Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infeceted With Winantivirus/winantiviruspro/adultfriendfinder/privatephone/drivecleaner/vipringtones Malware


  • Please log in to reply
8 replies to this topic

#1 nhdon

nhdon

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:45 PM

Posted 01 July 2006 - 10:40 PM

Hi, I'm getting a large number of popups that are the result of a winativirus bug that I have picked up. In a number of different incarnations, I'm told that my computer may be running slow and I should download(insert whatever product here), I close the window and another full screen popup occurs, close that and a download window opens up. It seems like a vundo problem that i ahve previously fixed using VundoFix, but it didn't work this time. I've used adware, spybot, etc. on my own and I have just followed all of you instructions, the only thing I didn't do was post a HJT log, but the problem still exists, so I followed the steps again, only this time I'll paste my HJT log below.

I also receive this message when I use spybot:
Error during check!
Mailbot(DateIC:\windows\win.INI Kahn Nicht Ge÷ffnet Werden. The process cannot access the file because it is being used by another process)
Also, when I run Bitdefender, this file can't be deleted:
C:\ProgramFiles\yeus\xuqpzko.exe


Any help with this would be greatly appreciated.

Thanks

I have a question about the HJT. I followed the download instructions, saved it to desktop, unzipped, but when I click on the icon, it doesn't open, it just asks me to unzip again. The only way I could run it, was to go searching for the HJT file, just wondering why it doesn't open from it's desktop location.

HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 9:25:42 PM, on 7/1/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\TSI32\tsircusr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\System32\VTtrayp.exe
C:\WINDOWS\shicoxp.exe
C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\Yeus\Xuqpzko.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\LapLink\Scheduler\LLSCHENG.EXE
C:\Program Files\Lexmark 7100 Series\lxbxmon.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Lexmark 7100 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\NovaStor\NovaBackup\7\NSENGINE.exe
C:\Program Files\M4800\PVRemote.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\TSIRCSRV.EXE
C:\WINDOWS\System32\lxbxcoms.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neopets.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://home.netscape.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\TSI32\tsircusr.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [shicoxp] C:\WINDOWS\shicoxp.exe
O4 - HKLM\..\Run: [Ulead Photo Express Calendar Checker] C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\calcheck.exe
O4 - HKLM\..\Run: [LapLink Scheduler] "C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE"
O4 - HKLM\..\Run: [AtariBanner] "C:\Program Files\Infogrames\Atari Anniversary Edition\Volume 2\Banner.exe" /0
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [PowerS] C:\WINDOWSPowerS.exe
O4 - HKLM\..\Run: [WinDVR SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [Bjwzwt] C:\Program Files\Yeus\Xuqpzko.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "C:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Remote.lnk = C:\Program Files\M4800\PVRemote.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us/ht...ALStreaming.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1143711123921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbxcoms.exe
O23 - Service: NsEngine - Unknown owner - C:\Program Files\NovaStor\NovaBackup\7\NSENGINE.exe
O23 - Service: Phoenix VCD Service (PhnxVCDService) - Phoenix Technologies Ltd. - C:\WINDOWS\System32\PhnxCDSvr.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TSI Remote Control Service (TSIRCSRV) - LapLink, Inc. - C:\WINDOWS\System32\TSIRCSRV.EXE

BC AdBot (Login to Remove)

 


#2 didom

didom

  • Members
  • 1,389 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:45 PM

Posted 02 July 2006 - 10:06 AM

Hi,

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: Posted Image
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    Posted Image
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously, along with a fresh HijackThis log, in your next reply.

Edited by didom, 02 July 2006 - 10:06 AM.


#3 nhdon

nhdon
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:45 PM

Posted 02 July 2006 - 05:20 PM

Hi,

Thanks for the starting point. I ran drweb-cureit, it found a bunch of stuff, then I followed your directions and then rebooted. After reboot, as soon as I launched an IE window, I got a a popup. Here is my drweb-cureit log(boy it's long), followed by my latest HJT.

drweb-cureit log

Xuqpzko.exe;C:\Program Files\Yeus;Trojan.DownLoader.1389;Deleted.;
dfrddd.dll;C:\WINDOWS\system32;Adware.Duncan;Incurable.Will be moved after reboot.;
jkkli.dll;C:\WINDOWS\System32;Trojan.Virtumod;Will be cured after reboot.;
jkkli.dll;C:\WINDOWS\system32;Trojan.Virtumod;Will be cured after reboot.Deleted.;
jkkjk.dll;C:\WINDOWS\system32;Trojan.Virtumod;Deleted.;
ddccy.exe;C:\WINDOWS\system32;Probably BINARYRES;Incurable.Moved.;
dfrddd.dll;C:\WINDOWS\system32;Adware.Duncan;Incurable.Will be moved after reboot.;
ProxyStub.dll;C:\Documents and Settings\us\Local Settings\Temp\temp.fr60E8;Adware.Apropos;Incurable.Moved.;
proxystub.dll;C:\Documents and Settings\us\Local Settings\Temp\temp.fr60E8\pstub0;Adware.Apropos;Incurable.Moved.;
proxystub.dll;C:\Documents and Settings\us\Local Settings\Temp\temp.frE15E\pstub0;Adware.Apropos;Incurable.Moved.;
ProxyStub.dll;C:\Documents and Settings\us\Local Settings\Temp\temp.fr7FEC;Adware.Apropos;Incurable.Moved.;
WinGenerics.dll;C:\Documents and Settings\us\Local Settings\Temp\temp.fr7FEC;Adware.Apropos;Incurable.Moved.;
proxystub.dll;C:\Documents and Settings\us\Local Settings\Temp\temp.fr4FAD\pstub0;Win32.Porad;Incurable.Moved.;
new[1].htm\javascript.0;C:\Documents and Settings\us\Local Settings\Temporary Internet Files\Content.IE5\WBLXYTV9\new[1].htm;Trojan.DownLoader.7201;;
new[1].htm;C:\Documents and Settings\us\Local Settings\Temporary Internet Files\Content.IE5\WBLXYTV9;Archive contains infected objects;Moved.;
proxystub.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1].htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1].htm;Trojan.DownLoader.7201;;
new[1].htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_0.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_0.htm;Trojan.DownLoader.7201;;
new[1]_0.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu1.dll;C:\Documents and Settings\us\DoctorWeb\Quarantine;Win32.Porad;Incurable.Moved.;
new[1]_1.htm\javascript.0;C:\Documents and Settings\us\DoctorWeb\Quarantine\new[1]_1.htm;Trojan.DownLoader.7201;;
new[1]_1.htm;C:\Documents and Settings\us\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
proxystu0.dll;C:\Documents and Settings\us\DoctorWe

#4 didom

didom

  • Members
  • 1,389 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:45 PM

Posted 03 July 2006 - 05:25 AM

OK. That looks fine!

Please post a fresh HijackThis log in your next reply.

#5 nhdon

nhdon
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:45 PM

Posted 03 July 2006 - 06:37 AM

Hi,
Thanks for the follow up. It may look fine to you, but as I said in my last post, the pop ups still exist. In fact, they've increased tenfold since following your first repair suggestions. At this point, posting another HJT log would be identical(or close) to the last one, as nothing has been deleted. Anything you or anyone else could do to help would be greatly appreciated.

Thanks,
Don

#6 didom

didom

  • Members
  • 1,389 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:45 PM

Posted 03 July 2006 - 06:50 AM

I didn't say you were clean... i only said that it was nice Dr.Web CureIt removed all those things. You aren't clean at all. So please post a fresh HijackThis log so we can continue the cleaning.

Edited by didom, 03 July 2006 - 06:50 AM.


#7 nhdon

nhdon
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:45 PM

Posted 03 July 2006 - 06:55 AM

:thumbsup: Oh, okay! I knew I wasn't clean! Give me a minute and I'll post one for you.

#8 nhdon

nhdon
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:45 PM

Posted 03 July 2006 - 06:58 AM

Here you go:

Logfile of HijackThis v1.99.1
Scan saved at 7:57:08 AM, on 7/3/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\NovaStor\NovaBackup\7\NSENGINE.exe
C:\WINDOWS\TSI32\tsircusr.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\TSIRCSRV.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\System32\VTtrayp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\shicoxp.exe
C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\calcheck.exe
C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE
C:\Program Files\Common Files\LapLink\Scheduler\LLSCHENG.EXE
C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\Lexmark 7100 Series\lxbxmon.exe
C:\Program Files\Lexmark 7100 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\M4800\PVRemote.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\lxbxcoms.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\us\Desktop\drweb-cureit.exe
C:\DOCUME~1\us\LOCALS~1\Temp\RarSFX0\_start.exe
C:\DOCUME~1\us\LOCALS~1\Temp\RarSFX0\cureit.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neopets.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://home.netscape.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\TSI32\tsircusr.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [shicoxp] C:\WINDOWS\shicoxp.exe
O4 - HKLM\..\Run: [Ulead Photo Express Calendar Checker] C:\Program Files\Ulead Systems\Ulead Photo Express My Scrapbook 2.0\calcheck.exe
O4 - HKLM\..\Run: [LapLink Scheduler] "C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE"
O4 - HKLM\..\Run: [AtariBanner] "C:\Program Files\Infogrames\Atari Anniversary Edition\Volume 2\Banner.exe" /0
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [PowerS] C:\WINDOWSPowerS.exe
O4 - HKLM\..\Run: [WinDVR SchSvr] "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [Bjwzwt] C:\Program Files\Yeus\Xuqpzko.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxbxmon.exe] "C:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Remote.lnk = C:\Program Files\M4800\PVRemote.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.connect.com/XSL/mb_us/ht...ALStreaming.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1143711123921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbxcoms.exe
O23 - Service: NsEngine - Unknown owner - C:\Program Files\NovaStor\NovaBackup\7\NSENGINE.exe
O23 - Service: Phoenix VCD Service (PhnxVCDService) - Phoenix Technologies Ltd. - C:\WINDOWS\System32\PhnxCDSvr.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TSI Remote Control Service (TSIRCSRV) - LapLink, Inc. - C:\WINDOWS\System32\TSIRCSRV.EXE

#9 didom

didom

  • Members
  • 1,389 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:45 PM

Posted 03 July 2006 - 02:58 PM

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

Step #1

Scan again with HijackThis and check the following items:
R3 - Default URLSearchHook is missing

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O4 - HKLM\..\Run: [Bjwzwt] C:\Program Files\Yeus\Xuqpzko.exe

After checking these items, close all browser windows except HijackThis and click "Fix checked".

Step #2

We need to make sure all hidden files are showing so please:
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Step #3

Reboot Your System in Safe Mode:
  • Restart the computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Step #4

Find and delete these files and folders (if they are still there):
C:\Program Files\Yeus <= this folder


Reboot your computer normally.

Step #5

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
Start HijackThis, perform a new scan and save the log file.

Use the Add Reply button to post your new logs back here along with details of any problems you encountered performing the above steps and I will review it when it comes in.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users