by user
20-6-2008 23:34:13 Detected: not-a-virus:AdWare.Win32.Altnet.o F:\System Volume Information\_restore{78393027-A9F8-48BA-BA5B-FAE0B3D21772}\RP31\A0001262.exe/data0014
20-6-2008 23:34:11 Detected: Multi.Packed F:\Rome Total War - Gold Edition\pztrain.exe/PE_Patch
20-6-2008 23:34:11 Untreated: Multi.Packed F:\Rome Total War - Gold Edition\pztrain.exe/PE_Patch/MewBundle Skipped by user
20-6-2008 23:34:10 Detected: Multi.Packed F:\Rome Total War - Gold Edition\pztrain.exe/PE_Patch/MewBundle
20-6-2008 23:26:02 Detected: Multi.Packed F:\Rome Total War - Gold Edition\pztrain.exe/PE_Patch
20-6-2008 23:26:02 Untreated: Multi.Packed F:\Rome Total War - Gold Edition\pztrain.exe/PE_Patch/MewBundle Postponed
20-6-2008 23:26:02 Detected: Multi.Packed F:\Rome Total War - Gold Edition\pztrain.exe/PE_Patch/MewBundle
20-6-2008 23:26:01 Detected: Multi.Packed F:\Rome Total War - Gold Edition\pdrtw15t.rar/pztrain.exe/PE_Patch
20-6-2008 23:26:01 Untreated: Multi.Packed F:\Rome Total War - Gold Edition\pdrtw15t.rar/pztrain.exe/PE_Patch/MewBundle Postponed
20-6-2008 23:26:01 Detected: Multi.Packed F:\Rome Total War - Gold Edition\pdrtw15t.rar/pztrain.exe/PE_Patch/MewBundle
20-6-2008 23:04:11 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\zh_TW.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:11 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:11 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\sv.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:11 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\nl.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:11 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\nb.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:11 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\ko.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:11 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\ja.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:11 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\it.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\fr.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\fi.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\QuickTimeWebHelper.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\es.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\en.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\de.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeWebHelper.Resources\da.lproj\QuickTimeWebHelperLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\zh_TW.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\zh_CN.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\sv.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\nl.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:10 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\nb.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\ko.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\ja.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\it.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\fr.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\fi.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\es.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\en.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\de.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\da.lproj\QuickTimeVRLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeVR.Resources\QuickTimeVR.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\zh_TW.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\zh_CN.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\sv.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\nl.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\nb.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\ko.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\ja.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\it.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\fr.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\fi.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\en.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\es.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:09 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\de.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\zh_TW.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\da.lproj\QuickTimeStreamingExtrasLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingExtras.Resources\QuickTimeStreamingExtras.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\zh_CN.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\sv.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\nl.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\nb.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\ko.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\ja.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\it.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\fr.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\fi.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\es.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\en.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\de.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\da.lproj\QuickTimeStreamingAuthoringLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreamingAuthoring.Resources\QuickTimeStreamingAuthoring.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\zh_TW.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\zh_CN.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:08 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\sv.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\nl.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\nb.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\ko.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\ja.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\it.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\fr.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\fi.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\es.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\en.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\de.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\da.lproj\QuickTimeStreamingLocalized.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeStreaming.Resources\QuickTimeStreaming.qtr
20-6-2008 23:04:07 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\zh_TW.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\zh_CN.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\sv.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\nl.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\nb.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\ko.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\ja.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\it.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\fr.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\fi.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\es.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\en.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\de.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\da.lproj\QuickTimeQD3DLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\zh_TW.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeQD3D.Resources\QuickTimeQD3D.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\zh_CN.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\sv.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\nl.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\nb.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\ko.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\ja.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:06 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\it.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\fr.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\fi.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\es.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\en.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\de.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\da.lproj\QuickTimeMusicLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMusic.Resources\QuickTimeMusic.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\zh_TW.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\zh_CN.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\sv.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\nl.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\nb.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\ko.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\ja.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\it.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\fr.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\fi.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\es.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\en.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\da.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:05 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\de.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4Authoring.Resources\QuickTimeMPEG4Authoring.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\zh_TW.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\zh_CN.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\sv.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\nb.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\nl.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\ko.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\ja.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\it.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\fr.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\es.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\fi.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\en.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\de.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\da.lproj\QuickTimeMPEG4Localized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG4.Resources\QuickTimeMPEG4.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\zh_TW.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\zh_CN.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\sv.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\nl.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\nb.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:04 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\ko.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\ja.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\it.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\fr.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\fi.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\es.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\en.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\de.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\da.lproj\QuickTimeMPEGLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\zh_TW.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeMPEG.Resources\QuickTimeMPEG.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\zh_CN.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\sv.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\nl.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\nb.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\ko.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\ja.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:03 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\it.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\fr.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\fi.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\es.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\en.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\de.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\da.lproj\QuickTimeInternetExtrasLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeInternetExtras.Resources\QuickTimeInternetExtras.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\zh_TW.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\zh_CN.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\sv.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\nl.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\nb.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\ko.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:02 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\ja.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\it.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\fr.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\fi.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\es.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\en.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\de.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\da.lproj\QuickTimeImageLocalized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeImage.Resources\QuickTimeImage.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\zh_TW.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\zh_CN.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\sv.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\nl.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\nb.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\ko.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\ja.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\it.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\fr.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\fi.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\en.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\es.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\da.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:01 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\de.lproj\QuickTimeH264Localized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeH264.Resources\QuickTimeH264.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\zh_TW.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\zh_CN.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\sv.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\nl.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\nb.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\ko.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\it.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\ja.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\fr.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\fi.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\es.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\en.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\QuickTimeEssentials.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\de.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEssentials.Resources\da.lproj\QuickTimeEssentialsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\zh_TW.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\zh_CN.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\sv.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\nb.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:04:00 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\nl.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\ko.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\ja.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\fr.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\it.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\fi.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\es.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\en.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\de.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\da.lproj\QuickTimeEffectsLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\zh_TW.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeEffects.Resources\QuickTimeEffects.qtr
20-6-2008 23:03:59 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\zh_CN.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:58 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\sv.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:58 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\nl.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:58 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\nb.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:58 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\ko.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:58 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\ja.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:57 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\it.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:57 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\fr.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:57 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\fi.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:57 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\es.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:56 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\en.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:56 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\de.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:56 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\da.lproj\QuickTimeAuthoringLocalized.qtr
20-6-2008 23:03:55 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAuthoring.Resources\QuickTimeAuthoring.qtr
20-6-2008 23:03:55 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\zh_TW.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:55 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:55 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\sv.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:55 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\nl.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:55 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\nb.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:55 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\ko.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:54 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\ja.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:54 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\it.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:54 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\fr.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:54 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\fi.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:54 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\es.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:54 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:54 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\de.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:54 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\da.lproj\QuickTimeAudioSupportLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTimeAudioSupport.Resources\QuickTimeAudioSupport.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\zh_TW.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\zh_CN.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\sv.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\nl.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\nb.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\ko.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\ja.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\it.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\fr.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\fi.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\es.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\en.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\de.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:53 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\da.lproj\QuickTime3GPPAuthoringLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPPAuthoring.Resources\QuickTime3GPPAuthoring.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\zh_CN.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\zh_TW.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\nl.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\sv.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\ko.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\nb.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\it.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\ja.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\fr.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\fi.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\es.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\en.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\da.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\de.lproj\QuickTime3GPPLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime3GPP.Resources\QuickTime3GPP.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\zh_TW.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\zh_CN.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:52 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\sv.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:51 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\nl.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:51 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\nb.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:51 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\ko.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:51 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\ja.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:51 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\it.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:50 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\fr.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:50 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\fi.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:50 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\es.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:50 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\de.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\da.lproj\QuickTimeLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.Resources\QuickTime.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\zh_TW.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\zh_CN.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\sv.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\nl.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\nb.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\ko.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:49 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\ja.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:48 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\it.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:48 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\fr.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:48 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\fi.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:48 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\es.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:48 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\en.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:48 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\de.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:48 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\da.lproj\CoreVideoLocalized.qtr
20-6-2008 23:03:48 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\CoreVideo.Resources\CoreVideo.qtr
20-6-2008 23:03:44 Detected: http://www.viruslist.com/en/advisories/29293 E:\QuickTime Alternative\QTSystem\QuickTime.cpl
20-6-2008 23:01:45 Detected: http://www.viruslist.com/en/advisories/29434 E:\7-Zip\7zG.exe
20-6-2008 23:01:43 Detected: http://www.viruslist.com/en/advisories/29434 E:\7-Zip\7z.exe
20-6-2008 23:01:11 Detected: http://www.viruslist.com/en/advisories/28083 c:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
20-6-2008 23:01:09 Detected: http://www.viruslist.com/en/advisories/28083 c:\WINDOWS\system32\Macromed\Flash\swflash.ocx
20-6-2008 22:59:49 Detected: http://www.viruslist.com/en/advisories/29293 c:\WINDOWS\system32\QuickTime.qts
20-6-2008 22:48:28 Detected: http://www.viruslist.com/en/advisories/12430 c:\program files\winzip\winzip32.exe
20-6-2008 22:47:46 Detected: http://www.viruslist.com/en/advisories/28083 c:\program files\mozilla firefox\plugins\NPSWF32.dll
20-6-2008 22:47:37 Detected: http://www.viruslist.com/en/advisories/29787 c:\program files\mozilla firefox\firefox.exe
20-6-2008 22:43:11 Detected: http://www.viruslist.com/en/advisories/29239 c:\program files\Java\jre1.6.0_03\bin\java.exe
20-6-2008 22:42:51 Detected: http://www.viruslist.com/en/advisories/29239 c:\program files\Java\jre1.5.0_12\bin\java.exe
20-6-2008 22:38:08 Detected: http://www.viruslist.com/en/advisories/29321 c:\program files\Common Files\Microsoft Shared\Office10\MSO.DLL
20-6-2008 22:33:53 Untreated: Trojan-PSW.Win32.Gadu.r c:\Documents and Settings\GrimReaper\Mijn documenten\JuegaNodBF.rar/JuegaNodBF\JuegaNodBF.exe/PE_Patch.UPX/UPX Postponed
20-6-2008 22:33:53 Detected: Trojan-PSW.Win32.Gadu.r c:\Documents and Settings\GrimReaper\Mijn documenten\JuegaNodBF.rar/JuegaNodBF\JuegaNodBF.exe/PE_Patch.UPX/UPX
20-6-2008 22:28:25 Untreated: not-a-virus:AdWare.Win32.Altnet.o F:\System Volume Information\_restore{78393027-A9F8-48BA-BA5B-FAE0B3D21772}\RP31\A0001262.exe/data0014 Postponed
20-6-2008 22:28:25 Detected: not-a-virus:AdWare.Win32.Altnet.o F:\System Volume Information\_restore{78393027-A9F8-48BA-BA5B-FAE0B3D21772}\RP31\A0001262.exe/data0014
20-6-2008 22:23:47 Detected: http://www.viruslist.com/en/advisories/12430 c:\program files\winzip\winzip32.exe
20-6-2008 22:23:41 Detected: http://www.viruslist.com/en/advisories/29787 c:\program files\mozilla firefox\firefox.exe
20-6-2008 22:21:50 Task started
Full Scan: completed 20-6-2008 23:34:17 (events: 351, objects: 339782, time: 1:12:27)
20-6-2008 22:15:02 Task completed
20-6-2008 22:12:15 Task started
Hell was too full so I came back.

#8 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 21 June 2008 - 12:12 PM

Try this link instead: http://www.kaspersky.com/kos/english/kavwebscan.html

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image


#9 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 24 June 2008 - 03:45 PM

It's ok now. I had some trouble with the internet lately, because I reinstalled windows xp home edition (a few times).
After all the trouble I've been through, this one is cleared.
But now I'm afraid to install internet explorer 7 (which I prefer over firefox or the earlier version).
When I reinstalled windows xp I tried using the net again. Ofcourse, no internet, forgot the drivers for my main board. Well, after that everything is ok. Then after that I noticed I still had a setup for IE7 on my external harddrive, so I installed it.
After the first part of the setup I had to restart windows and so I did. I finished the installation, no problems, nothing weird.
Then when I tried to open any webpage, nothing came up. Some times it didn't load further than half of the loading bar and some times a message came up, saying "the page cannot be opened" or something similiar.
But the weird thing was, every setting I know of was set correctly. And when I used the "ping" command in ms-dos, all packages were received, so there must have been a connection to the internet. (I checked with firefox too and no connection)
When I got tired of it I reinstalled windows xp again. Now I have internet, but I use the early version of IE and sometimes firefox when I plan to use tabs.

Edited by Snake_death2, 24 June 2008 - 03:48 PM.

Hell was too full so I came back.

#10 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 25 June 2008 - 03:58 PM

Is everything running okay now, then?

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image


#11 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 26 June 2008 - 12:58 PM

Actually yes, but the only problem I have right now is, should I install explorer 7? Previous time it caused me nothing but trouble. (no internet)
Hell was too full so I came back.

#12 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 26 June 2008 - 03:10 PM

You don't have to install it, indeed it is completely optional; if you had problems with it before I would encourage you to perhaps not install it.

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image


#13 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 27 June 2008 - 03:35 AM

Ok, thanks.
But in all this time I used it, I didn't have a problem until I reinstalled my computer and then installed IE7...
Hell was too full so I came back.

#14 Snake_death2

Snake_death2
  • Topic Starter

  • Members
  • 70 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 27 June 2008 - 03:35 AM

Sorry for doublepost, computer must be lagging.

Edited by Snake_death2, 27 June 2008 - 03:36 AM.

Hell was too full so I came back.

#15 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:03:38 PM

Posted 30 June 2008 - 03:38 PM

Like I said, it's entirely up to you. Some people have problems, others don't; ultimately they can probably be resolved anyway.

Edited by rookie147, 30 June 2008 - 03:40 PM.

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users