Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HJT log


  • This topic is locked This topic is locked
8 replies to this topic

#1 mahadv

mahadv

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:39 PM

Posted 22 January 2009 - 06:33 PM

Hi,

My machine seems to have been infected with some backdoor type trojans. I ran malware bytes in safe mode, and it cleaned up a lot of infected objects. Then I installed and ran Kaspersky Labs scan which again cleaned some stuff. But I still see a message "Generic host process for win32 services" whenever i restart the machine.

I am posting the HJT log below. Can someone take a look and tell me if I need to do more to disinfect my machine?

thanks,
vijay

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:36:36 PM, on 1/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070623
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070623
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070623
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [jrcejzcz.exe] C:\WINDOWS\jrcejzcz.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/lib/ucsd/support/pl...s/ebraryRdr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3CBA13C3-58C7-47F1-9758-D4B255A50D52} (SESSearchCtrl Class) - http://www.svcl.ucsd.edu/private/proceedin...x/sessearch.ocx
O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - http://www.cooliris.com/shared/plinstll.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O17 - HKLM\Software\..\Telephony: DomainName = svc-dc.svcl.ucsd.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE9B937F-20A9-49FA-9DFE-4365576D69A0}: NameServer = 192.168.65.81,192.168.65.10,132.239.1.52
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O20 - Winlogon Notify: yecoyv - C:\WINDOWS\SYSTEM32\yecoyv.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

--
End of file - 9402 bytes

BC AdBot (Login to Remove)

 


#2 mahadv

mahadv
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:39 PM

Posted 22 January 2009 - 07:57 PM

I ran combofix on the machine and this is the log. The "Generic Win32 .." error message doesnt appear anymore..
Can someone look at the log and tell me if it looks clean?

thanks,
Vijay


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:09:45 PM, on 1/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070623
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070623
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/lib/ucsd/support/pl...s/ebraryRdr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3CBA13C3-58C7-47F1-9758-D4B255A50D52} (SESSearchCtrl Class) - http://www.svcl.ucsd.edu/private/proceedin...x/sessearch.ocx
O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - http://www.cooliris.com/shared/plinstll.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O17 - HKLM\Software\..\Telephony: DomainName = svc-dc.svcl.ucsd.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE9B937F-20A9-49FA-9DFE-4365576D69A0}: NameServer = 192.168.65.81,192.168.65.10,132.239.1.52
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

--
End of file - 8397 bytes

#3 aommaster

aommaster

    I !<3 malware


  • Malware Response Team
  • 5,289 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dubai
  • Local time:07:39 AM

Posted 23 January 2009 - 07:18 PM

Hello, Vijay.

My name is aommaster and I will be helping you with your log.

I apologize for the delay in response we get overwhelmed at times but we are trying our best to keep up.
If you have since resolved the original problem you were having would appreciate you letting us know If not please perform the following below so I can have a look at the current condition of your machine.

Thanks and again sorry for the delay.

Please note that I am in the process of my training so it may take a while for me to get back to you, as each of my fixes need to be checked by a coach first.
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
Next
Please do a scan with Kaspersky Online Scanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • RSIT Log
  • Kaspersky Log

My website: http://aommaster.com
unite_blue.png
Please do not send me PM's requesting for help. The forums are there for a reason : )
If I am helping you and do not respond to your thread for 48 hours, please send me a PM


#4 mahadv

mahadv
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:39 PM

Posted 26 January 2009 - 04:38 PM

Thanks for the response. I have attached the logs below. I installed a trial version of Kaspersky labs antivirus and have attached the log for that instead of the online scanner.


******************RSIT Info***************************************************
info.txt logfile of random's system information tool 1.05 2009-01-26 09:20:13

======Uninstall list======

-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
-->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
Adobe Acrobat 6.0.1 Professional-->MsiExec.exe /I{AC76BA86-1033-0000-7760-000000000001}
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.8-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
AFPL Ghostscript 8.14-->C:\gs\uninstgs.exe "C:\gs\gs8.14\uninstal.txt"
AFPL Ghostscript Fonts-->C:\gs\uninstgs.exe "C:\gs\fonts\uninstal.txt"
Apple Software Update-->MsiExec.exe /I{A260B422-70E1-41E2-957D-F76FA21266D5}
A-Z Video Converter Ultimate 6.88-->"C:\Program Files\A-Z\A-Z Video Converter Ultimate\unins000.exe"
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CoffeeCup HTML Editor 2007-->C:\PROGRA~1\COFFEE~1\UNWISE.EXE C:\PROGRA~1\COFFEE~1\INSTALL.LOG
Cooliris for Internet Explorer-->MsiExec.exe /I{B46BC183-3713-3814-9067-D1C6BC952F7B}
Core FTP LE 1.3c-->C:\PROGRA~1\CoreFTP\UNWISE.EXE C:\PROGRA~1\CoreFTP\INSTALL.LOG
Corel Paint Shop Pro Photo XI-->MsiExec.exe /I{93A1B09E-BAFA-4628-A5B6-921CB026955A}
Corel Snapfire Plus-->MsiExec.exe /I{7ADE3A47-B425-45E9-8FF6-11BE2B775645}
Dell CinePlayer-->MsiExec.exe /I{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}
Dell Driver Reset Tool-->MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
Dell Support 3.2.1-->MsiExec.exe /X{CEE2252C-4035-4B27-8EC6-0B085DD3A413}
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Talk (remove only)-->"C:\Program Files\Google\Google Talk\uninstall.exe"
Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
GPL Ghostscript 8.57-->C:\Program Files\gs\uninstgs.exe "C:\Program Files\gs\gs8.57\uninstal.txt"
GPL Ghostscript Fonts-->C:\Program Files\gs\uninstgs.exe "C:\Program Files\gs\fonts\uninstal.txt"
GSview 4.9-->C:\Program Files\Ghostgum\gsview\uninstgs.exe "C:\Program Files\Ghostgum\gsview\uninstal.txt"
High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Intel® Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
Intel® Matrix Storage Manager-->C:\WINDOWS\System32\Imsmudlg.exe
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Java™ 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Kaspersky Anti-Virus 2009-->MsiExec.exe /I{6580C5A3-2336-4EC5-85F1-3448C5F6208A}
Kaspersky Anti-Virus 2009-->MsiExec.exe /I{6580C5A3-2336-4EC5-85F1-3448C5F6208A}
LEd Beta 0.51-->"C:\Program Files\LEd\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MATLAB R2007a-->C:\Program Files\MATLAB\R2007a\uninstall\uninstall.exe C:\Program Files\MATLAB\R2007a\
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0-->C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Plus! Digital Media Edition Installer-->MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Plus! Photo Story 2 LE-->MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs-->MsiExec.exe /X{90120000-00B2-0409-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
MiKTeX 2.6-->"C:\Program Files\MiKTeX 2.6\miktex\bin\copystart_admin.exe" "C:\Program Files\MiKTeX 2.6\miktex\config\uninstall.dat"
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
Python 2.4 numarray-1.3.3-->"C:\Python24\Removenumarray.exe" -u "C:\Python24\numarray-wininst.log"
Python 2.4 Numeric-24.2-->"C:\Python24\RemoveNumeric.exe" -u "C:\Python24\Numeric-wininst.log"
Python 2.4 PIL-1.1.6-->"C:\Python24\RemovePIL.exe" -u "C:\Python24\PIL-wininst.log"
Python 2.4 pygame-1.7.1release-->"C:\Python24\Removepygame.exe" -u "C:\Python24\pygame-wininst.log"
Python 2.4 PyOpenGL-2.0.2.01-->"C:\Python24\RemovePyOpenGL.exe" -u "C:\Python24\PyOpenGL-wininst.log"
Python 2.4 visionegg-1.0-->"C:\Python24\Removevisionegg.exe" -u "C:\Python24\visionegg-wininst.log"
Python 2.4.4-->MsiExec.exe /I{60E2C8C9-6CF3-4B1A-9618-E304946C94E6}
QuickTime-->MsiExec.exe /I{08094E03-AFE4-4853-9D31-6D0743DF5328}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Roxio DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Roxio MyDVD LE-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Roxio RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Roxio RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Roxio RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
SearchAssist-->C:\DELL\SearchAssist\UninstSA.bat
Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Visio 2007 (KB947590)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Sonic Activation Module-->MsiExec.exe /I{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}
Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
SSH Secure Shell-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{74E2CD0C-D4A2-11D3-95A6-0000E86CFDE5}\Setup.exe"
Subversion 1.4.4-r25188-->"C:\Program Files\Subversion\unins000.exe"
TexPoint 2.0.3-->MsiExec.exe /I{D1284921-C0EE-4792-AB17-B492C43744C4}
Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
Update for Office 2007 (KB946691)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb959141)-->msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {CC6191C2-B0CE-473C-AD77-61EA3497D796}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
URL Assistant-->regsvr32 /u /s "C:\Program Files\BAE\BAE.dll"
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
VLC media player 0.9.4-->C:\Program Files\VideoLAN\VLC\uninstall.exe
WD Diagnostics-->MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 10-->MsiExec.exe /I{33BB4982-DC52-4886-A03B-F4C5C80BEE89}
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinMPG VideoConvert 6.8-->"C:\Program Files\WinMPG VideoConvert\unins000.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
XviD MPEG-4 Codec-->"C:\Program Files\XviD\UninstXviD.exe"
Yahoo! Browser Services-->C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Music Jukebox-->MsiExec.exe /X{7C49EA42-5647-4051-84C2-E6404F25A931}
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

======Security center information======

AV: Kaspersky Anti-Virus

System event log

Computer Name: CHANDRA
Event Code: 3
Message: Printer Microsoft XPS Document Writer (from VIJAY-NOTEBOOK) was deleted.

Record Number: 15711
Source Name: Print
Time Written: 20081225224045.000000-480
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: CHANDRA
Event Code: 4
Message: Printer Microsoft XPS Document Writer (from VIJAY-NOTEBOOK) is pending deletion.

Record Number: 15710
Source Name: Print
Time Written: 20081225224042.000000-480
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: CHANDRA
Event Code: 8
Message: Printer Microsoft XPS Document Writer (from VIJAY-NOTEBOOK) was purged.

Record Number: 15709
Source Name: Print
Time Written: 20081225224042.000000-480
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: CHANDRA
Event Code: 40961
Message: The Security System could not establish a secured connection with the server DNS/prisoner.iana.org. No authentication protocol was available.

Record Number: 15708
Source Name: LSASRV
Time Written: 20081225212939.000000-480
Event Type: warning
User:

Computer Name: CHANDRA
Event Code: 1111
Message: Driver Send To Microsoft OneNote Driver required for printer Send To OneNote 2007 is unknown. Contact the administrator to install the driver before you log in again.

Record Number: 15707
Source Name: TermServDevices
Time Written: 20081225212730.000000-480
Event Type: error
User:

Application event log

Computer Name: CHANDRA
Event Code: 1030
Message: Windows cannot query for the list of Group Policy objects. A message that describes the reason for this was previously logged by the policy engine.

Record Number: 5
Source Name: Userenv
Time Written: 20090121191948.000000-480
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: CHANDRA
Event Code: 1058
Message: Windows cannot access the file gpt.ini for GPO CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=svc-dc,DC=svcl,DC=ucsd,DC=edu. The file must be present at the location <\\svc-dc.svcl.ucsd.edu\sysvol\svc-dc.svcl.ucsd.edu\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>. (Incorrect function. ). Group Policy processing aborted.

Record Number: 4
Source Name: Userenv
Time Written: 20090121191948.000000-480
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: CHANDRA
Event Code: 1054
Message: Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.

Record Number: 3
Source Name: Userenv
Time Written: 20090121174644.000000-480
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: CHANDRA
Event Code: 0
Message:
Record Number: 2
Source Name: SBAMSvc
Time Written: 20090121174616.000000-480
Event Type: information
User:

Computer Name: CHANDRA
Event Code: 0
Message:
Record Number: 1
Source Name: SBAMSvc
Time Written: 20090121174614.000000-480
Event Type: information
User:

======Environment variables======

"APR_ICONV_PATH"=C:\Program Files\Subversion\iconv
"CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"NUMBER_OF_PROCESSORS"=2
"OS"=Windows_NT
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;c:\program files\miktex 2.6\miktex\bin;c:\program files\intel\dmix;c:\program files\common files\roxio shared\dllshared;c:\program files\quicktime\qtsystem;C:\Program Files\MATLAB\R2007a\bin;C:\Program Files\MATLAB\R2007a\bin\win32;;C:\Program Files\Subversion\bin;C:\gs\gs8.14\bin
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 5, GenuineIntel
"PROCESSOR_LEVEL"=15
"PROCESSOR_REVISION"=0605
"QTJAVA"=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
"SonicCentral"=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"windir"=%SystemRoot%

-----------------EOF-----------------


******************RSIT Log***************************************************

Logfile of random's system information tool 1.05 (written by random/random)
Run by vijay at 2009-01-26 09:20:04
Microsoft Windows XP Professional Service Pack 3
System drive C: has 114 GB (76%) free of 149 GB
Total RAM: 1014 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:20:10 AM, on 1/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\cygwin\usr\X11R6\bin\XWin.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\cygwin\bin\xterm.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\cygwin\bin\bash.exe
C:\cygwin\bin\sh.exe
C:\cygwin\bin\rlogin.exe
C:\cygwin\bin\rlogin.exe
C:\Documents and Settings\Vijay.SVC-DC\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\vijay.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070623
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://education.dellnet.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: MWOL &Dictionary - res://C:\WINDOWS\_MWOLTB.DLL/23/219
O8 - Extra context menu item: MWOL &Thesaurus - res://C:\WINDOWS\_MWOLTB.DLL/23/220
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/lib/ucsd/support/pl...s/ebraryRdr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3CBA13C3-58C7-47F1-9758-D4B255A50D52} (SESSearchCtrl Class) - http://www.svcl.ucsd.edu/private/proceedin...x/sessearch.ocx
O16 - DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - http://www.cooliris.com/shared/plinstll.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O17 - HKLM\Software\..\Telephony: DomainName = svc-dc.svcl.ucsd.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE9B937F-20A9-49FA-9DFE-4365576D69A0}: NameServer = 192.168.65.81,192.168.65.10,132.239.1.52
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = svc-dc.svcl.ucsd.edu
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

--
End of file - 8217 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1650842470-4203624185-2766465924-1143.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{BEEE7492-8D47-49D1-93DF-0E7B4EC16A43}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2007-05-30 808472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll [2003-11-03 54248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-05-08 308856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll [2008-11-11 62728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 198136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08 110652]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar2.dll [2007-07-13 2554944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
AcroIEToolbarHelper Class - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 147456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-09-21 737776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\BAE\BAE.dll [2006-12-08 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA}]
C:\Program Files\PicLensIE\cooliris.dll [2008-11-21 3725272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar2.dll [2007-07-13 2554944]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 147456]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2007-05-30 808472]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2008-11-11 206088]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-13 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe [2006-08-14 462336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-09-08 122940]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
C:\Program Files\Dell\Media Experience\DMXLauncher.exe [2005-10-05 94208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-24 29744]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Vijay.SVC-DC\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe [2006-07-21 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2006-07-06 151552]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe [2006-07-21 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
c:\progra~1\common~1\instal~1\update~1\isuspm.exe [2004-07-27 221184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-07-27 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe [2006-07-21 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2007-04-27 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
C:\WINDOWS\stsystra.exe [2006-07-24 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-07-13 68856]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-05-08 185896]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2007-10-09 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [2007-07-16 4670704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
C:\PROGRA~1\Adobe\ACROBA~2.0\Distillr\acrotray.exe [2003-10-23 217194]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2005-09-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AntiVirService"=2
"AntiVirScheduler"=2

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-07-21 147456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2008-11-11 218376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5dsxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7apxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati5dsxx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati7apxx.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe"="C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\English\setup.exe:*:Enabled:Kaspersky Anti-Virus 2009 Setup"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\cygwin\usr\X11R6\bin\XWin.exe"="C:\cygwin\usr\X11R6\bin\XWin.exe:*:Enabled:XWin"
"C:\Program Files\SSH Communications Security\SSH Secure Shell\SshClient.exe"="C:\Program Files\SSH Communications Security\SSH Secure Shell\SshClient.exe:*:Enabled:Secure Shell Client"
"C:\cygwin\bin\xterm.exe"="C:\cygwin\bin\xterm.exe:*:Enabled:xterm"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

======List of files/folders created in the last 1 months======

2009-01-26 09:20:04 ----D---- C:\rsit
2009-01-23 09:55:13 ----SHD---- C:\RECYCLER
2009-01-23 09:38:32 ----D---- C:\WINDOWS\temp
2009-01-23 09:38:30 ----A---- C:\ComboFix.txt
2009-01-23 09:30:24 ----D---- C:\ComboFix
2009-01-22 16:07:31 ----A---- C:\Boot.bak
2009-01-22 16:07:19 ----RASHD---- C:\cmdcons
2009-01-22 16:06:27 ----A---- C:\WINDOWS\zip.exe
2009-01-22 16:06:27 ----A---- C:\WINDOWS\VFIND.exe
2009-01-22 16:06:27 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-22 16:06:27 ----A---- C:\WINDOWS\SWSC.exe
2009-01-22 16:06:27 ----A---- C:\WINDOWS\SWREG.exe
2009-01-22 16:06:27 ----A---- C:\WINDOWS\sed.exe
2009-01-22 16:06:27 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-22 16:06:27 ----A---- C:\WINDOWS\grep.exe
2009-01-22 16:06:27 ----A---- C:\WINDOWS\fdsv.exe
2009-01-22 16:06:10 ----D---- C:\WINDOWS\ERDNT
2009-01-22 16:06:10 ----D---- C:\Qoobox
2009-01-22 15:36:16 ----D---- C:\Program Files\Trend Micro
2009-01-22 11:09:54 ----D---- C:\Program Files\Kaspersky Lab
2009-01-22 11:09:54 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-01-22 10:48:28 ----D---- C:\Program Files\CCleaner
2009-01-22 10:35:45 ----D---- C:\Program Files\AVG
2009-01-22 10:13:54 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-01-22 10:09:57 ----D---- C:\Documents and Settings\All Users\Application Data\Avg8
2009-01-22 10:07:54 ----A---- C:\avenger.txt
2009-01-21 17:43:41 ----D---- C:\Documents and Settings\All Users\Application Data\Sunbelt
2009-01-21 13:43:54 ----A---- C:\WINDOWS\system32\OLD1E.tmp
2009-01-21 13:36:57 ----D---- C:\Documents and Settings\All Users\Application Data\Dell
2009-01-21 13:30:12 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-01-21 13:06:18 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-01-21 13:06:18 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-21 11:02:37 ----A---- C:\WINDOWS\system32\OLD16.tmp
2009-01-21 09:34:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-21 09:34:53 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-21 08:31:43 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-01-20 16:32:13 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-01-20 16:32:02 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-01-20 16:31:45 ----A---- C:\WINDOWS\system32\MRT.INI
2009-01-01 13:26:15 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-01-01 13:26:04 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-01-01 13:25:53 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-01-01 13:25:42 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-01-01 13:25:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-01-01 13:25:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-01-01 13:25:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-01-01 13:24:55 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-01-01 13:24:44 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-01-01 13:24:34 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-01-01 13:24:23 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-01-01 13:24:11 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-01-01 13:24:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-01-01 13:23:50 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-01-01 13:23:39 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2009-01-01 13:23:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-01-01 13:23:16 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-01-01 13:23:05 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-01-01 13:22:53 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-01-01 13:22:42 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-01-01 13:18:19 ----D---- C:\WINDOWS\system32\scripting
2009-01-01 13:18:19 ----D---- C:\WINDOWS\l2schemas
2009-01-01 13:18:18 ----D---- C:\WINDOWS\system32\en
2009-01-01 13:18:18 ----D---- C:\WINDOWS\system32\bits
2009-01-01 13:15:50 ----D---- C:\WINDOWS\ServicePackFiles
2009-01-01 13:14:28 ----D---- C:\WINDOWS\network diagnostic
2009-01-01 13:11:06 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$

======List of files/folders modified in the last 1 months======

2009-01-26 09:20:07 ----D---- C:\WINDOWS\Prefetch
2009-01-26 08:35:26 ----D---- C:\WINDOWS
2009-01-26 05:23:39 ----D---- C:\WINDOWS\security
2009-01-24 03:05:53 ----D---- C:\WINDOWS\system32
2009-01-24 03:05:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-24 03:02:21 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-24 03:00:34 ----HD---- C:\WINDOWS\inf
2009-01-23 16:25:58 ----D---- C:\Documents and Settings\Vijay.SVC-DC\Application Data\AdobeUM
2009-01-23 09:54:49 ----D---- C:\Research
2009-01-23 09:36:03 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-23 09:34:48 ----A---- C:\WINDOWS\system.ini
2009-01-23 09:32:48 ----D---- C:\WINDOWS\system32\drivers
2009-01-23 09:32:47 ----D---- C:\WINDOWS\AppPatch
2009-01-23 09:32:47 ----D---- C:\Program Files\Common Files
2009-01-23 09:30:31 ----SHD---- C:\System Volume Information
2009-01-23 09:30:31 ----D---- C:\WINDOWS\system32\Restore
2009-01-23 08:56:29 ----RASH---- C:\boot.ini
2009-01-23 08:56:29 ----A---- C:\WINDOWS\win.ini
2009-01-22 17:02:15 ----D---- C:\Program Files\Mozilla Firefox
2009-01-22 16:16:20 ----D---- C:\WINDOWS\system32\config
2009-01-22 16:14:15 ----RD---- C:\Program Files
2009-01-22 14:09:52 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-01-22 14:09:47 ----A---- C:\WINDOWS\system32\svchost.exe
2009-01-22 11:10:44 ----SHD---- C:\WINDOWS\Installer
2009-01-22 11:07:24 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-01-22 11:02:32 ----SD---- C:\WINDOWS\Tasks
2009-01-22 10:49:06 ----D---- C:\WINDOWS\Debug
2009-01-22 10:49:05 ----D---- C:\WINDOWS\Minidump
2009-01-22 10:35:44 ----D---- C:\WINDOWS\WinSxS
2009-01-22 10:26:59 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-01-22 08:42:59 ----SHD---- C:\WINDOWS\CSC
2009-01-21 16:08:32 ----D---- C:\WINDOWS\system32\DLA
2009-01-21 09:09:11 ----D---- C:\Documents and Settings
2009-01-21 08:31:16 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-01-20 16:32:12 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-13 08:19:11 ----D---- C:\WINDOWS\Help
2009-01-09 17:35:28 ----A---- C:\WINDOWS\system32\MRT.exe
2009-01-07 10:54:29 ----A---- C:\WINDOWS\matlab.ini
2009-01-06 16:46:04 ----D---- C:\Tmp
2009-01-04 17:13:25 ----SD---- C:\Documents and Settings\Vijay.SVC-DC\Application Data\Microsoft
2009-01-01 15:48:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-01 15:46:39 ----D---- C:\WINDOWS\system32\Setup
2009-01-01 15:46:39 ----D---- C:\Program Files\Messenger
2009-01-01 15:46:38 ----RSD---- C:\WINDOWS\Fonts
2009-01-01 15:46:38 ----D---- C:\WINDOWS\system32\wbem
2009-01-01 13:18:32 ----D---- C:\WINDOWS\system32\inetsrv
2009-01-01 13:18:32 ----D---- C:\WINDOWS\ime
2009-01-01 13:18:20 ----D---- C:\WINDOWS\system32\usmt
2009-01-01 13:18:20 ----D---- C:\WINDOWS\system32\en-US
2009-01-01 13:18:18 ----D---- C:\WINDOWS\PeerNet
2009-01-01 13:18:18 ----D---- C:\Program Files\Movie Maker
2009-01-01 13:15:41 ----D---- C:\WINDOWS\system32\npp
2009-01-01 13:15:41 ----D---- C:\WINDOWS\mui
2009-01-01 13:15:39 ----D---- C:\WINDOWS\msagent
2009-01-01 13:15:38 ----D---- C:\WINDOWS\srchasst
2009-01-01 13:15:37 ----D---- C:\Program Files\NetMeeting
2009-01-01 13:15:36 ----D---- C:\WINDOWS\system32\Com
2009-01-01 13:15:35 ----D---- C:\Program Files\Windows NT
2009-01-01 13:15:35 ----D---- C:\Program Files\Windows Media Player
2009-01-01 13:15:34 ----D---- C:\Program Files\Outlook Express
2009-01-01 13:15:33 ----D---- C:\Program Files\Common Files\System
2009-01-01 13:15:25 ----D---- C:\WINDOWS\system32\oobe
2009-01-01 13:15:24 ----D---- C:\WINDOWS\system
2009-01-01 13:13:20 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-01-01 13:11:04 ----D---- C:\WINDOWS\ehome
2008-12-30 14:21:48 ----SD---- C:\WINDOWS\Downloaded Program Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2005-08-25 5628]
R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2005-08-25 22684]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2009-01-22 227344]
R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2005-09-08 25628]
R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2005-09-08 86524]
R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2005-09-08 6364]
R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2005-09-08 87036]
R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2005-09-08 94332]
R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2005-08-12 40544]
R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2006-07-19 230400]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2006-07-21 1095968]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-07-24 1156648]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 e6001fb4;e6001fb4; C:\WINDOWS\System32\drivers\e6001fb4.sys []
S1 etheqied;etheqied; C:\WINDOWS\system32\drivers\etheqied.sys []
S1 ethvgifh;ethvgifh; C:\WINDOWS\system32\drivers\ethvgifh.sys []
S2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS []
S2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 DSproct;DSproct; \??\C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys []
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvw32.sys []
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 atapi;Standard IDE/ESDI Hard Disk Controller; C:\WINDOWS\system32\DRIVERS\atapi.sys [2008-04-13 96512]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVP;Kaspersky Anti-Virus; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe [2008-11-11 206088]
R2 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2006-07-06 90112]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-24 29744]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-07-13 138168]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2009-01-22 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------




*****************************Kaspersky log**************************************

Full Scan: completed 1/26/2009 1:23:21 PM (events: 422, objects: 786362, time: 01:56:14)
1/26/2009 11:27:07 AM Task started
1/26/2009 11:28:48 AM Detected: http://www.viruslist.com/en/advisories/23483 c:\program files\adobe\acrobat 6.0\acrobat\acrobat.exe
1/26/2009 11:28:57 AM Detected: http://www.viruslist.com/en/advisories/31371 c:\program files\winamp\winamp.exe
1/26/2009 11:29:46 AM Detected: http://www.viruslist.com/en/advisories/26625 c:\program files\subversion\bin\svn.exe
1/26/2009 12:08:53 PM Detected: http://www.viruslist.com/en/advisories/28083 c:\i386\Flash9d.ocx
1/26/2009 12:09:22 PM Detected: http://www.viruslist.com/en/advisories/31010 c:\i386\java.exe
1/26/2009 12:10:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\i386\QuickTime.qts
1/26/2009 12:12:48 PM Detected: http://www.viruslist.com/en/advisories/23483 c:\program files\adobe\acrobat 6.0\acrobat\acrobat.exe
1/26/2009 12:14:03 PM Detected: http://www.viruslist.com/en/advisories/30832 c:\program files\adobe\Acrobat 7.0\Reader\AcroRd32.dll
1/26/2009 12:17:51 PM Detected: http://www.viruslist.com/en/advisories/20845 c:\program files\Dell\Media Experience\InterActual\bin\pcfpatch
1/26/2009 12:18:27 PM Detected: http://www.viruslist.com/en/advisories/20845 c:\program files\InterActual\InterActual Player\bin\IAMime.dll
1/26/2009 12:18:28 PM Detected: http://www.viruslist.com/en/advisories/20845 c:\program files\InterActual\InterActual Player\bin\pcfpatch
1/26/2009 12:18:32 PM Detected: http://www.viruslist.com/en/advisories/26619 c:\program files\IrfanView\i_view32.exe
1/26/2009 12:18:33 PM Detected: http://www.viruslist.com/en/advisories/31010 c:\program files\Java\jre1.5.0_06\bin\java.exe
1/26/2009 12:18:33 PM Detected: http://www.viruslist.com/en/advisories/31010 c:\program files\Java\jre1.5.0_06\bin\javaws.exe
1/26/2009 12:18:45 PM Detected: http://www.viruslist.com/en/advisories/31010 c:\program files\Java\jre1.6.0_02\bin\java.exe
1/26/2009 12:21:32 PM Detected: http://www.viruslist.com/en/advisories/31010 c:\program files\MATLAB\R2007a\sys\java\jre\win32\jre1.5.0_07\bin\java.exe
1/26/2009 12:21:32 PM Detected: http://www.viruslist.com/en/advisories/31010 c:\program files\MATLAB\R2007a\sys\java\jre\win32\jre1.5.0_07\bin\javaws.exe
1/26/2009 12:39:42 PM Detected: http://www.viruslist.com/en/advisories/28083 c:\program files\Mozilla Firefox\plugins\NPSWF32.dll
1/26/2009 12:39:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\PictureViewer.qtr
1/26/2009 12:39:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\da.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\de.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\en.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\es.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\fi.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\fr.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\it.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\ja.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\ko.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\nb.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\nl.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:54 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\sv.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:54 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\zh_CN.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:54 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PictureViewer.Resources\zh_TW.lproj\PictureViewerLocalized.qtr
1/26/2009 12:39:55 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\PanelHelperBase.qtr
1/26/2009 12:39:55 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\da.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:55 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\de.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:55 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\en.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:55 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\es.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:55 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\fi.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:56 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\fr.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:56 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\it.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:56 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ko.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:56 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ja.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:56 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\nb.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:56 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\nl.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:56 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\sv.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:57 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\zh_CN.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:57 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PanelHelperBase.Resources\zh_TW.lproj\PanelHelperBaseLocalized.qtr
1/26/2009 12:39:57 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\PropPanelHelpers.qtr
1/26/2009 12:39:57 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\da.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:57 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\de.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:57 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\en.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:58 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\es.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:58 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\fi.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:58 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\fr.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:58 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\it.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:58 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ja.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:58 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ko.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:58 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\nb.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:59 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\nl.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:59 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\sv.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:59 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\zh_CN.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:39:59 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\zh_TW.lproj\PropPanelHelpersLocalized.qtr
1/26/2009 12:40:01 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\CoreVideo.qtr
1/26/2009 12:40:01 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\da.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:01 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\en.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:01 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\de.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:01 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\es.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:01 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\fi.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:01 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\fr.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:02 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\it.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:02 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\ja.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:02 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\ko.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:02 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\nb.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:02 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\nl.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:02 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\sv.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:02 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\zh_CN.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:02 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\CoreVideo.Resources\zh_TW.lproj\CoreVideoLocalized.qtr
1/26/2009 12:40:03 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\QuickTime.qtr
1/26/2009 12:40:03 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\da.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:03 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\de.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:03 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:03 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\fi.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:03 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\es.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:04 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\fr.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:04 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\it.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:04 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\ja.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:04 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\ko.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:04 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\nb.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:05 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\nl.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:05 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\sv.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:05 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\zh_CN.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:05 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime.Resources\zh_TW.lproj\QuickTimeLocalized.qtr
1/26/2009 12:40:05 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\QuickTime3GPP.qtr
1/26/2009 12:40:05 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\da.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:05 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\de.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:06 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\en.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:06 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\es.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:06 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\fi.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:06 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\fr.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:06 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\it.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:06 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\ja.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:07 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\ko.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:07 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\nb.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:07 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\nl.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:07 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\sv.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:07 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\zh_CN.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:07 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPP.Resources\zh_TW.lproj\QuickTime3GPPLocalized.qtr
1/26/2009 12:40:08 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\QuickTime3GPPAuthoring.qtr
1/26/2009 12:40:08 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\da.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:08 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\de.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:08 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\en.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:08 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\es.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:08 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\fi.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:08 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\fr.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:09 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\it.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:09 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ja.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:09 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ko.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:09 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\nb.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:09 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\nl.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:09 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\sv.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:09 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\zh_CN.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:09 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\zh_TW.lproj\QuickTime3GPPAuthoringLocalized.qtr
1/26/2009 12:40:10 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\QuickTimeAudioSupport.qtr
1/26/2009 12:40:10 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\da.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:10 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\de.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:10 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:10 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\es.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:10 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\fi.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:11 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\fr.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:11 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\it.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:11 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\ja.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:11 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\ko.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:11 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\nb.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:11 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\nl.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:12 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\sv.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:12 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:12 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAudioSupport.Resources\zh_TW.lproj\QuickTimeAudioSupportLocalized.qtr
1/26/2009 12:40:12 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\QuickTimeAuthoring.qtr
1/26/2009 12:40:12 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\da.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:13 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\de.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:13 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\en.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:13 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\es.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:13 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\fi.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:13 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\fr.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:13 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\it.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:14 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\ja.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:14 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\ko.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:14 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\nb.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:14 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\nl.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:14 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\sv.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:14 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\zh_CN.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:14 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeAuthoring.Resources\zh_TW.lproj\QuickTimeAuthoringLocalized.qtr
1/26/2009 12:40:15 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\QuickTimeCapture.qtr
1/26/2009 12:40:15 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\da.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:15 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\de.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:15 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\en.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:15 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\es.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:15 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\fi.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:15 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\fr.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:15 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\it.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:16 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\ja.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:16 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\ko.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:16 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\nb.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:16 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\nl.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:16 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\sv.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:16 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\zh_CN.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:16 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeCapture.Resources\zh_TW.lproj\QuickTimeCaptureLocalized.qtr
1/26/2009 12:40:17 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\QuickTimeEffects.qtr
1/26/2009 12:40:17 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\da.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:17 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\de.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:17 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\en.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:17 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\es.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:17 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\fi.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:18 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\fr.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:18 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\it.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:18 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\ja.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:18 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\ko.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:18 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\nb.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:18 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\nl.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:18 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\sv.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:19 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\zh_CN.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:19 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEffects.Resources\zh_TW.lproj\QuickTimeEffectsLocalized.qtr
1/26/2009 12:40:19 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\QuickTimeEssentials.qtr
1/26/2009 12:40:19 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\da.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:19 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\de.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:19 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\en.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:19 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\es.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:20 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\fi.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:20 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\fr.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:20 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\it.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:20 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\ja.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:20 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\ko.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:20 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\nb.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:20 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\nl.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:21 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\sv.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:21 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\zh_CN.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:21 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeEssentials.Resources\zh_TW.lproj\QuickTimeEssentialsLocalized.qtr
1/26/2009 12:40:21 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\QuickTimeH264.qtr
1/26/2009 12:40:21 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\da.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:21 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\en.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:22 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\de.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:22 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\es.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:22 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\fi.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:22 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\fr.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:22 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\it.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:22 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\ja.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:22 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\ko.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:23 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\nb.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:23 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\nl.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:23 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\sv.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:23 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\zh_CN.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:23 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeH264.Resources\zh_TW.lproj\QuickTimeH264Localized.qtr
1/26/2009 12:40:23 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\QuickTimeImage.qtr
1/26/2009 12:40:23 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\da.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:24 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\de.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:24 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\en.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:24 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\es.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:24 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\fi.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:24 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\fr.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:24 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\it.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:24 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\ja.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:25 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\ko.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:25 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\nb.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:25 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\nl.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:25 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\sv.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:25 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\zh_CN.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:25 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeImage.Resources\zh_TW.lproj\QuickTimeImageLocalized.qtr
1/26/2009 12:40:25 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\QuickTimeInternetExtras.qtr
1/26/2009 12:40:26 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\da.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:26 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\de.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:26 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\en.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:26 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\es.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:26 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\fi.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:26 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\fr.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:26 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\it.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:27 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\ja.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:27 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\ko.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:27 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\nb.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:27 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\nl.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:27 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\sv.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:27 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\zh_CN.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:28 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeInternetExtras.Resources\zh_TW.lproj\QuickTimeInternetExtrasLocalized.qtr
1/26/2009 12:40:28 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\QuickTimeMPEG.qtr
1/26/2009 12:40:28 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\da.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:28 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\de.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:28 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\en.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:28 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\es.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:29 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\fi.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:29 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\fr.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:29 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\it.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:29 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\ja.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:29 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\ko.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:29 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\nb.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:29 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\nl.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:30 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\sv.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:30 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\zh_CN.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:30 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG.Resources\zh_TW.lproj\QuickTimeMPEGLocalized.qtr
1/26/2009 12:40:30 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\QuickTimeMPEG4.qtr
1/26/2009 12:40:30 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\da.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:30 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\de.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:30 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\en.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:31 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\es.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:31 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\fi.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:31 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\fr.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:31 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\ja.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:31 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\it.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:31 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\ko.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:31 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\nb.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:32 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\nl.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:32 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\sv.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:32 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\zh_CN.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:32 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4.Resources\zh_TW.lproj\QuickTimeMPEG4Localized.qtr
1/26/2009 12:40:32 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\QuickTimeMPEG4Authoring.qtr
1/26/2009 12:40:32 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\da.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:33 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\de.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:33 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\en.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:33 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\es.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:33 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\fi.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:33 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\fr.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:33 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\it.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:33 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\ja.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:33 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\ko.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:34 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\nb.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:34 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\nl.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:34 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\sv.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:34 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\zh_CN.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:34 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMPEG4Authoring.Resources\zh_TW.lproj\QuickTimeMPEG4AuthoringLocalized.qtr
1/26/2009 12:40:34 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\QuickTimeMusic.qtr
1/26/2009 12:40:34 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\da.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:35 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\de.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:35 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\en.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:35 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\es.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:35 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\fi.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:35 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\fr.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:35 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\it.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:35 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\ja.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:35 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\ko.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:36 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\nb.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:36 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\nl.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:36 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\sv.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:36 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\zh_CN.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:36 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeMusic.Resources\zh_TW.lproj\QuickTimeMusicLocalized.qtr
1/26/2009 12:40:36 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\QuickTimeQD3D.qtr
1/26/2009 12:40:37 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\da.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:37 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\de.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:37 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\en.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:37 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\fi.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:37 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\es.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:37 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\fr.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:37 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\it.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:38 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\ja.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:38 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\ko.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:38 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\nb.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:38 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\nl.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:38 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\sv.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:38 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\zh_CN.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:39 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeQD3D.Resources\zh_TW.lproj\QuickTimeQD3DLocalized.qtr
1/26/2009 12:40:39 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\QuickTimeStreaming.qtr
1/26/2009 12:40:39 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\da.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:39 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\de.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:39 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\en.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:39 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\es.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:40 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\fi.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:40 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\fr.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:40 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\it.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:40 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\ja.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:40 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\ko.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:41 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\nb.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:41 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\nl.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:41 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\sv.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:41 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\zh_CN.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:41 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreaming.Resources\zh_TW.lproj\QuickTimeStreamingLocalized.qtr
1/26/2009 12:40:41 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\QuickTimeStreamingAuthoring.qtr
1/26/2009 12:40:42 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\da.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:42 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\de.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:42 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\en.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:42 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\es.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:42 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\fi.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:42 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\fr.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:42 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\it.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:43 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\ja.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:43 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\ko.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:43 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\nb.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:43 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\nl.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:43 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\sv.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:43 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\zh_CN.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:44 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingAuthoring.Resources\zh_TW.lproj\QuickTimeStreamingAuthoringLocalized.qtr
1/26/2009 12:40:44 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\QuickTimeStreamingExtras.qtr
1/26/2009 12:40:44 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\da.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:44 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\de.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:44 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\en.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:44 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\es.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:45 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\fi.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:45 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\fr.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:45 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\it.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:45 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\ja.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:45 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\ko.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:45 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\nb.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:46 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\nl.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:46 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\sv.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:46 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\zh_CN.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:46 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeStreamingExtras.Resources\zh_TW.lproj\QuickTimeStreamingExtrasLocalized.qtr
1/26/2009 12:40:46 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\QuickTimeVR.qtr
1/26/2009 12:40:46 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\da.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:46 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\de.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:47 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\en.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:47 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\es.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:47 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\fi.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:47 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\fr.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:47 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\it.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:47 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\ja.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:47 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\ko.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:48 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\nb.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:48 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\nl.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:48 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\sv.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:48 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\zh_CN.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:48 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVR.Resources\zh_TW.lproj\QuickTimeVRLocalized.qtr
1/26/2009 12:40:48 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\QuickTimeVRAuthoring.qtr
1/26/2009 12:40:49 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\da.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:49 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\de.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:49 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\en.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:49 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\es.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:49 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\fi.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:49 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\fr.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:49 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\it.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:50 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\ja.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:50 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\ko.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:50 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\nb.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:50 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\nl.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:50 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\sv.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:50 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\zh_CN.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:50 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeVRAuthoring.Resources\zh_TW.lproj\QuickTimeVRAuthoringLocalized.qtr
1/26/2009 12:40:51 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\QuickTimeWebHelper.qtr
1/26/2009 12:40:51 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\da.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:51 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\de.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:51 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\en.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\es.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\fi.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\fr.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\it.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\ja.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\ko.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:52 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\nb.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\nl.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\sv.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QuickTimePlayer.Resources\QuickTimePlayer.qtr
1/26/2009 12:40:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:40:53 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\program files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\zh_TW.lproj\QuickTimeWebHelperLocalized.qtr
1/26/2009 12:41:48 PM Detected: http://www.viruslist.com/en/advisories/26625 c:\program files\subversion\bin\svn.exe
1/26/2009 12:42:31 PM Detected: http://www.viruslist.com/en/advisories/31371 c:\program files\winamp\winamp.exe
1/26/2009 12:45:02 PM Detected: Worm.Win32.AutoRun.ypp c:\Qoobox\Quarantine\C\Program Files\Microsoft Common\svchost.exe.vir
1/26/2009 12:45:02 PM Untreated: Worm.Win32.AutoRun.ypp c:\Qoobox\Quarantine\C\Program Files\Microsoft Common\svchost.exe.vir Postponed
1/26/2009 1:21:30 PM Detected: HEUR:Trojan.Win32.Generic c:\WINDOWS\system32\OLD1E.tmp:ext.exe
1/26/2009 1:21:30 PM Untreated: HEUR:Trojan.Win32.Generic c:\WINDOWS\system32\OLD1E.tmp:ext.exe Postponed
1/26/2009 1:21:47 PM Detected: http://www.viruslist.com/en/advisories/29293 c:\WINDOWS\system32\QuickTime.qts
1/26/2009 1:22:32 PM Detected: http://www.viruslist.com/en/advisories/28083 c:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
1/26/2009 1:23:10 PM Detected: Worm.Win32.AutoRun.ypp c:\Qoobox\Quarantine\C\Program Files\Microsoft Common\svchost.exe.vir
1/26/2009 1:23:21 PM Deleted: Worm.Win32.AutoRun.ypp c:\Qoobox\Quarantine\C\Program Files\Microsoft Common\svchost.exe.vir
1/26/2009 1:23:21 PM Detected: HEUR:Trojan.Win32.Generic c:\WINDOWS\system32\OLD1E.tmp:ext.exe
1/26/2009 1:23:21 PM Task completed

#5 aommaster

aommaster

    I !<3 malware


  • Malware Response Team
  • 5,289 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dubai
  • Local time:07:39 AM

Posted 27 January 2009 - 05:21 PM

Thanks for posting your log.

Logs take a while to process due to intensive research that must be done. Please give me some time to look over your logs and I will post back soon :thumbup2:

My website: http://aommaster.com
unite_blue.png
Please do not send me PM's requesting for help. The forums are there for a reason : )
If I am helping you and do not respond to your thread for 48 hours, please send me a PM


#6 mahadv

mahadv
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:39 PM

Posted 27 January 2009 - 06:43 PM

no problemo! thanks for poring over such lengthy logs!

#7 aommaster

aommaster

    I !<3 malware


  • Malware Response Team
  • 5,289 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dubai
  • Local time:07:39 AM

Posted 29 January 2009 - 07:08 AM

Hello, mahadv.
Your log doesn't seem to show any signs of infection. However, this does not mean that you are clean. First, please answer the following questions:
1.Do you recognise this domain?
svc-dc.svcl.ucsd.edu
2.It looks like you have run Combofix on your computer before posting here. Do you happen to have a log from it? The log should be under C:\ComboFix.txt
3.What are problems on your computer that seem to imply that you have a virus infection? This can be anything from adware/spyware, so just go wild :thumbup2:

If you don't have HijackThis installed on your computer, or you haven't updated it, please do so:
Click here to download HijackThis.
Save HJTInstall.exe to your Desktop.
Double click on the HJTInstall.exe icon to start the program.
By default it will install to C:\Program Files\Trend Micro\HijackThis

Go to Start > My Computer
Go to Tools > Folder Options
Click on the View tab
Untick the following:
  • Hide extensions for known file types
  • Hide protected operating system files (Recommended)
You will get a message warning you about showing protected operating system files, click Yes
Make sure this option is selected:
  • Show hidden files and folders
Click Apply and then click OK


Run HijackThis.
Click on Do a system scan only.
Place a checkmark next to these lines (if still present).


O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll


Then close all windows except HijackThis and click Fix Checked.

Restart

Delete these files:
c:\WINDOWS\system32\OLD1E.tmp

Delete these folders:
C:\Program Files\BAE

As an example:
To delete C:\WINDOWS\badfile.dll
Double click the My Computer icon on your Desktop. Or click on the Windows KEY + E.
Double click on Local Disc (C:\)
Double click on the Windows folder,
Right click on badfile.dll and then from the menu that appears, click on Delete


In your next reply, please include the following:
  • RSIT Log
  • Description of any remaining problems
  • Answers to my questions at the start of my post

My website: http://aommaster.com
unite_blue.png
Please do not send me PM's requesting for help. The forums are there for a reason : )
If I am helping you and do not respond to your thread for 48 hours, please send me a PM


#8 aommaster

aommaster

    I !<3 malware


  • Malware Response Team
  • 5,289 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dubai
  • Local time:07:39 AM

Posted 31 January 2009 - 01:41 PM

Hello mahadv
Are you still with us?

My website: http://aommaster.com
unite_blue.png
Please do not send me PM's requesting for help. The forums are there for a reason : )
If I am helping you and do not respond to your thread for 48 hours, please send me a PM


#9 harrythook

harrythook


  • Security Colleague
  • 4,152 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Philadelphia
  • Local time:10:39 PM

Posted 01 February 2009 - 10:21 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.
All others please read The Preparation Guide before starting your topic.

Veni Vidi Vici
THE FIGHT AGAINST MALWARE

Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users