Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

System Infected with Vundo!grb


  • This topic is locked This topic is locked
16 replies to this topic

#1 Dooderty

Dooderty

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 13 April 2009 - 09:26 PM

:thumbup2: Hi, I am infected and now while browsing the internet I keep getting hijacked, Now every time I start up my computer McAfee virus software pops up saying it has blocked the Vundo!grb virus at:

C:\WINDOWS\system32\alesayov.tmp

Basically whenever i search for something on Google or go to new website a pop-up is coming up. I've also noticed that now my automatic windows updates are disabled when I boot up, I am able to turn them back on. I have only disabled a few item during startup to this point.
Hopefully you guys can help and I thank you for your time.

Here's the DDS file:


DDS (Ver_09-03-16.01) - NTFSx86
Run by owner at 21:11:50.60 on Mon 04/13/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2313 [GMT -5:00]

AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\CSHelper.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\My Installed Software\MCEBuddy\MCEBuddySvc.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\My Installed Software\Nitro PDF\NitroPDFPrinterMonitor.exe
C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\owner.LONEWOLF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\My Installed Software\Advanced SystemCare 3\AWC.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\My Installed Software\MCEBuddy\MCEBuddyConfig.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\My Installed Software\Maxthon\Maxthon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\system32\rundll32.exe
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\owner.LONEWOLF\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://my.myway.com/index.jsp?speedbarconfigchanged
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\my installed software\snagit 7\SnagItBHO.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {6b80dd5a-251f-4cae-8cc9-0a37253c85e6} - c:\windows\system32\rizadewe.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\Scriptcl.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\my installed software\snagit 7\SnagItIEAddin.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\owner.lonewolf\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Advanced SystemCare 3] "c:\my installed software\advanced systemcare 3\AWC.exe" /startup
uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime
mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Verizon_McciTrayApp] c:\program files\verizon\McciTrayApp.exe
mRun: [Nitro PDF Printer Monitor] "c:\my installed software\nitro pdf\NitroPDFPrinterMonitor.exe"
mRun: [CTCheck] c:\my installed software\creative\creative zen\zen media explorer\CTCheck.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [1902804f] rundll32.exe "c:\windows\system32\voyasela.dll",b
mRun: [CPM1a31b3d3] Rundll32.exe "c:\windows\system32\wujaluta.dll",a
mRun: [razikinoka] Rundll32.exe "c:\windows\system32\nakisidi.dll",s
StartupFolder: c:\docume~1\owner~1.lon\startm~1\programs\startup\mcebud~1.lnk - c:\docume~1\owner~1.lon\applic~1\microsoft\installer\{bafc1680-d56c-4079-98b7-b71b99f29647}\_7E43DD945644F5638C1291.exe
StartupFolder: c:\docume~1\owner~1.lon\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\aticat~1.lnk - c:\program files\ati technologies\ati.ace\CLI.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214682580140
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {97770E5B-2028-48AC-B4DA-1F991376D2B6} - hxxp://download.copysafe.net/plugins5/installers/Copysafe.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: c:\windows\system32\wujaluta.dll,c:\windows\system32\wulupopo.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\wujaluta.dll
STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\wujaluta.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Notification Packages = scecli c:\windows\system32\wulupopo.dll

================= FIREFOX ===================

FF - ProfilePath -

============= SERVICES / DRIVERS ===============

R0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys --> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]
R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2006-11-30 31944]
R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2008-9-20 192512]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2007-9-23 104000]
R2 MCE Buddy;MCE Buddy Service;c:\my installed software\mcebuddy\MCEBuddySvc.exe [2007-12-16 20480]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2007-2-22 144960]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2007-2-22 54872]
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2008-8-27 72264]
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2008-8-27 34152]
R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2008-8-27 170408]
S3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [2008-7-7 152576]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-11-16 550272]

=============== Created Last 30 ================

2009-03-23 11:08 2,145,280 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-23 11:08 2,189,184 -------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-23 11:08 2,023,936 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-23 11:08 2,066,048 -------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-23 11:08 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-23 11:08 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-03-23 11:08 331,776 -------- c:\windows\system32\dllcache\msadce.dll
2009-03-23 11:07 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-03-23 11:07 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-03-23 11:07 1,106,944 -------- c:\windows\system32\dllcache\msxml3.dll
2009-03-21 07:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-21 07:31 <DIR> --d----- c:\docume~1\owner~1.lon\applic~1\AVSMedia
2009-03-21 07:27 <DIR> --d----- c:\docume~1\owner~1.lon\applic~1\AVS4YOU
2009-03-21 07:27 <DIR> --d----- c:\program files\AVS4YOU
2009-03-19 10:19 <DIR> --d----- C:\tmpDownload
2009-03-17 21:31 <DIR> --d----- c:\program files\common files\Stardock
2009-03-17 21:31 163,712 a------- c:\windows\system32\drivers\vidstub.sys
2009-03-14 23:40 87,608 a------- c:\docume~1\owner~1.lon\applic~1\inst.exe
2009-03-14 23:40 47,360 a------- c:\windows\system32\drivers\pcouffin.sys
2009-03-14 23:40 47,360 a------- c:\docume~1\owner~1.lon\applic~1\pcouffin.sys
2009-03-14 23:40 217,127 a------- c:\windows\system32\drv43260.dll
2009-03-14 23:40 208,935 a------- c:\windows\system32\drv33260.dll
2009-03-14 23:40 102,439 a------- c:\windows\system32\sipr3260.dll
2009-03-14 23:40 1,184,984 a------- c:\windows\system32\wvc1dmod.dll
2009-03-14 23:40 626,688 a------- c:\windows\system32\vp7vfw.dll
2009-03-14 23:40 176,165 a------- c:\windows\system32\drv23260.dll
2009-03-14 23:40 65,602 a------- c:\windows\system32\cook3260.dll
2009-03-14 23:40 <DIR> --d----- c:\program files\VSO

==================== Find3M ====================

2009-04-13 17:06 49,152 a--sh--- c:\windows\system32\midajewi.dll
2009-04-13 17:06 87,552 a--sh--- c:\windows\system32\wujaluta.dll
2009-04-13 17:06 79,872 a--sh--- c:\windows\system32\voyasela.dll
2009-04-13 05:05 51,200 a--sh--- c:\windows\system32\rukifopi.exe
2009-04-13 05:05 87,552 a--sh--- c:\windows\system32\beyefazi.dll
2009-04-13 05:05 79,872 -------- c:\windows\system32\tegalizi.dll
2009-02-27 18:42 28,352 a------- c:\windows\system32\drivers\MxlW2k.sys
2009-02-09 06:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-09 06:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2009-01-16 21:35 3,594,752 -------- c:\windows\system32\dllcache\mshtml.dll
2008-12-15 11:42 61,224 a------- c:\documents and settings\owner.lonewolf\GoToAssistDownloadHelper.exe
2008-09-03 21:53 116 a------- c:\docume~1\owner~1.lon\applic~1\wklnhst.dat

============= FINISH: 21:13:21.46 ===============

Edited by Dooderty, 13 April 2009 - 10:29 PM.


BC AdBot (Login to Remove)

 


#2 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:08:31 AM

Posted 16 April 2009 - 01:16 AM

Please download Malwarebytes' Anti-Malware from HERE or HERE

Note: If you already have Malwarebytes' Anti-Malware, just run and update it.. Then do a "Perform Full Scan"

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.




NEXT


Please download RSIT by random/random and save it to your Desktop.
  • Double click on RSIT.exe to run RSIT
  • Before you click "Continue", make sure you change the List files/folders created or modified in the last 3 months
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt and info.txt in your next reply.



NEXT


Please download GMER and unzip it to your Desktop. <<mirror>>
  • Open the program and click on the Rootkit tab.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
  • Click on Scan.
  • When the scan has run click Copy and paste the results into a Notepad >> save it and attach in this thread.
IMPORTANT: Do NOT run any program while you are doing these scans as it may interfere with the output results



Post me these logs in your next reply.. Post each log in separate post..

1. Malwarebytes'
2. RSIT log.txt
3. RSIT info.txt
4. Attach GMER result..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#3 Dooderty

Dooderty
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 17 April 2009 - 10:55 AM

Interestingly enough I have already ran Malwarebytes before your reply and here is the log file from my first scan. Just to let you know after the first full scan and restart the system seemed to run clean and free of Vundo!grp, a while later I began to once again get Vundo detections from McAfee so I proceeded to run Malwarebyte a second time. I have been free of Vundo from then on but following through to make sure to clean up my system. I am also attaching the log from the second scan.


1st scan Malwarebytes log;

Malwarebytes' Anti-Malware 1.36
Database version: 1983
Windows 5.1.2600 Service Pack 3

4/15/2009 8:22:07 AM
mbam-log-2009-04-15 (08-21-53).txt

Scan type: Full Scan (C:\|D:\|N:\|O:\|)
Objects scanned: 589959
Time elapsed: 3 hour(s), 4 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 6
Registry Keys Infected: 7
Registry Values Infected: 5
Registry Data Items Infected: 5
Folders Infected: 23
Files Infected: 86

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\voyasela.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\wulupopo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\nakisidi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\rizadewe.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\wopowupa.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\zejohavu.dll (Trojan.Vundo) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6b80dd5a-251f-4cae-8cc9-0a37253c85e6} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6b80dd5a-251f-4cae-8cc9-0a37253c85e6} (Trojan.Vundo.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6b80dd5a-251f-4cae-8cc9-0a37253c85e6} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\1902804f (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\razikinoka (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm1a31b3d3 (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\wulupopo.dll -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\wulupopo.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\wopowupa.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\zejohavu.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
C:\Program Files\Starware337 (Adware.Starware) -> No action taken.
C:\Program Files\Starware337\icons (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337 (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\contexts (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337 (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\BrowserSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ErrorSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Games (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Manager (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Movies (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Recipes (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\RecipeSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Reference (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\RelatedSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ScreensaversMarketingSitePager (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\SearchAssistPlus (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\SearchMatch (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarLogo (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\TravelSearch (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Weather (Adware.Starware) -> No action taken.

Files Infected:
C:\WINDOWS\system32\voyasela.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\nakisidi.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\wopowupa.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\rizadewe.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\wulupopo.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\zejohavu.dll (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\owner.LONEWOLF\My Documents\Shedevil Files\My Shared Folder\How 2\How to Crack Windows XP & Office XP Service pack 1 - includes KeyGen\XPKey.exe (Trojan.Downloader) -> No action taken.
C:\My Installed Software\JetAudio\jetUpdate.exe (Rogue.MalwareSweeper) -> No action taken.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067326.dll (Trojan.Vundo.H) -> No action taken.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067327.dll (Trojan.Vundo.H) -> No action taken.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067328.dll (Trojan.Vundo.H) -> No action taken.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067330.dll (Trojan.Vundo.H) -> No action taken.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067331.dll (Trojan.Vundo.H) -> No action taken.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067357.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\beyefazi.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\midajewi.dll (Trojan.Vundo.H) -> No action taken.
C:\Program Files\Starware337\brand.bmp (Adware.Starware) -> No action taken.
C:\Program Files\Starware337\Starware337Config.xml (Adware.Starware) -> No action taken.
C:\Program Files\Starware337\Starware337Uninstall.exe (Adware.Starware) -> No action taken.
C:\Program Files\Starware337\Thumbs.db (Adware.Starware) -> No action taken.
C:\Program Files\Starware337\icons\star_16.ico (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiRSS.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiRSS.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiSearch.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiSearch.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindIt.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindItHot.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\findithotxp.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\finditxp.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Highlight.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\HighlightHot.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\highlighthotxp.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\highlightxp.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\logo.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\logoxp.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Reference.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\ReferenceHot.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencehotxp.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencexp.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Weather.bmp (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\weatherhotxp.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\weatherxp.png (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\error.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\related.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\travel.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\ProductMessagingConfig.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\ProductMessagingConfig.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\SimpleUpdateConfig.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\SimpleUpdateConfig.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\TimerManagerConfig.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\TimerManagerConfig.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\BrowserSearch\BrowserSearch.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\BrowserSearch\BrowserSearch.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Games\GamesOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Games\GamesOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Manager\ManagerOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Manager\ManagerOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Movies\MoviesOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Movies\MoviesOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Recipes\RecipesOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Recipes\RecipesOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Reference\ReferenceOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Reference\ReferenceOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml.backup (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Weather\WeatherOptions.xml (Adware.Starware) -> No action taken.
C:\Documents and Settings\owner\Application Data\Starware337\Weather\WeatherOptions.xml.backup (Adware.Starware) -> No action taken.
C:\WINDOWS\system32\wujaluta.dll (Trojan.Vundo) -> No action taken.



2nd Scan log file;

Malwarebytes' Anti-Malware 1.36
Database version: 1983
Windows 5.1.2600 Service Pack 3

4/15/2009 8:24:41 AM
mbam-log-2009-04-15 (08-24-41).txt

Scan type: Full Scan (C:\|D:\|N:\|O:\|)
Objects scanned: 589959
Time elapsed: 3 hour(s), 4 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 6
Registry Keys Infected: 7
Registry Values Infected: 5
Registry Data Items Infected: 5
Folders Infected: 23
Files Infected: 86

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\voyasela.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\wulupopo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\nakisidi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\rizadewe.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\wopowupa.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\zejohavu.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6b80dd5a-251f-4cae-8cc9-0a37253c85e6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6b80dd5a-251f-4cae-8cc9-0a37253c85e6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6b80dd5a-251f-4cae-8cc9-0a37253c85e6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\1902804f (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\razikinoka (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm1a31b3d3 (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo) -> Delete on reboot.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\wulupopo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\wulupopo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\wopowupa.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\zejohavu.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\icons (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\contexts (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\BrowserSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ErrorSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Games (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Manager (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Movies (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Recipes (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\RecipeSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Reference (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\RelatedSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ScreensaversMarketingSitePager (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\SearchAssistPlus (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\SearchMatch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarLogo (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\TravelSearch (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Weather (Adware.Starware) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\voyasela.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\nakisidi.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\wopowupa.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\rizadewe.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\wulupopo.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\zejohavu.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\owner.LONEWOLF\My Documents\Shedevil Files\My Shared Folder\How 2\How to Crack Windows XP & Office XP Service pack 1 - includes KeyGen\XPKey.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\My Installed Software\JetAudio\jetUpdate.exe (Rogue.MalwareSweeper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067326.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067327.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067328.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067330.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067331.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP309\A0067357.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\beyefazi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\midajewi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\brand.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\Starware337Config.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\Starware337Uninstall.exe (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\Thumbs.db (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware337\icons\star_16.ico (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiRSS.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiRSS.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiSearch.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiSearch.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Highlight.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\HighlightHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\highlighthotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\highlightxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Reference.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\ReferenceHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencehotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencexp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Weather.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\weatherhotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\weatherxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\ProductMessagingConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\ProductMessagingConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\SimpleUpdateConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\SimpleUpdateConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\TimerManagerConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\TimerManagerConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\BrowserSearch\BrowserSearch.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\BrowserSearch\BrowserSearch.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Games\GamesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Games\GamesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Manager\ManagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Manager\ManagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Movies\MoviesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Movies\MoviesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Recipes\RecipesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Recipes\RecipesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Reference\ReferenceOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Reference\ReferenceOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Weather\WeatherOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\owner\Application Data\Starware337\Weather\WeatherOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wujaluta.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

#4 Dooderty

Dooderty
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 17 April 2009 - 11:01 AM

RSIT log.txt

Logfile of random's system information tool 1.06 (written by random/random)
Run by owner at 2009-04-17 10:57:59
Microsoft Windows XP Professional Service Pack 3
System drive C: has 25 GB (11%) free of 230 GB
Total RAM: 3070 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:58:14 AM, on 4/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\CSHelper.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\My Installed Software\Nitro PDF\NitroPDFPrinterMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\owner.LONEWOLF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\My Installed Software\Advanced SystemCare 3\AWC.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\My Installed Software\Maxthon\Maxthon.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\owner.LONEWOLF\Desktop\RSIT.exe
C:\Program Files\trend micro\owner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.myway.com/index.jsp?speedbarconfigchanged
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...arm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 82.98.231.89 browser-security.microsoft.com
O1 - Hosts: 82.98.231.89 best-click-scanner.info
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\My Installed Software\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\My Installed Software\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [Nitro PDF Printer Monitor] "C:\My Installed Software\Nitro PDF\NitroPDFPrinterMonitor.exe"
O4 - HKLM\..\Run: [CTCheck] C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\owner.LONEWOLF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\My Installed Software\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - Startup: MCEBuddy Taskbar Monitor.lnk = ?
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1214682580140
O16 - DPF: {97770E5B-2028-48AC-B4DA-1F991376D2B6} - http://download.copysafe.net/plugins5/inst...rs/Copysafe.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs:
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: MCE Buddy Service (MCE Buddy) - Unknown owner - C:\My Installed Software\MCEBuddy\MCEBuddySvc.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 13974 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\AWC AutoSweep.job
C:\WINDOWS\tasks\AWC Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2372944-1335694676-2409864563-1009.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}]
HelperObject Class - C:\My Installed Software\SnagIt 7\SnagItBHO.dll [2005-10-14 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-10-09 308832]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll [2006-11-30 67136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2005-10-18 720896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2005-10-18 720896]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - C:\My Installed Software\SnagIt 7\SnagItIEAddin.dll [2005-10-14 131072]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"AlwaysReady Power Message APP"=C:\WINDOWS\ARPWRMSG.EXE [2005-08-03 77312]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-08-18 14820864]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-08-10 61440]
"HPHUPD08"=c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe [2005-06-02 49152]
"HPBootOp"=C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2005-02-26 245760]
"KBD"=C:\HP\KBD\KBD.EXE [2005-02-02 61440]
"ShStatEXE"=C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [2007-02-22 112216]
"McAfeeUpdaterUI"=C:\Program Files\McAfee\Common Framework\UdaterUI.exe [2006-12-19 136768]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-10-09 185872]
"Verizon_McciTrayApp"=C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
"Nitro PDF Printer Monitor"=C:\My Installed Software\Nitro PDF\NitroPDFPrinterMonitor.exe [2008-12-05 210240]
"CTCheck"=C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe [2007-11-06 397312]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-01-05 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-03-12 342312]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"Google Update"=C:\Documents and Settings\owner.LONEWOLF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-13 133104]
"Advanced SystemCare 3"=C:\My Installed Software\Advanced SystemCare 3\AWC.exe [2008-12-21 2250256]
"CTSyncU.exe"=C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe [2007-07-17 868352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1902804f]
C:\WINDOWS\system32\voyasela.dll,b []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM1a31b3d3]
c:\windows\system32\wujaluta.dll,a []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe [2005-05-12 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe [2004-01-26 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\razikinoka]
C:\WINDOWS\system32\nakisidi.dll,s []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ad-Aware 2007.lnk]
C:\MYINST~1\Lavasoft\AD-AWA~1\AD-AWA~1.EXE [2008-04-10 2711376]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\Documents and Settings\owner.LONEWOLF\Start Menu\Programs\Startup
MCEBuddy Taskbar Monitor.lnk - C:\Documents and Settings\owner.LONEWOLF\Application Data\Microsoft\Installer\{BAFC1680-D56C-4079-98B7-B71B99F29647}\_7E43DD945644F5638C1291.exe
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-08-10 46080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\My Installed Software\Shareaza\Shareaza\Shareaza.exe"="C:\My Installed Software\Shareaza\Shareaza\Shareaza.exe:*:Enabled:Shareaza"
"C:\My Installed Software\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\My Installed Software\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe"="C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Explorer"
"C:\WINDOWS\ehome\ehtray.exe"="C:\WINDOWS\ehome\ehtray.exe:*:Enabled:ehtray"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\iTunes\iTunes.exe"="%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

======List of files/folders created in the last 3 months======

2009-04-17 10:57:59 ----D---- C:\rsit
2009-04-17 10:57:59 ----D---- C:\Program Files\trend micro
2009-04-15 11:09:55 ----A---- C:\WINDOWS\system32\MRT.exe
2009-04-15 11:09:20 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-04-15 11:09:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-04-15 11:09:00 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-04-15 11:08:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-04-15 11:08:31 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-04-15 11:08:25 ----A---- C:\WINDOWS\imsins.BAK
2009-04-15 11:08:20 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-04-15 11:03:49 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-04-14 22:28:51 ----D---- C:\Documents and Settings\owner.LONEWOLF\Application Data\Malwarebytes
2009-04-14 22:28:40 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-04-14 22:28:39 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-03-24 03:33:04 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-03-24 03:32:11 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-03-24 03:31:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-03-24 03:31:05 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-03-24 03:30:43 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-03-24 03:29:14 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-03-24 03:28:15 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-03-24 03:28:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-03-24 03:26:14 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-03-24 03:23:49 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-03-24 03:23:39 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-03-24 03:23:26 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-03-24 03:23:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-03-24 03:22:59 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-03-24 03:21:07 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-03-24 03:20:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-03-24 03:20:32 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-03-24 03:15:37 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-03-24 03:06:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-03-24 03:06:33 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-03-24 03:05:38 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-03-24 03:05:26 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-03-24 03:05:14 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-03-24 03:04:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-03-24 03:03:45 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-03-21 07:49:09 ----D---- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-21 07:31:02 ----D---- C:\Documents and Settings\owner.LONEWOLF\Application Data\AVSMedia
2009-03-21 07:27:30 ----D---- C:\Documents and Settings\owner.LONEWOLF\Application Data\AVS4YOU
2009-03-21 07:27:01 ----D---- C:\Program Files\AVS4YOU
2009-03-17 21:31:14 ----D---- C:\Program Files\Common Files\Stardock
2009-03-14 23:40:27 ----A---- C:\Documents and Settings\owner.LONEWOLF\Application Data\inst.exe
2009-03-14 23:40:26 ----D---- C:\Documents and Settings\owner.LONEWOLF\Application Data\Vso
2009-03-14 23:40:17 ----A---- C:\WINDOWS\system32\sipr3260.dll
2009-03-14 23:40:17 ----A---- C:\WINDOWS\system32\drv43260.dll
2009-03-14 23:40:17 ----A---- C:\WINDOWS\system32\drv33260.dll
2009-03-14 23:40:16 ----A---- C:\WINDOWS\system32\wvc1dmod.dll
2009-03-14 23:40:16 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2009-03-14 23:40:16 ----A---- C:\WINDOWS\system32\drv23260.dll
2009-03-14 23:40:16 ----A---- C:\WINDOWS\system32\cook3260.dll
2009-03-14 23:40:14 ----D---- C:\Program Files\VSO
2009-03-09 17:04:21 ----D---- C:\Program Files\audible
2009-03-09 16:52:40 ----D---- C:\Documents and Settings\owner.LONEWOLF\Application Data\Creative
2009-03-09 16:03:29 ----N---- C:\WINDOWS\Ctregrun.exe
2009-03-09 16:02:43 ----N---- C:\WINDOWS\system32\msxml3a.dll
2009-03-09 16:01:08 ----HDC---- C:\WINDOWS\$NtUninstallKB895316$
2009-03-09 15:58:51 ----D---- C:\Documents and Settings\All Users\Application Data\Creative
2009-03-09 15:57:20 ----N---- C:\WINDOWS\system32\CTSVCCTL.EXE
2009-03-09 15:57:20 ----N---- C:\WINDOWS\system32\CTSVCCDA.EXE
2009-03-09 15:56:58 ----D---- C:\Program Files\Creative
2009-03-09 15:56:47 ----D---- C:\Program Files\Common Files\Creative
2009-03-09 15:56:45 ----HD---- C:\Program Files\Creative Installation Information
2009-03-04 11:34:52 ----D---- C:\Program Files\Microsoft SharedView
2009-03-04 11:06:57 ----N---- C:\WINDOWS\system32\spmsg2.dll
2009-03-03 23:24:38 ----D---- C:\Documents and Settings\owner.LONEWOLF\Application Data\muvee Technologies
2009-02-27 18:43:10 ----A---- C:\WINDOWS\system32\RIOWMSP.DLL
2009-02-27 18:42:36 ----D---- C:\VirginDrivers

======List of files/folders modified in the last 3 months======

2009-04-17 10:57:59 ----D---- C:\Program Files
2009-04-17 10:57:46 ----D---- C:\WINDOWS\Prefetch
2009-04-17 10:17:28 ----D---- C:\WINDOWS
2009-04-17 10:16:58 ----D---- C:\WINDOWS\system32\Lang
2009-04-17 10:16:47 ----D---- C:\WINDOWS\Temp
2009-04-17 10:16:41 ----D---- C:\WINDOWS\Registration
2009-04-17 10:16:00 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-17 08:29:32 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-16 05:21:37 ----D---- C:\WINDOWS\system32\drivers
2009-04-15 22:36:09 ----D---- C:\QUARANTINE
2009-04-15 19:14:21 ----D---- C:\WINDOWS\system32
2009-04-15 18:27:22 ----D---- C:\WINDOWS\system32\wbem
2009-04-15 18:27:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-15 11:13:21 ----D---- C:\WINDOWS\AppPatch
2009-04-15 11:09:57 ----D---- C:\WINDOWS\Debug
2009-04-15 11:09:49 ----HD---- C:\WINDOWS\inf
2009-04-15 11:09:44 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-04-15 11:09:40 ----D---- C:\WINDOWS\system32\en-US
2009-04-15 11:09:40 ----D---- C:\Program Files\Internet Explorer
2009-04-15 11:09:30 ----D---- C:\WINDOWS\ie7updates
2009-04-15 11:08:38 ----HD---- C:\WINDOWS\$hf_mig$
2009-04-15 11:07:53 ----SHD---- C:\WINDOWS\Installer
2009-04-15 11:07:47 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-04-15 11:06:42 ----A---- C:\WINDOWS\win.ini
2009-04-13 05:05:55 ----ASH---- C:\WINDOWS\system32\rukifopi.exe
2009-04-08 17:54:13 ----D---- C:\My Installed Software
2009-04-06 21:57:58 ----D---- C:\Program Files\Common Files\DVDVIDEOSOFT
2009-03-27 21:54:49 ----D---- C:\WINDOWS\system32\FxsTmp
2009-03-24 03:32:14 ----D---- C:\Program Files\Messenger
2009-03-24 03:26:15 ----D---- C:\WINDOWS\WinSxS
2009-03-24 03:22:46 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2009-03-24 03:22:06 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-03-24 03:19:31 ----D---- C:\Program Files\Microsoft ActiveSync
2009-03-24 03:19:02 ----RSD---- C:\WINDOWS\Fonts
2009-03-24 03:18:06 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-03-24 03:04:26 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-24 03:03:32 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2009-03-23 11:04:54 ----D---- C:\WINDOWS\Help
2009-03-21 09:06:58 ----A---- C:\WINDOWS\system32\kernel32.dll
2009-03-21 07:49:35 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-03-21 07:49:34 ----D---- C:\Program Files\iTunes
2009-03-21 07:49:12 ----D---- C:\Program Files\iPod
2009-03-21 07:49:12 ----D---- C:\Program Files\Common Files\Apple
2009-03-21 07:47:12 ----D---- C:\Program Files\Bonjour
2009-03-21 07:46:20 ----D---- C:\Program Files\QuickTime
2009-03-21 07:43:49 ----D---- C:\Program Files\Apple Software Update
2009-03-21 07:43:44 ----SD---- C:\WINDOWS\Tasks
2009-03-21 07:29:29 ----D---- C:\Program Files\Common Files\AVSMedia
2009-03-17 21:31:14 ----D---- C:\Program Files\Common Files
2009-03-17 21:10:19 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-03-17 21:10:18 ----D---- C:\Program Files\Symantec
2009-03-17 21:03:37 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2009-03-13 05:11:41 ----A---- C:\fiosLog.txt
2009-03-11 10:23:35 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-03-10 22:42:08 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-09 16:39:58 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-03-08 20:35:15 ----A---- C:\WINDOWS\cdplayer.ini
2009-03-06 09:22:18 ----A---- C:\WINDOWS\system32\pdh.dll
2009-03-04 12:02:37 ----D---- C:\Program Files\Common Files\muvee Technologies
2009-03-04 11:07:21 ----D---- C:\WINDOWS\system32\spool
2009-03-03 23:10:25 ----SD---- C:\Documents and Settings\owner.LONEWOLF\Application Data\Microsoft
2009-03-02 19:18:25 ----A---- C:\WINDOWS\system32\wininet.dll
2009-02-27 18:42:41 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-02-20 13:09:38 ----N---- C:\WINDOWS\system32\occache.dll
2009-02-20 13:09:38 ----N---- C:\WINDOWS\system32\mstime.dll
2009-02-20 13:09:38 ----N---- C:\WINDOWS\system32\msrating.dll
2009-02-20 13:09:38 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-02-20 13:09:38 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-02-20 13:09:38 ----A---- C:\WINDOWS\system32\url.dll
2009-02-20 13:09:38 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-02-20 13:09:38 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-02-20 13:09:38 ----A---- C:\WINDOWS\system32\ieencode.dll
2009-02-20 13:09:37 ----N---- C:\WINDOWS\system32\jsproxy.dll
2009-02-20 13:09:37 ----N---- C:\WINDOWS\system32\iernonce.dll
2009-02-20 13:09:37 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-02-20 13:09:37 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-02-20 13:09:37 ----A---- C:\WINDOWS\system32\msfeeds.dll
2009-02-20 13:09:37 ----A---- C:\WINDOWS\system32\iertutil.dll
2009-02-20 13:09:36 ----N---- C:\WINDOWS\system32\iedkcs32.dll
2009-02-20 13:09:36 ----N---- C:\WINDOWS\system32\ieaksie.dll
2009-02-20 13:09:36 ----N---- C:\WINDOWS\system32\ieakeng.dll
2009-02-20 13:09:36 ----N---- C:\WINDOWS\system32\extmgr.dll
2009-02-20 13:09:36 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-02-20 13:09:36 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2009-02-20 13:09:36 ----A---- C:\WINDOWS\system32\icardie.dll
2009-02-20 13:09:36 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-02-20 13:09:35 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-02-20 13:09:35 ----A---- C:\WINDOWS\system32\advpack.dll
2009-02-20 05:20:49 ----N---- C:\WINDOWS\system32\ie4uinit.exe
2009-02-20 05:20:49 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-02-20 00:14:12 ----N---- C:\WINDOWS\system32\ieakui.dll
2009-02-09 07:10:49 ----A---- C:\WINDOWS\system32\lsasrv.dll
2009-02-09 07:10:48 ----A---- C:\WINDOWS\system32\rpcss.dll
2009-02-09 07:10:48 ----A---- C:\WINDOWS\system32\ntdll.dll
2009-02-09 07:10:48 ----A---- C:\WINDOWS\system32\advapi32.dll
2009-02-06 17:45:27 ----D---- C:\Documents and Settings\owner.LONEWOLF\Application Data\DivX
2009-02-06 06:11:05 ----A---- C:\WINDOWS\system32\services.exe
2009-02-06 06:06:41 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2009-02-06 05:39:08 ----A---- C:\WINDOWS\system32\sc.exe
2009-02-06 05:32:56 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2009-02-03 14:59:07 ----A---- C:\WINDOWS\system32\secur32.dll
2009-01-22 23:24:45 ----D---- C:\Downloads

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [2008-07-19 25244]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 mferkdk;VSCore mferkdk; \??\C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys []
R1 mfetdik;McAfee Inc.; C:\WINDOWS\system32\drivers\mfetdik.sys [2006-11-30 52136]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2007-01-20 31644]
R1 vmm;Virtual Machine Monitor; \??\C:\WINDOWS\system32\drivers\vmm.sys []
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-06-30 1094848]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-04 36224]
R3 aracpi;aracpi; C:\WINDOWS\system32\DRIVERS\aracpi.sys [2005-08-03 22784]
R3 arhidfltr;MS Ar HID Filter Driver; C:\WINDOWS\system32\DRIVERS\arhidfltr.sys [2005-08-03 19200]
R3 arkbcfltr;Microsoft PS2 Keyboard Filter; C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-03 5376]
R3 armoucfltr;Microsoft PS2 Mouse Filter; C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-03 4992]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ARPolicy;ARPolicy; C:\WINDOWS\system32\DRIVERS\arpolicy.sys [2005-08-03 10112]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-10 1273856]
R3 dsNcAdpt;Juniper Network Connect Adapter; C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2008-08-13 23552]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2009-01-15 23848]
R3 hcwPP2;Hauppauge WinTV PVR PCI II ([23|25|26]xxx); C:\WINDOWS\system32\DRIVERS\hcwPP2.sys [2005-07-28 156800]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidIr;Microsoft Infrared HID Driver; C:\WINDOWS\system32\DRIVERS\hidir.sys [2008-04-13 19200]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-08-18 3856896]
R3 IrBus;Infrared bus filter driver for eHome remote controls; C:\WINDOWS\system32\DRIVERS\IrBus.sys [2008-04-13 46592]
R3 mfeapfk;McAfee Inc.; C:\WINDOWS\system32\drivers\mfeapfk.sys [2006-11-30 64360]
R3 mfeavfk;McAfee Inc.; C:\WINDOWS\system32\drivers\mfeavfk.sys [2006-11-30 72264]
R3 mfebopk;McAfee Inc.; C:\WINDOWS\system32\drivers\mfebopk.sys [2006-11-30 34152]
R3 mfehidk;McAfee Inc.; C:\WINDOWS\system32\drivers\mfehidk.sys [2007-02-22 170408]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MxlW2k;MxlW2k; C:\WINDOWS\system32\drivers\MxlW2k.sys [2009-02-27 28352]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-03-14 47360]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-12 19072]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
S3 61883;61883 Unit Device; C:\WINDOWS\system32\DRIVERS\61883.sys [2008-04-13 48128]
S3 Avc;AVC Device; C:\WINDOWS\system32\DRIVERS\avc.sys [2008-04-13 38912]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 E100B;Intel® PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2004-10-14 155648]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS\system32\DRIVERS\msdv.sys [2008-04-13 51200]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 PID_0920;Logitech QuickCam Express(PID_0920); C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2003-09-15 152576]
S3 RIOUNIV;Rio universal USB driver; C:\WINDOWS\System32\Drivers\RIOUNIV.sys [2004-02-12 16128]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt2870.sys [2007-11-16 550272]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-03-06 132424]
R2 ARSVC;ARSVC; C:\WINDOWS\arservice.exe [2005-08-03 58880]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-10 380928]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-07-25 100032]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-12 44032]
R2 CSHelper;CopySafe Helper Service; C:\WINDOWS\system32\CSHelper.exe [2008-09-20 192512]
R2 dsNcService;Juniper Network Connect Service; C:\Program Files\Juniper Networks\Common Files\dsNcService.exe [2008-08-13 427376]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-07-25 53248]
R2 McAfeeFramework;McAfee Framework Service; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [2006-12-19 104000]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 McShield;McAfee McShield; C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe [2007-02-22 144960]
R2 McTaskManager;McAfee Task Manager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [2007-02-22 54872]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE [2007-08-09 73728]
R2 SymWSC;SymWMI Service; c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe [2004-11-03 316544]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-03-12 656168]
S2 MCE Buddy;MCE Buddy Service; C:\My Installed Software\MCEBuddy\MCEBuddySvc.exe [2007-12-16 20480]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-04-07 136120]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-07-25 2119360]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------

#5 Dooderty

Dooderty
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 17 April 2009 - 11:02 AM

RSIT info.txt

info.txt logfile of random's system information tool 1.06 2009-04-17 10:58:17

======Uninstall list======

-->"C:\Program Files\Creative Installation Information\CD_RIPPER_UNICODE_2\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_SYNC_MANAGER_U\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\CREATIVE_VIDEO_CONVERTER\Setup.exe" /remove /l0x0009
-->"C:\Program Files\Creative Installation Information\ZEN_MTP_MEDIA_EXPLORER\Setup.exe" /remove /l0x0009
-->C:\My Installed Software\DivX\DivXConverterUninstall.exe /CONVERTER
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
-->c:\WINDOWS\system32\\MSIEXEC.EXE /x {F80239D8-7811-4D5E-B033-0D0BBFE32920}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 7.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Advanced SystemCare 3-->"C:\My Installed Software\Advanced SystemCare 3\unins000.exe"
Agere Systems PCI Soft Modem-->agrsmdel
Apple Mobile Device Support-->MsiExec.exe /I{162B71B8-8464-4680-A086-601D555B331D}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ATI Catalyst Control Center-->MsiExec.exe /I{9A945BB0-FB9C-4DAA-9C72-789E4B97C595}
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AudibleManager-->C:\My Installed Software\Creative\Audible\Bin\Upgrade.exe /Uninstall
AVS Update Manager 1.0-->"C:\Program Files\AVS4YOU\AVSUpdateManger\unins000.exe"
Bejeweled 2 Deluxe from HP Media Center (remove only)-->"C:\Program Files\WildTangent\Apps\GameChannel\Games\47D5A62B-1B41-4DB1-8267-ADA434FA782B\Uninstall.exe"
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
BootSkin-->C:\MYINST~1\BootSkin\UNWISE.EXE C:\MYINST~1\BootSkin\INSTALL.LOG
CCleaner (remove only)-->"C:\My Installed Software\CCleaner\uninst.exe"
CmdHere Powertoy For Windows XP-->MsiExec.exe /I{6855CCDD-BDF9-48E4-B80A-80DFB96FE36C}
ConvertXtoDVD 3.4.7.121-->"C:\My Installed Software\ConvertX\3\unins000.exe"
CopySafe Plugin-->MsiExec.exe /X{A285E15B-62B6-4259-997D-DCD6F34CDA80}
Creative System Information-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
Creative ZEN-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1B2DBF55-05D4-4072-87D8-689141E262BD}\SETUP.EXE" -l0x9 /remove
Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
DivX Codec-->C:\My Installed Software\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\My Installed Software\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\My Installed Software\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\My Installed Software\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->C:\My Installed Software\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Dziobas Rar Player 0.007PL-->"C:\My Installed Software\Dziobas Rar Player\unins000.exe"
Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
Free Video to iPod Converter version 3.1-->"C:\My Installed Software\Free Video to iPod Converter\unins000.exe"
Free YouTube to iPod Converter version 3.1-->"C:\My Installed Software\Free YouTube to iPod Converter\unins000.exe"
GemMaster Mystic-->"C:\Program Files\GemMaster\uninstallgemmaster.exe"
Google Toolbar for Firefox-->MsiExec.exe /X{2CCBABCB-6427-4A55-B091-49864623C43F}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915800-v4)-->"C:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Boot Optimizer-->MsiExec.exe /I{3BA95526-6AE0-4B87-A62D-17187EF565FC}
HP Deskjet Printer Preload-->MsiExec.exe /I{2C5D07FB-31A2-4F2D-9FDA-0B24ACD42BD0}
HP DigitalMedia Archive-->MsiExec.exe /I{F80239D8-7811-4D5E-B033-0D0BBFE32920}
HP Document Viewer 5.3-->C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
HP Game Console and games-->C:\Program Files\WildTangent\Apps\hpuninstall.exe
HP Image Zone 5.3-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Image Zone for Media Center PC-->c:\Program Files\HP\Digital Imaging\bin\mcpc\setupmcl.exe /u
HP Imaging Device Functions 5.3-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart 330,380,420,470,7800,8000,8200 Series-->C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\setup\hpzscr01.exe -d MsiRollbackUninstaller -datfile hphscr08.dat
HP Photosmart Cameras 5.0-->C:\Program Files\HP\Digital Imaging\{C83A12B9-B31B-461A-BBD4-CE9B988094F1}\setup\hpzscr01.exe -datfile hpiscr01.dat
HP PSC & OfficeJet 5.3.B-->"C:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
HP Software Update-->MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
HP Solution Center & Imaging Support Tools 5.3-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Tunes-->MsiExec.exe /X{D54193B7-D2DF-4977-B546-86CA48DB214E}
HPTunesAddIn-->MsiExec.exe /I{69CF01AD-9E35-4BD7-9036-7B8478BEB839}
Intel® PRO Network Connections Drivers-->Prounstl.exe
IntelliMover Data Transfer Demo-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14589F05-C658-4594-9429-D437BA688686}\Setup.exe" -l0x9
InterVideo WinDVD Player-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
iTunes-->MsiExec.exe /I{C26B06A9-27BB-45B0-9873-9C623EC2BA38}
J2SE Runtime Environment 5.0-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
Java™ 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Juniper Networks Network Connect 6.0.0-->"C:\Program Files\Juniper Networks\Network Connect 6.0.0\uninstall.exe"
LiveUpdate 3.0 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee VirusScan Enterprise-->MsiExec.exe /I{35C03C04-3F1F-42C2-A989-A757EE691F65}
MCEBuddy-->MsiExec.exe /I{BAFC1680-D56C-4079-98B7-B71B99F29647}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Ultimate 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ULTIMATER /dll OSETUP.DLL
Microsoft Office Ultimate 2007-->MsiExec.exe /X{91120000-002E-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft SharedView-->MsiExec.exe /I{E6DE9A54-8514-446E-9D11-530DC599C355}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Virtual PC 2007 SP1-->MsiExec.exe /X{AD483998-2E9A-4405-83FF-6E503AF49CBB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works-->MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
Mozilla Firefox (2.0.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MUSICMATCH® Jukebox-->C:\PROGRA~1\MUSICM~1\MUSICM~1\unmatch.exe
muvee autoProducer 4.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2C3D719A-92C7-4323-89CC-C937D0267B84}\setup.exe" -l0x9
muvee autoProducer unPlugged 1.1 - HPD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B1931B3A-29E9-4F91-9B61-BE2CF05E84F1}\setup.exe" -l0x9
Nitro PDF Professional-->MsiExec.exe /I{29F2FE64-EFCE-4FC5-8FEB-16B688578F89}
Norton Security Center-->MsiExec.exe /X{503AA035-41E2-4858-B31F-1E49AC66C309}
Office 2003 Tour-->MsiExec.exe /I{BE9FEFBA-F2F8-468B-A108-4356F73A3E9C}
Otto-->"C:\Program Files\EnglishOtto\uninstallotto.exe"
Password Keeper-->C:\WINDOWS\SDUnInst.exe c:\my installed software\password keeper v7\passkeep.uni
Perfect Uninstaller v6.3.2.7-->"C:\My Installed Software\Perfect Uninstaller\unins000.exe"
Picasa 3-->"C:\My Installed Software\Picasa3\Uninstall.exe"
Polar Bowler from HP Media Center (remove only)-->"C:\Program Files\WildTangent\Apps\GameChannel\Games\1FFA88DF-0AC3-4D9E-9139-5FF98813C12C\Uninstall.exe"
PowerISO-->"C:\My Installed Software\PowerISO\uninstall.exe"
PS2-->C:\WINDOWS\system32\ps2.exe uninstall
Python 2.2 pywin32 extensions (build 203)-->"C:\Python22\Removepywin32.exe" -u "C:\Python22\pywin32-wininst.log"
Python 2.2.3-->C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
QuickTime-->MsiExec.exe /I{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
SCRABBLE Blast from HP Media Center (remove only)-->"C:\Program Files\WildTangent\Apps\GameChannel\Games\2BA80327-9385-4EC8-9796-47C49BD73352\Uninstall.exe"
SCRABBLE from HP Media Center (remove only)-->"C:\Program Files\WildTangent\Apps\GameChannel\Games\B7217206-A362-446B-A0F7-A2622B82F821\Uninstall.exe"
SCRABBLE Rack Attack from HP Media Center (remove only)-->"C:\Program Files\WildTangent\Apps\GameChannel\Games\EC03679F-C9F0-46E8-864D-FCCF83F4EB86\Uninstall.exe"
Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB960003)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {F04F8702-18D0-458D-921E-146FB7CD38CF}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft Office Excel 2007 (KB959997)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {9EAC3AEC-5C81-4856-A05B-DE9DC236D740}
Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Shareaza version 2.2.5.6-->"C:\My Installed Software\Shareaza\Shareaza\Uninstall\unins000.exe"
SnagIt 7-->MsiExec.exe /I{4360BB46-507E-4361-8DCB-4FF9BDC9907B}
Sonic Encoders-->MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Sonic MyDVD Plus-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
TreeSize Professional 5.1-->"C:\Program Files\JAM Software\TreeSize Professional\unins000.exe"
Uninstall 1.0.0.1-->"C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
Update for Office 2007 (KB946691)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb962871)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {297857BF-4011-449B-BD74-DB64D182821C}
Update for Windows Media Player 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Updates from HP (remove only)-->C:\WINDOWS\HPCPCUninstall-9972322\HPBWSetup.exe -appid 9972322 -uninstall
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
Verizon Media Manager-->MsiExec.exe /I{C74C97D8-8962-411C-B223-F60E6336C405}
Verizon Online Help and Support-->C:\PROGRA~1\Verizon\UNWISE.EXE C:\PROGRA~1\Verizon\INSTALL.LOG
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 10 Hotfix - KB895316-->"C:\WINDOWS\$NtUninstallKB895316$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Mobile® Device Handbook-->C:\Program Files\Windows Mobile Device Handbook\Windows Mobile Device Handbook\Bin\DHUninstall.exe
Windows Search 4.0-->"C:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\My Installed Software\WinRAR\uninstall.exe
ZENcast Organizer-->"C:\Program Files\Creative Installation Information\ZENCAST_ORGANIZER\Setup.exe" /remove /l0x0009

======Hosts File======

127.0.0.1 localhost
82.98.231.89 browser-security.microsoft.com
82.98.231.89 best-click-scanner.info

======Security center information======

AV: McAfee VirusScan Enterprise

======System event log======

Computer Name: LONEWOLF
Event Code: 256
Message: Timed out sending notification of device interface change to window of "C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe"

Record Number: 24178
Source Name: PlugPlayManager
Time Written: 20090323115054.000000-300
Event Type: warning
User:

Computer Name: LONEWOLF
Event Code: 256
Message: Timed out sending notification of device interface change to window of "C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe"

Record Number: 24177
Source Name: PlugPlayManager
Time Written: 20090323115054.000000-300
Event Type: warning
User:

Computer Name: LONEWOLF
Event Code: 256
Message: Timed out sending notification of device interface change to window of "C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe"

Record Number: 24176
Source Name: PlugPlayManager
Time Written: 20090323115054.000000-300
Event Type: warning
User:

Computer Name: LONEWOLF
Event Code: 256
Message: Timed out sending notification of device interface change to window of "C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe"

Record Number: 24175
Source Name: PlugPlayManager
Time Written: 20090323115054.000000-300
Event Type: warning
User:

Computer Name: LONEWOLF
Event Code: 256
Message: Timed out sending notification of device interface change to window of "C:\My Installed Software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe"

Record Number: 24174
Source Name: PlugPlayManager
Time Written: 20090323115054.000000-300
Event Type: warning
User:

=====Application event log=====

Computer Name: LONEWOLF
Event Code: 1517
Message: Windows saved user LONEWOLF\owner registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 22988
Source Name: Userenv
Time Written: 20090324223039.000000-300
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: LONEWOLF
Event Code: 1000
Message: Faulting application maxthon.exe, version 1.6.3.80, faulting module unknown, version 0.0.0.0, fault address 0xffff0ec7.

Record Number: 22951
Source Name: Application Error
Time Written: 20090324220420.000000-300
Event Type: error
User:

Computer Name: LONEWOLF
Event Code: 0
Message: Unable to start MCEBuddy, setup is invalid

Record Number: 22888
Source Name: MCEBuddy
Time Written: 20090324034127.000000-300
Event Type: error
User:

Computer Name: LONEWOLF
Event Code: 0
Message: Unable to destination path O:\New Folder\Recorded TV\Recorded MCEBuddy
If this is a network path, please ensure the account supplied has permissions to this location.

Record Number: 22887
Source Name: MCEBuddy
Time Written: 20090324034127.000000-300
Event Type: error
User:

Computer Name: LONEWOLF
Event Code: 1517
Message: Windows saved user LONEWOLF\owner registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 22879
Source Name: Userenv
Time Written: 20090324033926.000000-300
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI.ACE\;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 4, GenuineIntel
"PROCESSOR_REVISION"=0404
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"SonicCentral"=c:\Program Files\Common Files\Sonic Shared\Sonic Central\
"VSEDEFLOGDIR"=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
"DEFLOGDIR"=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------

#6 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:08:31 AM

Posted 17 April 2009 - 11:03 AM

Ok.. waiting for GMER result.. In the mean time, I have to do something important and will be back about 4-6 hours from now :thumbup2:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#7 Dooderty

Dooderty
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 17 April 2009 - 03:27 PM

Boy that took a while but here we go...GMER results

Attached Files

  • Attached File  GMER.txt   85.75KB   1 downloads


#8 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:08:31 AM

Posted 17 April 2009 - 09:03 PM

IMPORTANT!! Uninstall these programs first (if present..) so that they won't interfere with our fixes..

1. Ask Toolbar
2. Lavasoft Ad-Aware
3. Spybot - Search & Destroy
4. Viewpoint (all of them..)



Please re-open HijackThis and click on Do a system scan only. Check the boxes next to all the entries listed below.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.myway.com/index.jsp?speedbarconfigchanged
O1 - Hosts: 82.98.231.89 browser-security.microsoft.com
O1 - Hosts: 82.98.231.89 best-click-scanner.info


Now close all windows other than HijackThis, then click Fix checked. Close HijackThis.



NEXT


Please download the OTMoveIt3 by OldTimer
  • Save it to your Desktop.
  • Please double-click OTMoveIt3.exe to run it. (Vista users, please right click on OTMoveit3.exe and select "Run as an Administrator")
  • Let the Unregister Dll's and Ocx's remain ticked and Zip Files After Moves remain unticked..
  • Copy the codebox contents and paste it to the "Paste List of Files/Folders to Move" window (under the light Yellow bar)

    :processes
    explorer.exe
    
    :services
    
    :files
    C:\WINDOWS\system32\voyasela.dll
    c:\windows\system32\wujaluta.dll
    C:\WINDOWS\system32\nakisidi.dll
    
    :reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1902804f]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM1a31b3d3]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\razikinoka]
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Run RSIT again... Post these logs in your next reply..

1. OTMoveIt3
2. RSIT log.txt

Edited by fenzodahl512, 17 April 2009 - 09:12 PM.

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#9 Dooderty

Dooderty
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 17 April 2009 - 10:25 PM

OTMoveIt3 results;

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== FILES ==========
File/Folder C:\WINDOWS\system32\voyasela.dll not found.
File/Folder c:\windows\system32\wujaluta.dll not found.
File/Folder C:\WINDOWS\system32\nakisidi.dll not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1902804f\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM1a31b3d3\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\razikinoka\\ deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\owner~1.LON\LOCALS~1\Temp\NAILogs\UpdaterUI_LONEWOLF.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\owner~1.LON\LOCALS~1\Temp\Perflib_Perfdata_c4.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\owner~1.LON\LOCALS~1\Temp\Perflib_Perfdata_cb0.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\owner~1.LON\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\Z57949FG\gca_iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\Z57949FG\index[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\ORD2T2U5\iframe[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\86PQBUPS\topic219216[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\WFV3.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04172009_220841

Files moved on Reboot...
C:\DOCUME~1\owner~1.LON\LOCALS~1\Temp\NAILogs\UpdaterUI_LONEWOLF.log moved successfully.
File C:\DOCUME~1\owner~1.LON\LOCALS~1\Temp\Perflib_Perfdata_c4.dat not found!
File C:\DOCUME~1\owner~1.LON\LOCALS~1\Temp\Perflib_Perfdata_cb0.dat not found!
C:\DOCUME~1\owner~1.LON\LOCALS~1\Temp\WCESLog.log moved successfully.
File C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\Z57949FG\gca_iframe[1].htm not found!
File C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\Z57949FG\index[2].htm not found!
File C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\ORD2T2U5\iframe[1].htm not found!
File C:\Documents and Settings\owner.LONEWOLF\Local Settings\Temporary Internet Files\Content.IE5\86PQBUPS\topic219216[1].htm not found!
File move failed. C:\WINDOWS\temp\WFV3.tmp scheduled to be moved on reboot.

Attached Files

  • Attached File  log.txt   46.67KB   8 downloads


#10 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:08:31 AM

Posted 17 April 2009 - 10:39 PM

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix.. Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

Please download ComboFix by sUBs from one of the locations below, and save it to your Desktop.Link 1
Link 2
Link 3
Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

When finished, it shall produce a log for you. Post that log and a fresh HijackThis log in your next reply..

Note: DON'T do anything with your computer while ComboFix is running.. Let ComboFix finishes its job..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#11 Dooderty

Dooderty
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 18 April 2009 - 12:06 AM

ComboFix Log;

ComboFix 09-04-13.A2 - owner 2009-04-17 23:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2445 [GMT -5:00]
Running from: c:\documents and settings\owner.LONEWOLF\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\owner.LONEWOLF\Application Data\inst.exe
c:\progra~1\COMMON~1\{19028~1
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-03-18 to 2009-04-18 )))))))))))))))))))))))))))))))
.

2009-04-18 03:08 . 2009-04-18 03:08 -------- d-----w C:\_OTMoveIt
2009-04-17 15:57 . 2009-04-17 15:58 -------- d-----w C:\rsit
2009-04-17 15:57 . 2009-04-17 15:58 -------- d-----w c:\program files\trend micro
2009-04-15 16:08 . 2009-04-15 16:09 1374 ----a-w c:\windows\imsins.BAK
2009-04-15 16:04 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-15 16:04 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 16:04 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-15 16:04 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 16:04 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 16:04 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 16:04 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 16:04 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 16:04 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 16:03 . 2009-03-27 06:58 1203922 ------w c:\windows\system32\dllcache\sysmain.sdb
2009-04-15 16:03 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-15 16:03 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 03:28 . 2009-04-15 03:28 -------- d-----w c:\documents and settings\owner.LONEWOLF\Application Data\Malwarebytes
2009-04-15 03:28 . 2009-04-06 20:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-15 03:28 . 2009-04-06 20:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-15 03:28 . 2009-04-15 03:28 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-15 03:28 . 2009-04-15 03:29 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-23 16:08 . 2009-02-06 11:06 2145280 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-23 16:08 . 2009-02-06 11:08 2189056 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-23 16:08 . 2009-02-06 10:32 2023936 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-23 16:08 . 2009-02-08 00:02 2066048 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-23 16:08 . 2008-10-24 11:21 455296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2009-03-23 16:08 . 2008-12-11 10:57 333952 ------w c:\windows\system32\dllcache\srv.sys
2009-03-23 16:08 . 2008-05-01 14:33 331776 ------w c:\windows\system32\dllcache\msadce.dll
2009-03-23 16:07 . 2008-04-11 19:04 691712 ------w c:\windows\system32\dllcache\inetcomm.dll
2009-03-23 16:07 . 2008-10-15 16:34 337408 ------w c:\windows\system32\dllcache\netapi32.dll
2009-03-23 16:07 . 2008-09-04 17:15 1106944 ------w c:\windows\system32\dllcache\msxml3.dll
2009-03-21 14:06 . 2009-03-21 14:06 989696 ------w c:\windows\system32\dllcache\kernel32.dll
2009-03-21 12:49 . 2009-03-21 12:49 -------- d-----w c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-21 12:31 . 2009-03-21 12:31 -------- d-----w c:\documents and settings\owner.LONEWOLF\Application Data\AVSMedia
2009-03-21 12:27 . 2009-03-21 12:27 -------- d-----w c:\documents and settings\owner.LONEWOLF\Application Data\AVS4YOU
2009-03-21 12:27 . 2009-03-21 12:27 -------- d-----w c:\program files\AVS4YOU

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-18 04:44 . 2009-04-18 04:44 32768 --sha-w c:\windows\Temp\Temporary Internet Files\Content.IE5\index.dat
2009-04-18 04:44 . 2009-04-18 04:44 32768 --sha-w c:\windows\Temp\History\History.IE5\index.dat
2009-04-18 04:44 . 2009-04-18 04:44 16384 --sha-w c:\windows\Temp\Cookies\index.dat
2009-04-18 03:13 . 2008-07-01 22:38 95064 ----a-w c:\documents and settings\owner.LONEWOLF\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-15 16:07 . 2007-01-06 22:41 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-13 10:05 . 2009-01-13 10:05 51200 --sha-w c:\windows\system32\rukifopi.exe
2009-04-13 10:05 . 2009-01-13 10:05 51200 --sha-w c:\windows\system32\rukifopi.exe
2009-04-08 14:05 . 2009-03-15 04:40 -------- d-----w c:\documents and settings\owner.LONEWOLF\Application Data\Vso
2009-04-07 02:57 . 2007-09-11 20:59 -------- d-----w c:\program files\Common Files\DVDVIDEOSOFT
2009-03-24 08:19 . 2008-06-28 22:05 -------- d-----w c:\program files\Microsoft ActiveSync
2009-03-21 12:49 . 2005-10-18 23:07 -------- d-----w c:\program files\iTunes
2009-03-21 12:49 . 2007-07-04 15:11 -------- d-----w c:\program files\Common Files\Apple
2009-03-21 12:49 . 2005-10-18 23:07 -------- d-----w c:\program files\iPod
2009-03-21 12:47 . 2008-05-01 21:17 -------- d-----w c:\program files\Bonjour
2009-03-21 12:46 . 2005-10-18 23:08 -------- d-----w c:\program files\QuickTime
2009-03-21 12:43 . 2007-04-19 23:56 -------- d-----w c:\program files\Apple Software Update
2009-03-21 12:29 . 2007-04-26 02:46 -------- d-----w c:\program files\Common Files\AVSMedia
2009-03-18 22:09 . 2009-03-18 02:31 163712 ----a-w c:\windows\system32\drivers\vidstub.sys
2009-03-18 02:31 . 2009-03-18 02:31 -------- d-----w c:\program files\Common Files\Stardock
2009-03-18 02:10 . 2005-10-18 23:27 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-18 02:10 . 2005-10-18 23:26 -------- d-----w c:\program files\Symantec
2009-03-18 02:03 . 2005-10-18 23:26 -------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-15 04:40 . 2009-03-15 04:40 47360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-03-15 04:40 . 2009-03-15 04:40 47360 ----a-w c:\documents and settings\owner.LONEWOLF\Application Data\pcouffin.sys
2009-03-15 04:40 . 2009-03-15 04:40 -------- d-----w c:\program files\VSO
2009-03-13 10:11 . 2008-12-15 17:11 6448 ----a-w C:\fiosLog.txt
2009-03-11 15:23 . 2007-03-01 02:48 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-11 03:42 . 2005-10-18 23:02 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-10 02:58 . 2009-03-09 21:52 -------- d-----w c:\documents and settings\owner.LONEWOLF\Application Data\Creative
2009-03-09 22:04 . 2009-03-09 22:04 -------- d-----w c:\program files\audible
2009-03-09 21:47 . 2009-03-09 20:58 -------- d-----w c:\documents and settings\All Users\Application Data\Creative
2009-03-09 21:03 . 2009-03-09 20:56 -------- d-----w c:\program files\Creative
2009-03-09 20:59 . 2009-03-09 20:56 -------- d--h--w c:\program files\Creative Installation Information
2009-03-09 20:56 . 2009-03-09 20:56 -------- d-----w c:\program files\Common Files\Creative
2009-03-06 14:22 . 2004-08-10 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-04 17:02 . 2005-10-18 23:10 -------- d-----w c:\program files\Common Files\muvee Technologies
2009-03-04 16:34 . 2009-03-04 16:34 -------- d-----w c:\program files\Microsoft SharedView
2009-03-04 16:34 . 2009-03-04 04:24 -------- d-----w c:\documents and settings\owner.LONEWOLF\Application Data\muvee Technologies
2009-03-03 00:18 . 2004-08-10 12:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-03 00:18 . 2004-08-10 12:00 826368 ------w c:\windows\system32\dllcache\wininet.dll
2009-02-28 04:54 . 2004-08-10 12:00 636072 ------w c:\windows\system32\dllcache\iexplore.exe
2009-02-27 23:42 . 2009-02-27 23:41 28352 ----a-w c:\windows\system32\drivers\MxlW2k.sys
2009-02-20 10:20 . 2008-06-28 05:03 13824 ------w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2004-08-10 12:00 70656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2004-08-10 12:00 161792 ------w c:\windows\system32\dllcache\ieakui.dll
2009-02-09 12:10 . 2004-08-10 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-11 02:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-10 12:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-10 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2009-02-09 11:13 1846784 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-10 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2004-08-10 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2004-08-10 12:00 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-10 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:39 . 2004-08-10 12:00 35328 ----a-w c:\windows\system32\dllcache\sc.exe
2009-02-06 10:32 . 2004-08-11 02:00 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2009-02-03 19:59 56832 ------w c:\windows\system32\dllcache\secur32.dll
2009-02-03 19:59 . 2004-08-10 12:00 56832 ----a-w c:\windows\system32\secur32.dll
2008-12-18 04:54 . 2008-07-16 13:18 95064 ----a-w c:\documents and settings\KJoy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-12-15 16:42 . 2008-12-15 16:42 61224 ----a-w c:\documents and settings\owner.LONEWOLF\GoToAssistDownloadHelper.exe
2008-09-04 02:53 . 2008-09-04 02:04 116 ----a-w c:\documents and settings\owner.LONEWOLF\Application Data\wklnhst.dat
2008-07-16 13:56 . 2008-07-11 01:14 127 ----a-w c:\documents and settings\KJoy\Local Settings\Application Data\fusioncache.dat
2008-06-27 11:33 . 2008-06-27 11:32 137 ----a-w c:\documents and settings\owner.LONEWOLF\Local Settings\Application Data\fusioncache.dat
2008-06-26 02:19 . 2008-06-26 02:19 50280 ----a-w c:\documents and settings\HP_Administrator.LONEWOLF\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-06-26 01:56 . 2008-06-26 01:49 148 ----a-w c:\documents and settings\HP_Administrator.LONEWOLF\Local Settings\Application Data\fusioncache.dat
2008-06-15 02:02 . 2005-12-10 07:02 92328 ----a-w c:\documents and settings\owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-05-26 14:57 . 2005-12-04 02:53 92328 ----a-w c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-01-25 17:47 . 2008-01-25 17:47 217088 ----a-w c:\documents and settings\owner\Local Settings\Application Data\Interop.Microsoft.Office.Core.dll
2007-08-09 21:50 . 2007-08-09 21:50 16384 ----a-w c:\documents and settings\owner\Local Settings\Application Data\stdole.dll
2005-12-04 05:53 . 2005-12-04 05:53 128 ----a-w c:\documents and settings\owner\Local Settings\Application Data\fusioncache.dat
2005-12-04 01:53 . 2005-12-04 01:44 139 ----a-w c:\documents and settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
2005-10-18 22:17 . 2005-10-18 22:17 136 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2008-07-09 16:2008-06-28 05:10 45:23 . c:\program files\mozilla firefox\components\jar50.dll
2008-07-09 16:2008-06-28 05:10 45:23 . c:\program files\mozilla firefox\components\jsd3250.dll
2008-07-09 16:2008-07-09 16:45 45:23 . c:\program files\mozilla firefox\components\myspell.dll
2008-07-09 16:2008-07-09 16:45 45:24 . c:\program files\mozilla firefox\components\spellchk.dll
2008-07-09 16:2008-06-28 05:10 45:24 . c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\owner.LONEWOLF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-13 133104]
"Advanced SystemCare 3"="c:\my installed software\Advanced SystemCare 3\AWC.exe" [2008-12-21 2250256]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-10 61440]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-22 112216]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 136768]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-09 185872]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-09-28 936960]
"Nitro PDF Printer Monitor"="c:\my installed software\Nitro PDF\NitroPDFPrinterMonitor.exe" [2008-12-05 210240]
"CTCheck"="c:\my installed software\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-18 c:\windows\RTHDCPL.EXE]

c:\documents and settings\owner\Start Menu\Programs\Startup\
Memeo AutoBackup Launcher.lnk - c:\documents and settings\owner\Application Data\Microsoft\Installer\{5E30A8A3-1430-43A0-A25E-503B3A7D32BA}\NewShortcut4_51A847D327C24F7797772AF2A4E486ED.exe [2008-02-02 73728]

c:\documents and settings\owner.LONEWOLF\Start Menu\Programs\Startup\
MCEBuddy Taskbar Monitor.lnk - c:\documents and settings\owner.LONEWOLF\Application Data\Microsoft\Installer\{BAFC1680-D56C-4079-98B7-B71B99F29647}\_7E43DD945644F5638C1291.exe [2008-07-04 2462]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ATI CATALYST System Tray.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-08-10 61440]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ad-Aware 2007.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Ad-Aware 2007.lnk
backup=c:\windows\pss\Ad-Aware 2007.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 14:39 1289000 c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-12 08:12 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2004-01-26 11:46 53248 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\My Installed Software\\Shareaza\\Shareaza\\Shareaza.exe"=
"c:\\My Installed Software\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\ehome\\ehtray.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R2 MCE Buddy;MCE Buddy Service;c:\my installed software\MCEBuddy\MCEBuddySvc.exe [2007-12-16 20480]
R3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\DRIVERS\LV532AV.SYS [2003-09-15 152576]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys [2007-11-16 550272]
S0 BootScreen;BootScreen; [x]
S2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [2008-09-20 192512]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Nitro PDF Professional]
cscript //B "c:\my installed software\Nitro PDF\RemoveOldAddins.vbs"
.
Contents of the 'Scheduled Tasks' folder

2009-04-10 c:\windows\Tasks\1-Click Maintenance.job
- c:\my installed software\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 16:53]

2009-04-18 c:\windows\Tasks\AWC AutoSweep.job
- c:\my installed software\Advanced SystemCare 3\AutoSweep.exe [2008-12-12 13:17]

2009-04-17 c:\windows\Tasks\AWC Update.job
- c:\my installed software\Advanced SystemCare 3\IObitUpdate.exe [2009-03-20 21:01]

2009-04-17 c:\windows\Tasks\AWC Update.job
- c:\my installed software\Advanced SystemCare 3\ [2009-04-17 22:13]

2009-04-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2372944-1335694676-2409864563-1009.job
- c:\documents and settings\owner.LONEWOLF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-13 09:31]

2009-04-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 20:20]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)


.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
DPF: {97770E5B-2028-48AC-B4DA-1F991376D2B6} - hxxp://download.copysafe.net/plugins5/installers/Copysafe.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-17 23:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(784)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-04-17 23:54
ComboFix-quarantined-files.txt 2009-04-18 04:54

Pre-Run: 26,140,913,664 bytes free
Post-Run: 30,517,223,424 bytes free

275 --- E O F --- 2009-03-25 03:21

Attached Files



#12 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:08:31 AM

Posted 18 April 2009 - 03:50 AM

Please show hidden files and folders
Find and delete this file manually..

c:\windows\system32\rukifopi.exe


Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan
    Wait for the scan to finish
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
How's the computer now? :thumbup2:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#13 Dooderty

Dooderty
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 18 April 2009 - 12:18 PM

Funny thing is when I searched for c:\windows\system32\rukifopi.exe the file is not present, so I started the ESet scanner. interestingly enough McAffee popped up showing if found and deleted c:\windows\system32\rukifopi.exe. Anyway the scan is still in progress. I will post log when complete.
I just wanted to speak out in advance for alll the great support youu have been providing me. Keep up the great work. :thumbup2:

#14 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:08:31 AM

Posted 18 April 2009 - 02:00 PM

Ok.. waiting for your report :thumbup2:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#15 Dooderty

Dooderty
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:07:31 PM

Posted 18 April 2009 - 03:01 PM

ESet Log;
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=4018 (20090418)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2009-04-18 07:38:01
# local_time=2009-04-18 02:38:01 (-0600, Central Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=1560989
# found=468
# scan_time=24517
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\keygenerator + crack Panda Platinum e Titanium antivirus 200623_02_06.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\keygenerator + crack Panda Platinum e Titanium antivirus 200623_02_06.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Koyote IPOD Video Converter 2.4.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Koyote IPOD Video Converter 2.4.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\LavaSoft Ad-Aware 2007 Professional 7.0.2 .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\LavaSoft Ad-Aware 2007 Professional 7.0.2 .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Lavasoft.Ad-Aware.2007.Professional.Edition.v7.0.1.3.Incl-key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Lavasoft.Ad-Aware.2007.Professional.Edition.v7.0.1.3.Incl-key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\LimeWire Pro 4.14 Spped Download Patch.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\LimeWire Pro 4.14 Spped Download Patch.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\LimeWire Pro 4.17.0 Keygen ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\LimeWire Pro 4.17.0 Keygen ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Macromedia DreamWeaver CS3 +Plugins and keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Macromedia DreamWeaver CS3 +Plugins and keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Macromedia DreamWeaver CS3 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Macromedia DreamWeaver CS3 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic DVD Ripper 5.2.2 key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic DVD Ripper 5.2.2 key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic DVD Ripper 5.2.2 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic DVD Ripper 5.2.2 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic ISO 5.4 + serial.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic ISO 5.4 + serial.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic ISO 5.41 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic ISO 5.41 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic ISO Maker 5.4 with serial .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic ISO Maker 5.4 with serial .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic Video Converter 8.0.2 (The Ultimate Video Converter).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic Video Converter 8.0.2 (The Ultimate Video Converter).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic Video Converter 8.0.2.19 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Magic Video Converter 8.0.2.19 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Max Payne 2 Nocd-keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Max Payne 2 Nocd-keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Maximus Multiband Maximizer .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Maximus Multiband Maximizer .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee Anti-Virus 10 keygen.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee Anti-Virus 10 keygen.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee Antivirus 10 ENG-ESP-FRA keygeneratorrar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee Antivirus 10 ENG-ESP-FRA keygeneratorrar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee VirusScan Enterprise 8.5 Licensed.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee VirusScan Enterprise 8.5 Licensed.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee.Total.Protection.2007.Multilingual.keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee.Total.Protection.2007.Multilingual.keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee.Total.Protection.2008.WorkingPatch.Update.TILL.20.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\McAfee.Total.Protection.2008.WorkingPatch.Update.TILL.20.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MediaMonkey 3.0 Full Multilingual.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MediaMonkey 3.0 Full Multilingual.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2003 Professional with SP1 2 3 .Working keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2003 Professional with SP1 2 3 .Working keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Complete + keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Complete + keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Complete Version Keygen.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Complete Version Keygen.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 COMPLETE.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 COMPLETE.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Crack-Serial-Keygen.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Crack-Serial-Keygen.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Enterprise Edition Incl Keygen.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Enterprise Edition Incl Keygen.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Enterprise Genuine Patch .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Enterprise Genuine Patch .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 FULL + Keygen ( Vista comp.).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 FULL + Keygen ( Vista comp.).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Keygen ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Keygen ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 keygen.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 keygen.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Ultimate.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office 2007 Ultimate.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office Home and Student Edition 2007 FULL Versions with Working Activation Key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office Home and Student Edition 2007 FULL Versions with Working Activation Key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office XP PRO includes word, excel, powerpoint, outloock.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Office XP PRO includes word, excel, powerpoint, outloock.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Visual Studio 2008 Professional Edition.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Visual Studio 2008 Professional Edition.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows Media Player 11 [NOCD-Crack].rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows Media Player 11 [NOCD-Crack].rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows Vista 32-X86-X64 Activation Key-(june 08).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows Vista 32-X86-X64 Activation Key-(june 08).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows Vista Ultimate x86 crack November 2007..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows Vista Ultimate x86 crack November 2007..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows VISTA Validation Crack 05-2008.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows VISTA Validation Crack 05-2008.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows XP Pro SP2 WGA Validation Patch..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows XP Pro SP2 WGA Validation Patch..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows XP Professional Update crack-serial-keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft Windows XP Professional Update crack-serial-keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft.Windows.VISTA.Ultimate.Activation.Code.Patch.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft.Windows.VISTA.Ultimate.Activation.Code.Patch.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft.Windows.Vista.Ultimate.x64.Integrated.December..2007.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft.Windows.Vista.Ultimate.x64.Integrated.December..2007.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft.Windows.Vista.Ultimate.x64.Integrated.January.2008.OEM.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft.Windows.Vista.Ultimate.x64.Integrated.January.2008.OEM.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft.Windows.XP.WGA.Validate.Patcher.(funciona.perfieto!).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Microsoft.Windows.XP.WGA.Validate.Patcher.(funciona.perfieto!).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MIRC.6.3.+.keygenerator.+Manuales.+instrucions+scripts.(Pack.by.eLs0M).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MIRC.6.3.+.keygenerator.+Manuales.+instrucions+scripts.(Pack.by.eLs0M).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MKV to AVI Converter 3.0.0.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MKV to AVI Converter 3.0.0.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Movie Collector Pro 5.25.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Movie Collector Pro 5.25.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MP3 Remix Plus 3.31 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MP3 Remix Plus 3.31 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MP3Resizer 1.8 ESP keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MP3Resizer 1.8 ESP keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MS Office 2007 Full DVD Incl SN.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MS Office 2007 Full DVD Incl SN.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MSN Messenger 8 Fully Patched for XP Sp2 and Windows ViSTA.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MSN Messenger 8 Fully Patched for XP Sp2 and Windows ViSTA.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MSN Webcam Recorder 7.0 Crack Only SCRiPTMAFiA Working updated-fixed 09-2006.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MSN Webcam Recorder 7.0 Crack Only SCRiPTMAFiA Working updated-fixed 09-2006.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MSN.Messenger.8.Working.Patch..to.nudge.all.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\MSN.Messenger.8.Working.Patch..to.nudge.all.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\My Screen Recorder Pro 2.3 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\My Screen Recorder Pro 2.3 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra 8.1 ESPANOL co key funcionante actualizado!.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra 8.1 ESPANOL co key funcionante actualizado!.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition Key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition Key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition 8.1.1+Key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition 8.1.1+Key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition 8.2+Keymaker.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition 8.2+Keymaker.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition 8.2.8 (keygenerator).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition 8.2.8 (keygenerator).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition Serial Key .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 Ultra Edition Serial Key .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 with instructions(Only version that is fully keygenerator).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8 with instructions(Only version that is fully keygenerator).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8.2.8 Ultra Edition incl. keygenerator(WORKS PERFECT).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nero 8.2.8 Ultra Edition incl. keygenerator(WORKS PERFECT).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\nero crack 7.10.2.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\nero crack 7.10.2.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\nero.7.2.0.3b (keygenerator).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\nero.7.2.0.3b (keygenerator).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nidesoft DVD Audio Ripper v3.0.50 crack..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nidesoft DVD Audio Ripper v3.0.50 crack..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nidesoft DVD Ripper v3.0.50 crack .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nidesoft DVD Ripper v3.0.50 crack .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nik Sharpener Pro Photoshop Plugin v1.0d keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nik Sharpener Pro Photoshop Plugin v1.0d keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nod32 2.51.26 + crack Windows XP.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nod32 2.51.26 + crack Windows XP.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\NOD32 3.xxx Universal Fix ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\NOD32 3.xxx Universal Fix ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\NOD32 Antivirus 3.0.55 ESP.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\NOD32 Antivirus 3.0.55 ESP.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\NOD32 AntiVirus BUSINESS EDITIONv3.0.621.(NEW FIX.FINAL).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\NOD32 AntiVirus BUSINESS EDITIONv3.0.621.(NEW FIX.FINAL).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nofeel FTP Server Enterprise v3.2.3342.0 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nofeel FTP Server Enterprise v3.2.3342.0 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nokia multimedia Converter v2.0 crack -.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nokia multimedia Converter v2.0 crack -.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nokia multimedia Converter v2.0 serial number .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nokia multimedia Converter v2.0 serial number .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norman Virus Control v5.81 R8 crack.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norman Virus Control v5.81 R8 crack.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norman Virus Control v5.81 R8 Norwegian serial by CF Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norman Virus Control v5.81 R8 Norwegian serial by CF »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norman Virus Control v5.81 R8 serial by CF Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norman Virus Control v5.81 R8 serial by CF »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton 360 Tested Working crack.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton 360 Tested Working crack.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Anti Virus 2008 for Vista RETAiL + keygenerator .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Anti Virus 2008 for Vista RETAiL + keygenerator .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton AntiVirus 2007 crack -.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton AntiVirus 2007 crack -.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton AntiVirus 2007 serial number -.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton AntiVirus 2007 serial number -.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton AntiVirus 2008 16.0.0.5 KeyGen Crack.rar.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton AntiVirus 2008 16.0.0.5 KeyGen Crack.rar.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Antivirus 2008 Full Cracked INCL KEYGEN .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Antivirus 2008 Full Cracked INCL KEYGEN .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Ghost 12 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Ghost 12 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2007 crack -.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2007 crack -.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2007 serial -.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2007 serial -.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2007 v10.2 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2007 v10.2 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2008 15.0.0.58 Cracked .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2008 15.0.0.58 Cracked .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2008 Multilingual-(ESP-ITA-ENG-FRA)+ Guide to crack.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Internet Security 2008 Multilingual-(ESP-ITA-ENG-FRA)+ Guide to crack.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Partition Magic 8Full keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Partition Magic 8Full keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Product Suite 2007 Keygen.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton Product Suite 2007 Keygen.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton.Antivirus.2008.beta.with.keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton.Antivirus.2008.beta.with.keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton.Internet.Security.2008.+crack+instruciones.to.crack.it.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Norton.Internet.Security.2008.+crack+instruciones.to.crack.it.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\NortonInternetSecurity 2008 Espanol keygenerator .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\NortonInternetSecurity 2008 Espanol keygenerator .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nullsoft WinAmp v5.32 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Nullsoft WinAmp v5.32 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Oxygen Phone Manager for Nokia Phones II 2.12.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Oxygen Phone Manager for Nokia Phones II 2.12.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Panda Antivirus 2008 CracKed.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Panda Antivirus 2008 CracKed.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Panda Antivirus Plus Firewall (2008) keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Panda Antivirus Plus Firewall (2008) keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Panda Antivirus Titanium 2007 - Crack Username Y Password.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Panda Antivirus Titanium 2007 - Crack Username Y Password.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Patch + Crack + Serial Need For Speed Carbon.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Patch + Crack + Serial Need For Speed Carbon.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Patch Need For Speed Carbon.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Patch Need For Speed Carbon.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Patch ITA + Crack + Seriale Need For Speed Carbon.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Patch ITA + Crack + Seriale Need For Speed Carbon.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Patch.all.Windows.XP.in.a.second-(and make updates!).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Patch.all.Windows.XP.in.a.second-(and make updates!).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pc Game The Sims 2 (Crack ) ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pc Game The Sims 2 (Crack ) ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pc Game The Sims 2 (Crack Ita) ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pc Game The Sims 2 (Crack Ita) ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PC Satellite TV 2007 Elite Working KeyGen.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PC Satellite TV 2007 Elite Working KeyGen.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PC Tools AntiVirus 3.6.0 (version complete).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PC Tools AntiVirus 3.6.0 (version complete).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PC Tools Internet Security 2008 Patch to 2009 Updates.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PC Tools Internet Security 2008 Patch to 2009 Updates.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PDF Creator Plus 4 + keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PDF Creator Plus 4 + keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PES2008 crack for patch 1.10 Pro Evolution Soccer 2008 7 Vitality (packed by master3k).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PES2008 crack for patch 1.10 Pro Evolution Soccer 2008 7 Vitality (packed by master3k).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PhotoSphere Professional 2.2 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PhotoSphere Professional 2.2 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pinnacle Studio Plus 10.5.1.Titanium Edition (Crack & keygenerator).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pinnacle Studio Plus 10.5.1.Titanium Edition (Crack & keygenerator).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pinnacle Studio Plus 10.5.1.Titanium Edition - ITA - (Crack & keygenerator).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pinnacle Studio Plus 10.5.1.Titanium Edition - ITA - (Crack & keygenerator).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pinnacle Studio Plus v11 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pinnacle Studio Plus v11 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pinnacle Studio Plus v11 MultiLanguage Bonus DVD Incl Keygen.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pinnacle Studio Plus v11 MultiLanguage Bonus DVD Incl Keygen.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PlayStation 2 Emulator for PC +keygenerator .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PlayStation 2 Emulator for PC +keygenerator .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pocketgrandmaster Chess v3.0 Crack 17-09-2006 Vagus Arm Ppc With Program.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Pocketgrandmaster Chess v3.0 Crack 17-09-2006 Vagus Arm Ppc With Program.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Power ISO + keygenerator 3.8. latest.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Power ISO + keygenerator 3.8. latest.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Power ISO 3.8 + Aiudos + keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Power ISO 3.8 + Aiudos + keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Power ISO 3.9 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Power ISO 3.9 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PS3 Video Converter 3.1.21.011 NEW.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\PS3 Video Converter 3.1.21.011 NEW.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Psiloc Irremote 3Rd (n80-n73-n95) Crack.zip Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Psiloc Irremote 3Rd (n80-n73-n95) Crack.zip »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Rapidshare Leecher + Rapidshare Tools.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Rapidshare Leecher + Rapidshare Tools.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\RapidShare Manager 2008.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\RapidShare Manager 2008.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Rapidshare Premium Downloader Manager ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Rapidshare Premium Downloader Manager ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Real Player 11.0.0.373 keygenerator-W0rking.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Real Player 11.0.0.373 keygenerator-W0rking.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Real Player v10 Gold Ita Crack..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Real Player v10 Gold Ita Crack..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\RealPlayer 11 Plus for XP-VISTA keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\RealPlayer 11 Plus for XP-VISTA keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Regcure Crack All Versions..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Regcure Crack All Versions..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Registry First Aid Platinum 6.1.0.15 + Key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Registry First Aid Platinum 6.1.0.15 + Key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Resident Evil 3 Nemesis[PcGame][MULTI5]keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Resident Evil 3 Nemesis[PcGame][MULTI5]keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Ripcast Streaming Audio Ripper V1.9 + keygenerator (Yaya).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Ripcast Streaming Audio Ripper V1.9 + keygenerator (Yaya).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Rosetta Stone 2007 and language pack.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Rosetta Stone 2007 and language pack.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Screen Grab Pro Deluxe 1.1 (pics of your desktop).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Screen Grab Pro Deluxe 1.1 (pics of your desktop).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\SlySoft AnyDVD & AnyDVD HD 6.3 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\SlySoft AnyDVD & AnyDVD HD 6.3 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\SlySoft AnyDVD HD 6.3.0 FINAL incl crack by Team Resurrection.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\SlySoft AnyDVD HD 6.3.0 FINAL incl crack by Team Resurrection.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Slysoft AnyDVD HD 6.3.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Slysoft AnyDVD HD 6.3.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Socket Wifi Companion v2.9.3 Crack Updated-Fixed 10-2006.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Socket Wifi Companion v2.9.3 Crack Updated-Fixed 10-2006.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\SolSuite 2008 8 (Best Card Game!)..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\SolSuite 2008 8 (Best Card Game!)..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Sony DVD Architect Studio 4.5 (Complete Disk)..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Sony DVD Architect Studio 4.5 (Complete Disk)..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Sony Vegas 8 Complete keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Sony Vegas 8 Complete keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Sony Vegas Pro 8 0a build 179 .Corporate Full..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Sony Vegas Pro 8 0a build 179 .Corporate Full..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Sophos Antivirus 6.5.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Sophos Antivirus 6.5.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Spyware Doctor 5.1.0.2.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Spyware Doctor 5.1.0.2.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\spyware doctor CRACK 4.0.0.261 SERIAL.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\spyware doctor CRACK 4.0.0.261 SERIAL.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Spyware.Doctor.v5.0.0.169.Multilangages.Incl-Crack ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Spyware.Doctor.v5.0.0.169.Multilangages.Incl-Crack ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Steinberg Cubase SX3 + update 3.1.1.944 + dongle crack [H2O] ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Steinberg Cubase SX3 + update 3.1.1.944 + dongle crack [H2O] ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Super Internet TV 7 2007 Patched..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Super Internet TV 7 2007 Patched..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Super Todo En Uno V3 [DVD9][Spanish]..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Super Todo En Uno V3 [DVD9][Spanish]..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Surfoffline 1.4 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Surfoffline 1.4 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Symantec AntiVirus Corporate Edition 1.0.3-8 for Server..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Symantec AntiVirus Corporate Edition 1.0.3-8 for Server..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\System Mechanic 7.5 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\System Mechanic 7.5 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\System Mechanic Professional 7.5.5 Full.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\System Mechanic Professional 7.5.5 Full.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TechSmith Camtasia Studio 5 [Record your own videos]-Cracked.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TechSmith Camtasia Studio 5 [Record your own videos]-Cracked.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TEU Essentials 2007 ,.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TEU Essentials 2007 ,.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\The Elder Scrolls Iv Oblivion Crack (Test Ok)..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\The Elder Scrolls Iv Oblivion Crack (Test Ok)..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\The Shield Antivirus 2007 Pro & Firewall.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\The Shield Antivirus 2007 Pro & Firewall.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\The.witcher.Crack.Only ..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\The.witcher.Crack.Only ..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Tomtom Go key Mappe.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Tomtom Go key Mappe.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TomTom.Navigator.6.Europa.DVD.6.01 + CRACK.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TomTom.Navigator.6.Europa.DVD.6.01 + CRACK.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Total Commander 7 for XP-VISTA..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Total Commander 7 for XP-VISTA..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Trend Micro Anti-Spyware 3.5.0.10 (crackeado).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Trend Micro Anti-Spyware 3.5.0.10 (crackeado).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Trend Micro PC-Cillin Internet Security Pro 2008 16.05.10+ License keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Trend Micro PC-Cillin Internet Security Pro 2008 16.05.10+ License keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TuneUp Utilities 2007 6.0.2312 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TuneUp Utilities 2007 6.0.2312 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TuneUp Utilities 2008 7 working Key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\TuneUp Utilities 2008 7 working Key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Tunnel Client v2.7.1853 Setup And Crack - Hipbob.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Tunnel Client v2.7.1853 Setup And Crack - Hipbob.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Turning.Point.Fall.Of.Liberty.PROPER.Crack.Only-FL.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Turning.Point.Fall.Of.Liberty.PROPER.Crack.Only-FL.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Typing Master Pro 2005 6.30 (Multilanguage)(Typingmaster) Crack Lic.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Typing Master Pro 2005 6.30 (Multilanguage)(Typingmaster) Crack Lic.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\ULEAD DVD MOVIE FACTORY V4.0 + key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\ULEAD DVD MOVIE FACTORY V4.0 + key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\USB Safely Remove 3.3.0.6.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\USB Safely Remove 3.3.0.6.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Video Fixer 3.2 .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Video Fixer 3.2 .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Virtual Skipper 5 Crack.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Virtual Skipper 5 Crack.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Vista Codec Package 4.5(Audio and Video Codec).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Vista Codec Package 4.5(Audio and Video Codec).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\VLC Media Player 0.8.6d . (Latest Version.). Legal-Ups.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\VLC Media Player 0.8.6d . (Latest Version.). Legal-Ups.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WGA.Validate.2008.for.Windows.XP.Home+Professional.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WGA.Validate.2008.for.Windows.XP.Home+Professional.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Winamp 5.5. Pro incluido plugins-advanced system.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Winamp 5.5. Pro incluido plugins-advanced system.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Winamp Pro v5.6 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Winamp Pro v5.6 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinAVI Video Converter 8.0 keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinAVI Video Converter 8.0 keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinAVI Video Converter 9.0+keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinAVI Video Converter 9.0+keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows 98 Second Edition Full Bootable CD + CD Key.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows 98 Second Edition Full Bootable CD + CD Key.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows UE V.9.5 Fina [App][MULTI5].rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows UE V.9.5 Fina [App][MULTI5].rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Update Genuine Advantage Validation Patch Crack Xp(1)..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Update Genuine Advantage Validation Patch Crack Xp(1)..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Vista Ultimate 32bit keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Vista Ultimate 32bit keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Vista Ultimate 32bit.Full..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Vista Ultimate 32bit.Full..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Vista x86 MultiLang.AutoPatcher..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Vista x86 MultiLang.AutoPatcher..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Vista x86 Ultimate Genuine OEM keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Vista x86 Ultimate Genuine OEM keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Xp Pro Sp3 3264 Vista Style .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows Xp Pro Sp3 3264 Vista Style .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows XP Professional Genuine Crack marzo 2008.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows XP Professional Genuine Crack marzo 2008.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows XP Professional Service Pack 2 .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows XP Professional Service Pack 2 .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows XP Professional Student SP3-Integrated + CD Key .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Windows XP Professional Student SP3-Integrated + CD Key .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinRar 3.7 Crack..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinRar 3.7 Crack..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinRAR 3.7 Extreme cracked.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinRAR 3.7 Extreme cracked.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinRAR 3.71.1.0 Multilingual for XP and VISTA + keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinRAR 3.71.1.0 Multilingual for XP and VISTA + keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinZip 11 Crack-keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinZip 11 Crack-keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinZip 11.2 professional patched..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinZip 11.2 professional patched..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinZIP 12 (co el key funcionante).rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WinZIP 12 (co el key funcionante).rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WirelessMon 2.1 keygenerator .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WirelessMon 2.1 keygenerator .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WS FTP Server with SSH 6..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\WS FTP Server with SSH 6..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Xilisoft iPod to PC Copy 1.0.54.11.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Xilisoft iPod to PC Copy 1.0.54.11.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Yamicsoft Vista Manager 1.1.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Yamicsoft Vista Manager 1.1.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Your Uninstaller 2006 Pro 5.0.0.23 crack.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Your Uninstaller 2006 Pro 5.0.0.23 crack.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\ZoneAlarm Anti-Spyware + Firewall 7.0.46 Retail-ReLEASD.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\ZoneAlarm Anti-Spyware + Firewall 7.0.46 Retail-ReLEASD.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\ZoneAlarm Anti-Spyware and Antivirus 7.0.462 + working Key .rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\ZoneAlarm Anti-Spyware and Antivirus 7.0.462 + working Key .rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Zuma Deluxe Luxor Amun Rising Atlantis Crack.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\Zuma Deluxe Luxor Amun Rising Atlantis Crack.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[App - Cad] - Autocad 2004 ITA + keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[App - Cad] - Autocad 2004 ITA + keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[CRACK ITA] Football Manager 2008.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[CRACK ITA] Football Manager 2008.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[CRACK] - FINSON keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[CRACK] - FINSON keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[CRACK]_Windows_XP_SP2_Wpa_Kill 2.0.0.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[CRACK]_Windows_XP_SP2_Wpa_Kill 2.0.0.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[ITA] Avast! Antivirus 4.6.691 Professional Edition + keygenerator.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[ITA] Avast! Antivirus 4.6.691 Professional Edition + keygenerator.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[PC GAME ITA] Runaway 2 ita crack.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[PC GAME ITA] Runaway 2 ita crack.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[PC] - GTA 3 San Andreas keygenerator.rar.rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[PC] - GTA 3 San Andreas keygenerator.rar.rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[Software-Ita] Adobe CS3 Creative suite design Premium (Include Crack)..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[Software-Ita] Adobe CS3 Creative suite design Premium (Include Crack)..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[Software] Adobe CS3 Creative suite design Premium (Include Crack)..rar Win32/Archivarius.B worm (deleted) 00000000000000000000000000000000
C:\Documents and Settings\owner.LONEWOLF\Application Data\Shareaza\Collections\[Software] Adobe CS3 Creative suite design Premium (Include Crack)..rar »CAB »Setup+Patch.exe Win32/Archivarius.B worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Program Files\Google\Google Talk\uninstall.exe Win32/Adware.BHO.AV application (unable to clean - deleted) 00000000000000000000000000000000
C:\Program Files\Google\Google Talk\googletalk-1.0.0.104\googletalk-setup-upgrade.exe Win32/Adware.BHO.AV application (unable to clean - deleted) 00000000000000000000000000000000




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users