Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis Log: Please Help Diagnose


  • This topic is locked This topic is locked
69 replies to this topic

#1 Yippa

Yippa

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 16 February 2006 - 06:10 PM

Looking for some help. Have used Adaware & Xoftspy and removed everything but this Randomly Named Trojan. Also used the Add/remove feature to remove surf side kick 3

Logfile of HijackThis v1.99.1
Scan saved at 5:56:05 PM, on 2/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\TWFyayBZcHNpbGFudGlz\command.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Network Monitor\netmon.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\outlook\outlook.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\windows\winsysban9.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Common Files\VCClient\VCMain.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\MARKYP~1\LOCALS~1\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar2.dll
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd9.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\pciaiy.exe reg_run
O4 - HKLM\..\Run: [susse] "C:\WINDOWS\system32\hpsw.exe"
O4 - HKLM\..\Run: [winsysban] C:\windows\winsysban9.exe
O4 - HKLM\..\Run: [gimmygames] C:\windows\gimmygames9.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
O4 - HKCU\..\Run: [qmqm] C:\PROGRA~1\COMMON~1\qmqm\qmqmm.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\windows\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\windows\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {5512A947-7BF6-487F-9AE9-EAF9AA0A24B7} (Corex.SignatureCardMaker) - https://www.cardscan.net/cabs/signatureCardMaker.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15010/CTPID.cab
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\n6n6lg5s16.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWFyayBZcHNpbGFudGlz\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

BC AdBot (Login to Remove)

 


#2 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 16 February 2006 - 06:39 PM

Anybody out there?...I'm getting battered with adware and an occasional Norton notification about a trojan infection that has been either deleted quaritined or unfixable

#3 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:12:01 PM

Posted 17 February 2006 - 04:29 AM

Hi There! :thumbsup:

I am currently working on your log

I will get back to you as soon as possible.

David :flowers:

#4 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 17 February 2006 - 08:11 AM

Thanks David - really appreciate it!

I did get into some of the tutorials last night to see if I could clean up some of the obvious Registry anomalies. I've attached an updated HijackThis log to show what I have removed. I did not go into safe mode yet to remove file(s); was waiting for someone to give me direction on that. I'm not a novice when it comes to understanding this but by no means am I anywhere near an expert. Again thanks for your help! By the way I have run Adaware & Xsoftspy after I did the fixes and I'm still getting popups. A side note; my crtl+alt+del does not give me my process running screen anymore.


Logfile of HijackThis v1.99.1
Scan saved at 8:04:55 AM, on 2/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar2.dll
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd9.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\pciaiy.exe reg_run
O4 - HKLM\..\Run: [susse] "C:\WINDOWS\system32\hpsw.exe"
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [qmqm] C:\PROGRA~1\COMMON~1\qmqm\qmqmm.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\windows\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\windows\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {5512A947-7BF6-487F-9AE9-EAF9AA0A24B7} (Corex.SignatureCardMaker) - https://www.cardscan.net/cabs/signatureCardMaker.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15010/CTPID.cab
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\fpl0033me.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#5 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:12:01 PM

Posted 17 February 2006 - 08:14 AM

Ok, i'm just waiting on a teacher to approve my fix - i'll be back as soon as i can.
David

#6 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:12:01 PM

Posted 17 February 2006 - 08:31 AM

Hi Yippa and welcome to BleepingComputer.

You have quite a badly infected system with a number of infections. It is a good idea to print off these instructions - they will be needed later when internet access is not available. You may also like to save these instructions in word/notepad to the desktop where they can be easily found for the same reasons as above.
It is important that you complete the following instructions in the correct order, and also that you don't miss anything out! :thumbsup:
_____________________________

Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck.
  • Install background guard
  • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
    ewido manual updates
_____________________________

Please download ATF Cleaner by Atribune and save it to your desktop. Do not run it yet.
_____________________________

*Boot into Safe Mode (without networking support!)
By pressing the F8 key right when Windows starts, usually right after you hear your computer
beep when you reboot it (some versions of windows will display 'Starting Windows' with a grey progress bar)
you will be brought to a menu where you can choose to boot into safe mode.
_____________________________

Once the you are in safe mode run Ewido and complete the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido security suite.
_____________________________Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.]
_____________________________

Reboot back to normal mode.

Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task.
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button.
  • You will receive a Done Scanning message, click OK.
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your Firewall about this program accessing the Internet, please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
_____________________________

Please post back with the following logs:
  • The Ewido Report
  • A new HijackThis log
  • The C:\Look2Me-Destroyer.txt
David

#7 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 17 February 2006 - 10:54 AM

Hi David - I'm in the middles of the ewido scan and after the scan completed I'm getting this warning "C:\Documents and Settings\"my name"\Complete\"file name"\"name.exe" cannot be removed because it is embedded in the archive "C:\Documents and Settings\"my name"\Complete\"file name"\"name.exe". Dou you want to remove archive?

I'm getting this for a lot of files - and I'm still going. I've decided to delete most that I feel are not supposed to be there.

Please advise

#8 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 17 February 2006 - 01:55 PM

Hi David - you'll see that I have not posted the ewido log. I initially posted then realized my full name was posted and was uncomfortable with that. I have listed below in subsequent posts the hijack log & look2me txt. It apprears I do not have anymore popups for now.

Look forward to your response.

Edited by Yippa, 17 February 2006 - 02:14 PM.


#9 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 17 February 2006 - 02:05 PM

hh

Edited by Yippa, 17 February 2006 - 02:11 PM.


#10 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 17 February 2006 - 02:08 PM

hh

Edited by Yippa, 17 February 2006 - 02:11 PM.


#11 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 17 February 2006 - 02:10 PM

here is the hijack log

Logfile of HijackThis v1.99.1
Scan saved at 1:44:28 PM, on 2/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Ewido\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis\HijackThis.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar2.dll
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd9.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\pciaiy.exe reg_run
O4 - HKLM\..\Run: [susse] "C:\WINDOWS\system32\hpsw.exe"
O4 - HKLM\..\Run: [gimmygames] C:\windows\gimmygames9.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [qmqm] C:\PROGRA~1\COMMON~1\qmqm\qmqmm.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\windows\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\windows\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {5512A947-7BF6-487F-9AE9-EAF9AA0A24B7} (Corex.SignatureCardMaker) - https://www.cardscan.net/cabs/signatureCardMaker.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15010/CTPID.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Ewido\ewido anti-malware\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#12 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 17 February 2006 - 02:15 PM

Here's Look2Me destoryer txt.



Look2Me-Destroyer V1.0.5

Scanning for infected files.....
Scan started at 2/17/2006 1:28:34 PM

Infected! C:\WINDOWS\system32\fprq0395e.dll
Infected! C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP75\A0002647.dll
Infected! C:\WINDOWS\SYSTEM32\en86l1ls1.dll
Infected! C:\WINDOWS\SYSTEM32\fprq0395e.dll

Attempting to delete infected files...

Attempting to delete: C:\WINDOWS\system32\fprq0395e.dll
C:\WINDOWS\system32\fprq0395e.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP75\A0002647.dll
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP75\A0002647.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\en86l1ls1.dll
C:\WINDOWS\SYSTEM32\en86l1ls1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\fprq0395e.dll
C:\WINDOWS\SYSTEM32\fprq0395e.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Hints

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{05A6621B-8093-4FC0-AF54-E5DE44FD1E2F}"
HKCR\Clsid\{05A6621B-8093-4FC0-AF54-E5DE44FD1E2F}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{57CDC669-766B-46E6-870C-EFACE37DD443}"
HKCR\Clsid\{57CDC669-766B-46E6-870C-EFACE37DD443}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

#13 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:12:01 PM

Posted 18 February 2006 - 12:09 PM

Hi Yippa.

We've decided that we really do need to see the Ewido log in order to help you. If you are still not comfortable you will have to edit out your name in the log. Otherwise, we can't move on....

Sorry to be a pain but I really need to see it.
David

#14 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 18 February 2006 - 01:58 PM

I'm editing it as we speak

#15 Yippa

Yippa
  • Topic Starter

  • Members
  • 46 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 18 February 2006 - 02:06 PM

Here's the first part of the Ewido log (wow!, I had a lot of crap on this system!!). Can't seem to put in the max character limit so I'll be sending several more replies...sorry. By the way the computer appears to be running fine, no more popups...have done several Norton, Xoftspy and adaware scans with no problems identified....thanks again for all your help...I will be contributing to this great site.

ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 11:33:51 AM, 2/17/2006
+ Report-Checksum: 2AF2A3D5

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{39C78B50-7E98-4aa0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\FENX -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-3870953118-1158794349-95726358-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
[728] C:\WINDOWS\system32\KXDBR.DLL -> Adware.Look2Me : Error during cleaning
[840] C:\WINDOWS\system32\KXDBR.DLL -> Adware.Look2Me : Error during cleaning
C:\cygwid.exe -> Downloader.Small.bmx : Cleaned with backup
C:\Documents and Settings\"wife's name"\Cookies\"wife's name"@ads.x10[1].txt -> TrackingCookie.X10 : Cleaned with backup
C:\Documents and Settings\"wife's name"\Cookies\"wife's name"@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\"wife's name"\Cookies\"wife's name"@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\"wife's name"\Cookies\"wife's name"@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\"wife's name"\Cookies\"wife's name"@specificpop[1].txt -> TrackingCookie.Specificpop : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\¥¥¥ Fantasy Art - Louis Royo - Boris Vallejo - Julie Bell - Larry Elmore.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\02 10 06 A Chinese Tall Story 2005 情癲大聖-VCD.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\1998 bleeping Crazy.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 24 Season 1 Complete Divx Rkl.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e07 1pm 2pm Videoseed Com Ipod.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e07 Hdtv Ipod Format.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e07 Hdtv Xvid Lol Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e07 Hdtv Xvid Lol.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e07 Hdtv Xvid Xor Tensiontorrent Com Rar.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e07 Hr Hdtv Ac3 5 1 Xvid Dimension Eztv Rar.zip/Setup.exe -> Worm.VB.dw : Error during cleaning
C:\Documents and Settings\"my name"\Complete\24 S05e07 Hr Hdtv Ac3 5 1 Xvid Nbs Eztv Rar.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e08 Hdtv Xvid Lol Eztv.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e08 Hdtv Xvid Lol.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 S05e08 Hdtv Xvid Xor Tensiontorrent Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 Season04 Complete.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\24 The Game PAL Multi 9 Ita Spa Fra Eng Deu Ces Mag Pol Ned rar.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\32 Jimi Hendrix Albums (mp3,wav) (140kbps).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\A collection of Gamehouse Games for Windows incl Keygen.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\AA2K6GE Linux.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\About CNET Networks.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ACDSee V8.0.41 Mult-Lang[DEU,ENG,ITA] + Patch.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Adobe Photoshop CS2 incl KeyGen.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Advanced search.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ahq Dragon Ball Gt Complete.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Air America Radio - The Al Franken Show 021606 [mp3].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Air America Radio - The Mark Riley Show 021606 [mp3].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Air America Radio - The Mike Malloy Show 021506 [mp3].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Air America Radio - The Rachel Maddow Show 021606 [mp3].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Alien Arena 2006 Gold Edition.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\All Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\American Idol S05e10 Hdtv Xvid Xor Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Andrzej Mleczko - Najlepsze Rysunki [PL] [PDF].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\animation and 3D text AIO.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Anime Fin Ranma.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Animeu Shuffle 24 E8615431 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Arctic Monkeys-Whatever People Say I Am Thats What Im Not-CD-2006-LOSSLESS-QiE.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Atc Excel Saga Dual Audio.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Aura - Indywidualnie (2005) (mp3@160-256kbps).zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ayashi No Ceres Eng Subbed.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Béla Fleck and The Flecktones.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Backers Get Get 1 49 Eng Sub.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Battlefield 2 Dvd.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Battlestar Galactica S02e15 Ws Dsr Xvid Loki.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Big Mommas House 2 XViD TS-maVen-RmvBusterS.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Billy Squier-16 Strokes-(Retail)-1995-HHI.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Bingo-Jenna G-BINGOJG003R-2006-sour.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Binio Bill - 9 Komiksów [PL] [JPG].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Biquini Cavadão ao vivo[DVD-R][DVD Seeders].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Black And White 2 Clone.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Bleach Episode 67.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Bleach Society Bleach 65 Xvid 6c45a70b Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Bleach Society Bleach 67 Xvid C23d0d6c Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Bold and the beautiful - Bold and the beautiful Feb 16th 2006 avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Bones 1x13 Hdtv Xor Vtv.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Bones S01e13 Hdtv Xvid Xor Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Breakbeat Kaos-Pendulum-BBK016-Promo-Vinyl-2006-XTC.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Brokeback Mountain 2005 Dvdscr Kvcd Hockney Tus Release.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Browse categories.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Brunet Wieczorowa Pora (1976) [PL] [1CD] [DVDRip] [DivX].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Burnout Grenoble Wmv.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Call Of Duty 2 Dvd S Iso.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Call Of Duty 2 Multi Lang Dvd.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Call Of Duty 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Capture Wiz Pro - Corp Edition.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Chicken Little[2005]DvDrip AC3[Spanish-Latino].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Chocolate City - We Are Here To Stay.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Chuck Mangione - Children Of Sanchez [FLAC lossless].zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\CloneDVD v2.8.8.2 and Patch.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\CNET .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\CNET Channel.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\CNET Download.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\CNET News.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\CNET Reviews.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\CNET Shopper.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ColumboSeason3Episode05DVDripx264fullres1340122 Demonoid com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Command And Conquer The First Decade Read Nfo Clonedvd Mirror.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Command And Conquer The First Decade Www Limitedivx Com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Command Conquer Generals And Generals Zero H.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Computer Shopper.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Criminal - Victimized.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Curso de Redes CISCO BR by RCaldas.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\CyberLink PowerDVD XP 4.0 incl Serial.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Dalbello - Whomanfoursays.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Dave Emory - Crisis in Bosnia - FTR.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Bleach 64 9365aa69 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Bleach 65 F7a19c22 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Bleach 66 27163aea Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Bleach 68 69 3e34a169 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Naruto 168 93cde458 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Naruto 169 94a7d0a1 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Naruto 170 3766277f Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Naruto 171 F324d446 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Naruto 172 3cfa50fb Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Db Naruto 172 Sub French C8b83119 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Desperate Housewives Desperate Housewives S02e14 Hdtv Xvid Lol.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Desperate Housewives S02e11 Hdtv Xvid Xor Vtv Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Desperate Housewives S02e13 Hdtv Xvid Xor.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Desperate Housewives S02e14 Hdtv Xvid Lol.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Desperate Housewives Season01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\DJ Kentaro - On the Wheels of Solid Steel.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Doremi Otome Mai Otome 16 16161616 Avi.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Dragon Ball Complete 27gb.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Dragonball Z All Episodes Eng.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Dragonball Z Complete 38gb Wow.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Dragonball Z.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\DVDCopy Platinum V4.0 incl keymaker.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Early Entries #5 - Starring Tiffany Taylor, Teen bleeping.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyVersionControl 7.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyView X 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyViewOrcl 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyWallpaper 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyWare B2B Commerce 4.004.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyWare Shopping Cart 3.004.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyWatch 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyWebSave 1.2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyWMA 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EasyWMA Converter 1.22a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eat My Dust demo, large version .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eat My Dust demo, medium version .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eat My Dust demo, small version .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eatometer 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eAuction Watcher 2.3.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EAuthentix Outlook Plug-in 1.2.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eaz-Fix Professional 7.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eazi Website Monitor 1.0.2.196.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EaZip 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eazy Backup 2.0.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EazyBox for Palm 1.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EazyCode 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EazyDraw 1.8.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EazySQL 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBaitor 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EBAS 1.0.0.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBaum's World Funbar 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebay and Paypal Fee Calculator 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBay Auction Sniper and Auto Search 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebay Bargin Hunter 2.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBay Companion 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBay Fee Calculator 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebay Item Watcher 1.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBay Keyword Secrets 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBay Master Class 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebay Powerseller Articles 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBay Toolbar 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebay Tycoon--Play the Ebay.com Online MarketPlace Game 1.25.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebay Typo Auction Locator 3.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EbayMinder 5.0.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBC SIMON 1.1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebced 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EBgo Sniper 1.3.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EBgo Windows CD Key Extractor 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBible 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBible 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBlocs Security Toolbar 7.09.27.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EboBar 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBook 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBook Blaster 1.0.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBook Constructor 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBook Ideas 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EBook Maestro FREE 1.35.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EBook Maestro PRO 1.35.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBook Pack Express 1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBook Reader for Nokia 9500 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ebookers Desktop Travel Calendar 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBookGuard 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EbookMaker 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBookShelf 1.5.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBooksReader 2005.15.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBooksWriter Lite 2004.14.176.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eBot Free 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EBP Business Plan Designer 3.0.12.23.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ebrary Reader .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebstra Imperial 2BI.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ebstra-1 2BM.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eCafePro Server Platinum 3.62.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecamm Austin Powers Video Phone Sound .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecamm Babylon 5 Doorbell .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecamm Hitchhiker's Guide Beep .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecamm LongBell .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecamm Power Rangers Watch Sound .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecamm R2D2 Droid Chirp .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecamm R2D2 Droid Computing Sound .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecard Magic 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eCatalogDX 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eccentris Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EcGraph 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eChanblardNext 9.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echelon demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echelon Instant Action patch (non-Pentium, non-AMD) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echelon P11K6 processor patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echelon Wind Warriors demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echelon Wind Warriors E3 trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echelon Wind Warriors Instant Action patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echelon Wind Warriors v1.10 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echive Lease Planner 2.1.57.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Echo Password Manager 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EchoForum InvisionBoard LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EchoForum PhpBB LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EchoForum Simple Machines LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EchoForum UBB LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EchoForum vBulletin LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EchoForum XMB LACI 1.39.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EchoServer for Windows 1.41.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EchoVNC 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eclarsys PopGrabber 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EClean 1.4.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eCleaner 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eClick 1.2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eClickz Toolbar 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eclipse Service Management Software 4.16.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EclipseCrossword 1.2.54.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eCluster NT 3.6.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EcoEuroMillions 1.23.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EcoKeno 3.71.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EcoLotofoot 3.63.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecolotosystemes 4.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eComm Store 2.08.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Econ NetVert 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Economic Investment Amount 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Economics Terms Dictionary 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EconomiZation 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eContent Editor 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EControl Syntax Editor 2.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecosuper7 1.16.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EcoThunderball 1.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecotonoha Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eCover 1.0.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eCover 3D 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eCover Constructor 1.0 b18.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecstatica II demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ECTACO English - Japanese Talking Dictionary 2.5.81.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ECTACO English - Spanish Talking Dictionary 3.0.58.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ECTACO FlashCards English - German 1.1.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ECTACO FlashCards English - German 1.1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ECTACO FlashCards English - Spanish 1.1.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ECTI 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecto 1.7.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecto 2.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EctoSet Modeller 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ecyware GreenBlue Inspector 1.1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ED for Windows 4.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ed Michael Reggie Series - Time Value of Money 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDA 01.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eData Unerase Personal 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EdataSOS 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EdenGUI 2.0.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EdenSoft My Logo 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edgar Allan Poe e-Book Introduction 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edge 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDGE Diagrammer 5.03 build 1810.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edge Of Chaos 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edge2004 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EdgeDesk 4.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edges 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edgeworks 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edgeworks 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDictionary English-Russian 4.0.19.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDictionary Reader 4.0 build 40279.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDIdEv SEF Reader 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edit Buddy 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edit Digi Pictures 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edit JFIF Comment 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edit Prep 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Editable Photo Album (crocodile leather cover) 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Editable Photo Album (Crocodile Leather Frame) 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Editable Photo Album (Ostrich Leather Cover) 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Editable Victoria Photo Album 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditCNC 3.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditEx 2006.0.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edith 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditiX 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditLive for Java 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditLive for XML 2.0.zip/Setup.exe -> Worm.VB.dw : Error during cleaning
C:\Documents and Settings\"my name"\Complete\EditML Pro 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditOnline 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Editor2 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditPad Lite 5.4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditPad Pro 5.4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditPlus 2.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Editplus For .NET 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EditPro 1.57.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Editstudio 5.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ediware Client 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDL AutoSave 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edmund Spenser, Amoretti & Epithalamion 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDoc 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDoc Studio 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDocEngine ActiveX.NET 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDocEngine VCL 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDocOne 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDocPlus 3.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDocPrinter PDF Pro 6.16.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDocPrinter PDF Pro Danish 6.09.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDonkey Acceleration Patch 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDonkey Accelerator 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDonkey Manager 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDonkey2000 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edovia Antispam 2005.4.0.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edovia PopShield AntiPopup 1.0.0.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EdPAD 1.1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDraw Flowchart ActiveX Control 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDraw Flowchart Software 1.6.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDrawings 2005 5.1.1.232.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDrill Math Flashcard 3.26.2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EDrill's SpellingBee Flashcard 2.20.2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDrum MIDI Mapper 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Educational Compiler ComPas 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Educational eBooks for Children 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Educational Worksheets - Math (Windows XP) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EducLearning 4.2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eduinfo InstaM 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EduProfix 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Edushield 1.0.62.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDVD 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EdWin 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eDX Edit Control for .Net 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EEBond 26.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eek Adder for Myspace 3.6.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eek Band Promoter 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EePoker - Free Draw Poker Game 1.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eeppo 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eetee 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Efastar Supply Master 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eFAXy 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Effect3D 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Effect3D Studio 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Effective File Search 3.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Effective Meetings 1.5.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Effective Site Studio 20043.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Effective Site Studio Photo Edition 20042.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Effects 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Effects Pack (PowerPC) 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EffeTech HTTP Sniffer 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EffiValidation 3.0 lite.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EFGrabber 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eFileGo 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eFlowPDF Free Edition 1.0.610.60.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eFlowPDF Professional Edition 1.0.583.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EFM--CAD and Image File Manager 2.5.1.zip/Setup.exe -> Worm.VB.dw : Error during cleaning
C:\Documents and Settings\"my name"\Complete\EFormMaster 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eForPurchase UAsked4It 1.0.zip/Setup.exe -> Worm.VB.dw : Error during cleaning
C:\Documents and Settings\"my name"\Complete\eFox 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EFR (Extended Find and Replace) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EfreeBuy Folder Icon 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EfreeSoft Boss Key 3.30.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EFS Key 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EFS Standard 5.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EFT123 2.0.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EgaImages Screensaver 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eGames Pinball 1.0.zip/Setup.exe -> Worm.VB.dw : Error during cleaning
C:\Documents and Settings\"my name"\Complete\EGems Collector Pro 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eGenie 0.4.16.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Egg 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Egg Timer Plus 2.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Egg vs. Chicken 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Egg-stravaganza 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eggberts Easter Wish 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eggblog 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EggKey Gateway 1.0.66.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EggOn 0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EggRoll 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EggStatic 1.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EgoLex 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eGrader 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Egypt Dings 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Egyptian Art Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EHusBook 2.34.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eiffel API for NeoCore XMS 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EightBall 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Eikona 3D 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eIMAGE Recovery 3.3.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Einstein 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Einstein 1.54.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Einstein Information Management System 4.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Einstein Quote Generator 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Einstime 4.1a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EIOBoard 1.8.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eIT Guard 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ejector 0.7.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EjGSoftwareWeather 1.0.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eJournal 1.0.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\EJournal 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eJukebox 3.995.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Ekkeko 1.2.160.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\El Airplane .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\El Scripto 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\El-ixir 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\eLading Bill of Lading Software 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Elasto Mania - Elastomaniac.com level pack 1 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Elasto Mania - Elastomaniac.com level pack 2 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\Elasto Mania 1.11a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ELCAD 7.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\"my name"\Complete\ELChart ActiveX DLL 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users