Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Pop Ups, Toolbars, Tclock And Cntrl Alt Del


  • This topic is locked This topic is locked
22 replies to this topic

#1 saturniid

saturniid

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 29 July 2006 - 02:15 AM

I have been reading and executing some of the suggestions you have recomended for similar problems for better than 12 hours. Here is the Hijack log file. I felt I was making progress until I ran McAfee striker or whatever it is called. I have pop ups which now come so often i have to close them constantly to continue writing this post. When I boot to windows the loggin for IE immeadiately boots and I have to close it 5 or 6 times. The Clock is turned to military time and says Tclock when I hover over it. This all started when Toolber 888 appeared which seems to be gone now. Cntrl-alt-del does not work and booting taskmanager from the launch window does not worl either. I see many strange programs under add remover all relating to surfing or toolbars.

I have run BFU
I have run look2 me destroyer
I have run Ad Ware and Spybot Search and Destroy several
I have run and rerun Trend Micro Housecall
I have allowed for reboots to rerun and been to window to make sure I was as current on my patches as possible.

My sequencing may be off or perhaps there is a step I have ommited.

I use panicware pop up stopper which seems to have lost it effectiveness SINCE McAfee was run
I also use Privacy keeper to keep cookie at bay.

Please help.



Logfile of HijackThis v1.99.1
Scan saved at 2:52:24 AM, on 7/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Sm9l\command.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\yavbjvz.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\outlook\outlook.exe
C:\Program Files\ipwins\ipwins.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\dfndrfg_7.exe
C:\kybrdfg_7.exe
C:\WINDOWS\system32\cvn0.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\v1201.exe
C:\WINDOWS\SYSC00.exe
C:\WINDOWS\system32\n9nyb.exe
C:\WINDOWS\system32\ghynf.exe
C:\WINDOWS\system32\zqskw.exe
C:\WINDOWS\sys11-1540495750.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\yavbjvzA.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\windows\system32\osdsregl.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rwintpez.exe
C:\nwnmfg_7.exe
C:\WINDOWS\system32\redistributor.exe
C:\Program Files\Common Files\{A42DE67A-05D7-1033-0629-050408160001}\Update.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\System Files\System.exe
C:\PROGRA~1\COMMON~1\wkqu\wkqum.exe
C:\Program Files\PSHope\PSHope.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\PROGRA~1\COMMON~1\wkqu\wkqua.exe
C:\Program Files\TClock\TClock.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\unzipped\hijackthis_199\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.core.com:80
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\oqeul.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,ylkyvqk.exe
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Easy PDF Creator] C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [defender] C:\\dfndrfg_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdfg_7.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [sys11-1540495750] C:\WINDOWS\sys11-1540495750.exe
O4 - HKLM\..\Run: [yavbjvzA] C:\WINDOWS\yavbjvzA.exe
O4 - HKLM\..\Run: [quu3a89c] RUNDLL32.EXE w01d7c6e.dll,n 0023a89a0000000301d7c6e
O4 - HKLM\..\Run: [{DE-E6-67-7A-ZN}] C:\windows\system32\osdsregl.exe CORN003
O4 - HKLM\..\Run: [w022a5b5.dll] RUNDLL32.EXE w022a5b5.dll,I2 0023a89a0022a5b5
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\rwintpez.exe CORN003
O4 - HKLM\..\Run: [newname] C:\\nwnmfg_7.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [wkqu] C:\PROGRA~1\COMMON~1\wkqu\wkqum.exe
O4 - HKCU\..\Run: [PSHope] "C:\Program Files\PSHope\PSHope.exe"
O4 - Startup: Zeno.lnk = C:\WINDOWS\SYSTEM32\rwintpez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe
O4 - Global Startup: svchost.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/...FreeInstall.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{36A7AC5B-D25C-4F19-9DB7-65D9A7064858}: NameServer = 64.179.43.190 69.95.31.250
O17 - HKLM\System\CCS\Services\Tcpip\..\{9FA09FA4-1586-4FF5-90D1-10809ED790A3}: NameServer = 66.129.32.1,66.129.32.10
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\lv8o09l3e.dll
O20 - Winlogon Notify: logons - C:\WINDOWS\system32\redist.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Sm9l\command.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: Easy PDF Creator Printing (Service1) - Unknown owner - C:\Program Files\Easy PDF Creator\EasyPrinting.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\yavbjvz.exe

BC AdBot (Login to Remove)

 


#2 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:06:26 AM

Posted 29 July 2006 - 04:37 AM

Hi saturniid

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Send:

- combofix log
- a fresh HijackThis log
Microsoft MVP Consumer Security
Posted Image

Posted Image

#3 saturniid

saturniid
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 29 July 2006 - 10:21 AM

Trying to go to the page you suggested resulted in this...I did not get a chance to download the file you suggested.

MZP@ !L!This program must be run under Win32 $7PEL^B*  0@@(UPX0UPX1@.rsrc @2.00UPX! EtS (e&.f@BooleanFalseTrue ,Integero!D StringA : Mth7tx|pm405 TObjectl `qysm Irface g_-F'̃D$H ̐~P@HK [a L@rXXXlTd_%TAAPLHAdDh@dd<84dA0,(dA$ A`Ad dxtpdAA 2 Sļ hT,t\$0D[c2ɓ 2n;uYhDj|3$P, 6ҋLTTu @du܋Nuo{<Q~ݖ @SV_(0:ncOBF TD1{?S$TXoPmkYZ^cYνۉ(1> Jw3WU7ًmB5C,yR˵wʋ/M;u{۹] @- /};u;7u̷ӋYZ]_52pj_ouoo_1>_zdrv!~ߧA),x{auVM4u (3Z\>.v} + +~H 3pe57 ;YKpa7ŐËGڿ7} $ 昱ʼnsjh Vp_x;t#pc;$oP,cU@~Y`jOh URux$`6N v ۟I6lɉ^ ~,qKkq&:X\rRPJy8wEۮ{s~!hhlamLvog ]I ;uK Ɍ+ GiS&t}o\s*L=ۅM +|1rg[ͽ;;Es2m}vsBk +u6҇.s|`K}u=r\Űld A!Xs @fki$L{k?3 A;p 4˘ց]?v`4_JFGnw>xh/u8&&DanSls^# 5Ag;.t鼙;u_c+PA ylx3˷\m ʢ3ҹE BUQȀF4TfJR|;uBКc;$>X>>r8W.k@ wx iS3‘d2N$NБ';4;v_+*yݗʋ&c6t ҇L1d;fo|8QUhd2[d"h=E ? adOd hF=A@? "@=uEg'޺UvZYYW־h,p -Y]k5w5)~C0 ܬk{26~VE I% B u$H"-}t!Pdl t u2  YS;Au  PgNluy e?K Ћ-\m6Y>)Q̡[l6 :B[};rS <&~ ;=8 ܝwZCʃ p|bċ܆&|pN gЃu A8_: |nM lƒ QHOtsځd+W3xzKm)EZrcC uQiw3]m %`؅c 31#ZS,3 'r@xw5?Ѝ .++5+ }k ($Ka3 E<$:n.SV=L]Qv er@ZoX+)4F6 vu(.yVpon]s#@~lK,U%cnV}<| d ӎ8As7 W7E~@yc K+^ns % &RB5]q$:2\R ]zs Kh)GK-vsx\a;uGoaU06WC4Փ @0`#!^VT0 XFW;K_QZ {>]=L`q:Z{@#-b_k gZsl ;3!wt*vn A>z` Ĭ4 u;]'K) ,] ,V0YLBg9>#j,~i ZPjSk‘| }Ӓ4Wu JAXʞs jH 鰯SG9D 0ͯit~E/,%pFN& G ̏U9Z;]Չ e3[" ; u&C;M-۳a YBE-TH?;LS)M{ Ne[]29 3RD/3%E"t[/^p[2gus'၉]!*lçL E. ξ+-))S< `8a>a 9)+lHc~,40(F,)nbD~%x rt{g N澃<y+gA sv 3Hӣ$H< ' _>=>p0K >;DI g א+;#(--o;2)CE h)",# 7((LS+H=ve;O)=Ytd`Bnsŏ%Z X$D |OjL[!+"+%e}OY;f*`4u˜C C: >ɧ)XaN=\Cr }}~tlˑ(?hͪ)gC؛~H@ pZ336Xs*D8::-'oQt2tP6ۉ'HY 2p÷)@u볥l1Єw|1o\ODsu/ c/Ú 2XÑ;. /=`RB_  ={wÊLA -_ 3BgPRQZXu1txEZ="Ƌo%" t+~9)@|9ֈG1m_CS[ X ?wx dcI9wt/x*CWDv߿!t1|9p RȄ (|HlĆ3+Е& v 8"?Gx3B[ eg@; k[b+Qm,3t m& w8` Iʐ{Z2`gPL$s\.*vr`Er0C4n z8 6W',-JA+Yt39Sػ &# C dS;F2pX V+J "u h!Ft]PB1hq!3`!63=y8tRnۿ;|NU ATn= w   J#Kn'z(vDY4ۿ;fHfIfs e o}_,:t=ÂXgqd$`VrL[۲XC=Wr/ׅw)f% u9S;9k $tfOomH(iş@gcƟQШ9uENJtwZ 8D%eNu ^t6: u0Nt,H:Ju%]k X^8<8u ҃- StLjf >_1ifB] 0 Pvk lc& F,ooot-tb+t_$kxtZXtU0'J5=HC o-0 w%9w!)j+tCli}w] F~KxI[)G 뜿cM*tAarI lLv wЀ WɭPULÓuY128߁k@G n|M=͍ƒ۬SK1.b}tyt 2taC3S}H}F\sdD4۫A4ڭD - = ? @<C@ <ȃP$O~ (kȕ @C#.a*焑* -  1_04.7@v:k :#NJ>bxAz&Dn2xH/W ?hKN΄@aQYR@ȥoU@: 'X@ x9?\@ 6_@Ngb@"E@|oe@p+ŝi@զIxZ@ t=AGA+BkU'9p|B0<RB~QC/j\&һCv)/&D 'DDYdEJzEb>9FǑ F uuvHM䧓9;5S/=]oZ T7a>%]g']݀n R`%uYnb5 ^{%\=۽#xuj %t> h>؛$k%z b4B phLhQMr\M%4EYۋ^/P3DhFdM,Tfpwff_-?f f8OFTWARE\Borland\Delphi\RTLFPUMaskValu-96#MQ~^Rp-AJ, ҇z :J^J<2ŗN^ OuT*\12$IFOlOPNXMrZ)πOZQRQSԼq|1\d/LiAm8A @SZ)=,^Z#P9X}vL,R>! _ZX=,Fz@vP0TjIXg HW. s7(k}PS'A9ۅ5EA0Wq31\)8Qq$gRⲳZGXc%@r7uʁ8!Htn{Wm/[kM'{ [ 0|9t790v). Bw  X;^zd {:vP,u7lP<tpbF ӝ)S[o(PhR~%0[(/m oc_Gı~X(%T$AcK&A`%<+C8ot% B{rSu ZhLA+4ҿYq CB?@;OuW+ @BtwkE3uЀkKu@`w8!zAs! <L' m&V <[5L&a¥)cNP‹SB3NaAT6vX#7 <flZTUWVSHۡD <%ln_0[=O B ` ^g12paYTzf!H9m9hd9V]w(1jﶹ ooM=R,t\=tW--=HtN`q5?r6t0R=)m{t=-."$:-/'=t&,*&"oؿB 0RHx ]#{J?N\T;VcSCV\źx5w !}) !2S+ٚQH|A!}\1;GW R  nth4w֜ %9ȉ\'+y Z~9uvn0F1T^!G4* M?;K1BjDؔaqkE.f$orYG0prO;~lk`_ to;i } 6H8<(@u,C4 % /dß]< Ez Lؼ^_C(`'Mg& ep Յ,ÿgd0~ XIH۱%+Дۊh` )IS@[Էo=_w 7-Nv&,Q4BDWt=F@= ^  0jhjJ,hxA@g_4 ,[ V3>\/E Q꨷@{(6>M99ܡu G0`mw5u.&uC 63{?rG̋k_5zJ;uwV}6uE莈j RlI$WbLi1"Mt!1xx=AI|+CB-)^a#(9Nu)[!A B3X Hp;636{KC F~)~$P/ PaZfDl}+ 5ZPS:̉ىu @Љ;bG+RPpV\l `&8LSAnl 8oc_n}(Vg*k 63|CNjENԽTӝ,2 /}3--|b vRE۩B Q!R(P8t mU e\^B;Z).c/-Rf;mm0 ,39<k:;̊ BIW.(׈XfX__;j7S֋ZEx9|Wr@ ˟n`@*? ~PyuVv!B+RN,:DZcCaA<;Z;;߮2ĸ+58WӉC`Xډ؋KΎ=bSX/vOEpPƁȉʏ?S1J ǔp 9NB 5J'[v 92&JкQs0_lw< z< m<tlv<,<tێ<Bf b'; Rw9 n$[l;gUՋT. o\.L.]A2߃e+BBYkA oF9b OY(C@ UjA|^o Q)~ ]ëܖGm<+1 t= tI tUtp0e3hؕ0y؏ G}9090zYfކO9wa E.ƆXG88gV(eHfxh0  ~+D]$$s/d$ CYY,TwJ?H{ 3"ozG'p1wMK 6=谋/{m`$w_[DH@3} mA28@.Q pKPo@4U`EOHVm@;t_QM8r<(;~/S5h{Y+ˏ<%nD>#俻Xuc+H}b;]}L,=sKGR3&hmmPhMl]c],M+I["~%o+AYFJ+XZ-} s~(kK]C37:X+LF j6jOGT Y|35eI'/J'zT+~E:"źE3 54Kb@TCcj&Y,t[z]uzUOD-` {+\ R8RIJ%\U:BCS;. uBQB8L' 3t++?&t u N 6XsZ QKuj>\u(&6C[01hT~ >D DhV{6I0煥=L P|~/`;P3<-C 8{Ax\' ? gB &ZD" f@8 3f+]CitqӲpAk}+A@=m,TGW8f:FM=ĭTY0t{vܳ+DSPD\Ƅ2\6٬)^@_?/k.@ IG@F0c kernel32.dlletLongPathNameA Ҩ vwE-`ghtlVLY$I؀"; ,U}$vLF -; fd-60gy3U͈%`O߲=jV $YN 73ݶ}T =@5, hYښ.Yv#;  *~!Js3~s+!;j\5.d,C6$urtl;V* %6/9`gSoftwareecF2ales;$>l"Fk;F<h f Uݡ<cU;uV2LpG@ ?.x6CC3\sQ05 ۧ4 5u Z@G Ԇ*(@- \U Z|$Q7DJAw}RFYv1^ .w 0 v? \ Ty 0 0"+!%~Ms;rN_0"H>v FrVt&{lC,`YOeK*fkJ+P 2FUo7o ? t.-v&3cfȻ%] -)$f%MfA, B@M ;܂pr0HB6G!B[0l}5W .ru $cr@U> Z3whqI>m[8hwAB'lt^ / @%v'f50A gP70?.Tn@I$J7 ^u ÀA[Mh\N]95lBEM6:`7PrBJ;<89C90\8L$.$:@OK8IRJU3 ={$u }*2Q~ШCAv t4ȋa SHKm4hW/JT!>Sl]jURh{6 ^94''U]<=s]ŶW#H .ȳ  _a03W-B v7F܊nN#پf.L9Ãg%^`b 8X %^f-frTv؀l' _M00%쬂?6 E@N^7GA"6= p hN]`s PG)P \ >&4,G7/s wɏ/_d? `c-%k75`lȔE[P&P;!NHa(jmlj@$ .ea>MLQ2[s o+\2?w)D D}@8"7'%A@)ˉA g [^_3131 b/0٩ґ,Y!2ϳlVW LwtD;̲ *v f[:u.nD@d[jIt.ΉvvвшڻW ouGgB6q !x#ljFk+XD&Bj4'!4ؙvJ^|<XKփ9 U[$ I\WOM(# P9N  [#b wGDS!Mm2,q0P"} TCY _b

#4 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:06:26 AM

Posted 29 July 2006 - 10:47 AM

Hi

Right-click that link I gave and select save as. That's direct link to file :thumbsup:
Microsoft MVP Consumer Security
Posted Image

Posted Image

#5 saturniid

saturniid
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 29 July 2006 - 03:25 PM

I right mouse clicked the file...saved it to the c:drive and executed the file. Very quickly a black backgrounded window popped up and went away and there was no other apparent action taken.

A search of my c drive produced NO combofix log.

#6 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:06:26 AM

Posted 30 July 2006 - 03:56 AM

Hi

Lets try then some different tools:

Download and unzip BFU.zip from here.
Run the program and click the Web button as shown by the blue arrow below:
Posted Image

Use this URL to copy into the address bar of the Download script window:
http://metallica.geekstogo.com/alcanshorty.bfu

Execute the script by clicking the Execute button.

If you have any questions about the use of BFU please read here:
http://metallica.geekstogo.com/BFUinstructions.html

Reboot

Please download Qoofix by Rubber Ducky to your desktop.
  • Right click on the Qoofix folder, and choose "Extract All". Extract Qoofix to your C: drive
  • Close all windows and programs, including internet windows.
  • Go to C:\Qoofix and open the folder, then double click on Qoofix.exe
  • Click Begin Removal and wait for the scan to finish
  • If Qoofix finds an infection, select yes to restart your computer
  • You will now find a log from this tool, located at C:\Qoofix\Qoofix Logfile.txt Copy and paste the contents of that report into your next reply here.
Send:

- a fresh HijackThis log
- C:\Qoofix\Qoofix Logfile.txt
Microsoft MVP Consumer Security
Posted Image

Posted Image

#7 saturniid

saturniid
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 30 July 2006 - 01:44 PM

First of all...thank you for all your help. I think I forgot to say so earlier. Secondly, some things have changed as these log files will probably show. I have downloaded and installed Grisoft Anti Virus...I have run a scan and it found about 110 intances of virus or adware which have either been removed or Quarantined. I have also installed Softperfect Personal Firewall which I had previously downloaded but I do not think was working...now it it.

I am still expreinceing some prolems though. When I boot the computer to windows two dialog boxes pop up telling me it cannot find two dll files and the Internet login window opens once. I suspect that the reason this is happening is something is trying to reinstall itself. I have closed the login box each time it poppped up. I have obviously logged onto the internet by booting internet explorer myself. While on the internet I am still getting a window or two popping up. One of which is a "warning" that I have not completed a virus scan and would I like WinAntiVirus Pro 2006 to perform a quick and completely free scan of my system. This leads me to believe something is still left on my computer causing this window to open. Also taskmanager which now seems to be working is showing "Project1" as running. And my Quick Launch buttons are disappearing even though I have the tool bar locked...I have to unlock the tool bar...turn on the Quick Launch item and then relock the bar. I am sorry if these actions I have taken have circumvented your instuctions but I had to do something the problems had reached epic proportions.

Here are the two logs you requested...please give me advice as to further clean up my system.


Qoofix v1.02 by http://www.malwarebytes.org
Scan started on [7/30/2006] at [2:10:25 PM]
-------------------------------------------------------------
No malicious modules found!
-------------------------------------------------------------
No Qoologic infected files found!
-------------------------------------------------------------
Scan COMPLETED SUCCESSFULLY on [7/30/2006] at [2:12:15 PM]

Note: Some registry keys may have been removed.




Logfile of HijackThis v1.99.1
Scan saved at 2:15:05 PM, on 7/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Ewido\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
C:\kybrdfg_7.exe
C:\Program Files\SoftPerfect Personal Firewall\fw.exe
C:\Ewido\ewido anti-spyware 4.0\ewido.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\unzipped\hijackthis_199\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.core.com:80
R3 - Default URLSearchHook is missing
O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPKbho.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Easy PDF Creator] C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [quu3a89c] RUNDLL32.EXE w01d7c6e.dll,n 0023a89a0000000301d7c6e
O4 - HKLM\..\Run: [w022a5b5.dll] RUNDLL32.EXE w022a5b5.dll,I2 0023a89a0022a5b5
O4 - HKLM\..\Run: [SoftPerfect Personal Firewall] "C:\Program Files\SoftPerfect Personal Firewall\fw.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Ewido\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [wkqu] C:\PROGRA~1\COMMON~1\wkqu\wkqum.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/...FreeInstall.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{36A7AC5B-D25C-4F19-9DB7-65D9A7064858}: NameServer = 64.179.43.190 69.95.31.250
O17 - HKLM\System\CCS\Services\Tcpip\..\{9FA09FA4-1586-4FF5-90D1-10809ED790A3}: NameServer = 66.129.32.1,66.129.32.10
O20 - Winlogon Notify: logons - C:\WINDOWS\system32\redist.dll (file missing)
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\g022lafo1d2c.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Ewido\ewido anti-spyware 4.0\guard.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: Easy PDF Creator Printing (Service1) - Unknown owner - C:\Program Files\Easy PDF Creator\EasyPrinting.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#8 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:06:26 AM

Posted 31 July 2006 - 01:48 AM

Hi

Yes, that looks pretty good :thumbsup:

Open HijackThis, click do a system scan only and checkmark these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
O4 - HKLM\..\Run: [quu3a89c] RUNDLL32.EXE w01d7c6e.dll,n 0023a89a0000000301d7c6e
O4 - HKLM\..\Run: [w022a5b5.dll] RUNDLL32.EXE w022a5b5.dll,I2 0023a89a0022a5b5
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [wkqu] C:\PROGRA~1\COMMON~1\wkqu\wkqum.exe
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/...FreeInstall.cab
O20 - Winlogon Notify: logons - C:\WINDOWS\system32\redist.dll (file missing)
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\g022lafo1d2c.dll (file missing)


Boot in safe mode -> http://www.pchell.com/support/safemode.shtml

Delete these, if found:

C:\Program Files\Common Files\wkqu
C:\kybrdfg_7.exe

Reboot

Please download Look2Me-Destroyer.exe to your desktop.

* Close all windows before continuing.
* Double-click Look2Me-Destroyer.exe to run it.
* Put a check next to Run this program as a task.
* You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 1 minute. Click OK
* When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
* Once it's done scanning, click the Remove L2M button.
* You will receive a Done Scanning message, click OK.
* When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
* Your computer will then shutdown.
* Turn your computer back on.
* Please post the contents of Look2Me-Destroyer.txt and a new HiJackThis log.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases

  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Send:

- a fresh HijackThis log
- kaspersky report
- C:\Look2Me-Destroyer.txt
Microsoft MVP Consumer Security
Posted Image

Posted Image

#9 saturniid

saturniid
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 31 July 2006 - 11:19 AM

I thought I was making progress but perhaps not.


Logfile of HijackThis v1.99.1
Scan saved at 12:11:13 PM, on 7/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Ewido\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
C:\Program Files\SoftPerfect Personal Firewall\fw.exe
C:\Ewido\ewido anti-spyware 4.0\ewido.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\explorer.exe
C:\unzipped\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R3 - Default URLSearchHook is missing
O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPKbho.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Easy PDF Creator] C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SoftPerfect Personal Firewall] C:\Program Files\SoftPerfect Personal Firewall\fw.exe
O4 - HKLM\..\Run: [!ewido] "C:\Ewido\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/...FreeInstall.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9FA09FA4-1586-4FF5-90D1-10809ED790A3}: NameServer = 66.129.32.1,66.129.32.10
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Ewido\ewido anti-spyware 4.0\guard.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: Easy PDF Creator Printing (Service1) - Unknown owner - C:\Program Files\Easy PDF Creator\EasyPrinting.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Monday, July 31, 2006 12:07:39 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 31/07/2006
Kaspersky Anti-Virus database records: 211069
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
Z:\

Scan Statistics:
Total number of scanned objects: 123134
Number of viruses found: 44
Number of infected objects: 563
Number of suspicious objects: 10
Duration of the scan process: 01:41:30

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CASClient.zip/cas2stub.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CASClient.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/MTE3NDI6ODoxNg.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/drsmartload849a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip/drsmartload46a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/drsmartload45a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Games.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Games.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Games.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Music.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Music.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Music.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\# Scary Movie 4 UNRATED DVDRip XviD.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\# Scary Movie 4 UNRATED DVDRip XviD.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\# Scary Movie 4 UNRATED DVDRip XviD.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'David Guetta Vs The Egg - Love Dont Let Me Go (Walking Away) [2006][Other][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'David Guetta Vs The Egg - Love Dont Let Me Go (Walking Away) [2006][Other][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'David Guetta Vs The Egg - Love Dont Let Me Go (Walking Away) [2006][Other][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Janet jackson ft nelly - call on me - xvid [2006][][www bitmp3 com] .avi.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Janet jackson ft nelly - call on me - xvid [2006][][www bitmp3 com] .avi.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Janet jackson ft nelly - call on me - xvid [2006][][www bitmp3 com] .avi.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Paul Hardcastle - Jazzmasters V - Retail [2006][Jazz][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Paul Hardcastle - Jazzmasters V - Retail [2006][Jazz][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Paul Hardcastle - Jazzmasters V - Retail [2006][Jazz][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Dancetraxxx 05 - Retail [2006][Dance][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Dancetraxxx 05 - Retail [2006][Dance][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Dancetraxxx 05 - Retail [2006][Dance][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Manumission Ibiza Classics Collection[3CDs] [2006][Other][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Manumission Ibiza Classics Collection[3CDs] [2006][Other][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Manumission Ibiza Classics Collection[3CDs] [2006][Other][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Miami Vice - OST [2006][Soundtrack][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Miami Vice - OST [2006][Soundtrack][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Miami Vice - OST [2006][Soundtrack][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Reggae.CH Volume 2 [2006][Reggae][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Reggae.CH Volume 2 [2006][Reggae][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Reggae.CH Volume 2 [2006][Reggae][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\+-Demonoid com-+ Miami Vice 2006 New Wallpapers Posters 1849021 7696.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\+-Demonoid com-+ Miami Vice 2006 New Wallpapers Posters 1849021 7696.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\+-Demonoid com-+ Miami Vice 2006 New Wallpapers Posters 1849021 7696.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\=Demonoid com= -Lady In The Water 2006 Wallpapers posters 1849021 7696.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\=Demonoid com= -Lady In The Water 2006 Wallpapers posters 1849021 7696.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\=Demonoid com= -Lady In The Water 2006 Wallpapers posters 1849021 7696.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\A0015299.exe.bac_a02748 Infected: not-a-virus:AdWare.Win32.WebRebates.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\A0015300.exe.bac_a02748 Infected: not-a-virus:AdWare.Win32.WebRebates.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\A0015453.exe.bac_a02748 Infected: not-a-virus:AdWare.Win32.WebRebates.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\A0020753.exe.bac_a02744 Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\About CNET Networks.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\About CNET Networks.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\About CNET Networks.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\AbsoluteUninstaller v1.52 WInaLL+Serial.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\AbsoluteUninstaller v1.52 WInaLL+Serial.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\AbsoluteUninstaller v1.52 WInaLL+Serial.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Advanced search.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Advanced search.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Advanced search.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ahead Nero v7 2 3 2b with Keymaker.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ahead Nero v7 2 3 2b with Keymaker.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ahead Nero v7 2 3 2b with Keymaker.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Air America Radio - The Al Franken Show 072706 [mp3].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Air America Radio - The Al Franken Show 072706 [mp3].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Air America Radio - The Al Franken Show 072706 [mp3].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All RSS feeds.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All RSS feeds.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All RSS feeds.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Animated Gifs rar.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Animated Gifs rar.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Animated Gifs rar.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Aquaman S01E01 Pilot SCREENER XviD-iND [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Aquaman S01E01 Pilot SCREENER XviD-iND [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Aquaman S01E01 Pilot SCREENER XviD-iND [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-1717d1a8-2041a53a.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-1717d1a8-2041a53a.RB0.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-1717d1a8-2041a53a.RB0.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-4c34df20-4f2b55ae.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-4c34df20-4f2b55ae.RB0.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-4c34df20-4f2b55ae.RB0.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6024832b-207bd30b.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6024832b-207bd30b.RB0.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6024832b-207bd30b.RB0.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6572b74b-7dff0ca2.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6572b74b-7dff0ca2.RB0.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6572b74b-7dff0ca2.RB0.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6cae5a2f-45f56bb5.RB1.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6cae5a2f-45f56bb5.RB1.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6cae5a2f-45f56bb5.RB1.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Audio & Video Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Audio & Video Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Audio & Video Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\BlazingTools Perfect Keylogger 1.6.0.0.zip.bac_a02256/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\BlazingTools Perfect Keylogger 1.6.0.0.zip.bac_a02256 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\BlazingTools Perfect Keylogger 1.6.0.0.zip.bac_a02256 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Bleach - 90.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Bleach - 90.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Bleach - 90.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Boffo Tinseltowns Bombs And Blockbusters WS HBO Special DSR XviD-THOR [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Boffo Tinseltowns Bombs And Blockbusters WS HBO Special DSR XviD-THOR [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Boffo Tinseltowns Bombs And Blockbusters WS HBO Special DSR XviD-THOR [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Browse categories.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Browse categories.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Browse categories.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Buddhism As An Education - Master Chin Kung.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Buddhism As An Education - Master Chin Kung.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Buddhism As An Education - Master Chin Kung.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Business & Productivity.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Business & Productivity.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Business & Productivity.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 1st Image set.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 1st Image set.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 1st Image set.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 2nd Pic Set.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 2nd Pic Set.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 2nd Pic Set.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 4th Pic set.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 4th Pic set.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 4th Pic set.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Chat & E-mail.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Chat & E-mail.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Chat & E-mail.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cigarettes And Alcohol 40 Modern Anthems [UK] (Jamgood).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cigarettes And Alcohol 40 Modern Anthems [UK] (Jamgood).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cigarettes And Alcohol 40 Modern Anthems [UK] (Jamgood).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968 ZIP: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968 CryptFF.b: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968 ZIP: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968 CryptFF.b: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Clerks2 Xvid LRC www.wicked-torrents.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Clerks2 Xvid LRC www.wicked-torrents.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Clerks2 Xvid LRC www.wicked-torrents.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Channel.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Channel.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Channel.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Download.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Download.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Download.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET News.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET News.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET News.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Reviews.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Reviews.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Reviews.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Shopper.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Shopper.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Shopper.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET TV.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET TV.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET TV.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Compare Prices.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Compare Prices.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Compare Prices.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cool Edit Pro v1.2a - Full.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cool Edit Pro v1.2a - Full.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cool Edit Pro v1.2a - Full.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Copyright policy.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Copyright policy.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Copyright policy.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968 ZIP: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.zip.bac_a02740/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.zip.bac_a02740/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.zip.bac_a02740 ZIP: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.zip.bac_a02740 CryptFF.b: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968/Beyond.class Infected: Trojan.Java.Needy.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968/BlackBox.class Infected: Trojan.Java.ClassLoader.m skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968 ZIP: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/Counter.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/VerifierBug.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/Xeyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/web.exe Infected: Trojan-Downloader.Win32.Small.amq skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968 ZIP: infected - 5 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968 CryptFF.b: infected - 5 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dan Brown Collection ( Da Vinci Code, Angels &amp; Demons, Deception Point).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dan Brown Collection ( Da Vinci Code, Angels &amp; Demons, Deception Point).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dan Brown Collection ( Da Vinci Code, Angels &amp; Demons, Deception Point).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Derby Stallion P PSP JAP [solops2.com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Derby Stallion P PSP JAP [solops2.com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Derby Stallion P PSP JAP [solops2.com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Design Tools.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Design Tools.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Design Tools.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Desktop Enhancements.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Desktop Enhancements.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Desktop Enhancements.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Developer Tools.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Developer Tools.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Developer Tools.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Devil Wear Prada TS XviD-xNiGELx.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Devil Wear Prada TS XviD-xNiGELx.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Devil Wear Prada TS XviD-xNiGELx.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Digital Photography.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Digital Photography.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Digital Photography.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Discworld The Game + Sound fix for 2000 XP + Walkthru.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Discworld The Game + Sound fix for 2000 XP + Walkthru.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Discworld The Game + Sound fix for 2000 XP + Walkthru.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dita Von Teese M&amp;B Photosets.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dita Von Teese M&amp;B Photosets.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dita Von Teese M&amp;B Photosets.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dog Bites Man S01E07 DSR XviD-THOR [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dog Bites Man S01E07 DSR XviD-THOR [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dog Bites Man S01E07 DSR XviD-THOR [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Easy CD-DA Extractor Professional v10 0 0 Build 1-RES-crk.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Easy CD-DA Extractor Professional v10 0 0 Build 1-RES-crk.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Easy CD-DA Extractor Professional v10 0 0 Build 1-RES-crk.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Equipe du Jeudi 27 Juillet 2006 FRENCH EBOOK.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Equipe du Jeudi 27 Juillet 2006 FRENCH EBOOK.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Equipe du Jeudi 27 Juillet 2006 FRENCH EBOOK.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Erica Campbell M&amp;B Photosets.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Erica Campbell M&amp;B Photosets.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Erica Campbell M&amp;B Photosets.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Firmtools -Album Creator- Pro v3 4.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Firmtools -Album Creator- Pro v3 4.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Firmtools -Album Creator- Pro v3 4.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\For Dummies Collection.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\For Dummies Collection.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\For Dummies Collection.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Forgot password.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Forgot password.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Forgot password.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Formula One 06 PS2DVD-Allstars.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Formula One 06 PS2DVD-Allstars.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Formula One 06 PS2DVD-Allstars.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Free MP3s.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Free MP3s.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Free MP3s.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Full Speed Fast Internet Accelerator CRACKED.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Full Speed Fast Internet Accelerator CRACKED.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Full Speed Fast Internet Accelerator CRACKED.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ghost Raider 2006 Nicolas Cage Wallpapers posters O-Demonoid com-O 1849021 7696.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ghost Raider 2006 Nicolas Cage Wallpapers posters O-Demonoid com-O 1849021 7696.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ghost Raider 2006 Nicolas Cage Wallpapers posters O-Demonoid com-O 1849021 7696.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Gold Digger - The FunAdventureFantasyScifi AmeriManga.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Gold Digger - The FunAdventureFantasyScifi AmeriManga.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Gold Digger - The FunAdventureFantasyScifi AmeriManga.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Harry Potter Books 1-6 (Ebook - English).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Harry Potter Books 1-6 (Ebook - English).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Harry Potter Books 1-6 (Ebook - English).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Help Center.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Help Center.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Help Center.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Home & Education.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Home & Education.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Home & Education.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\How to advertise.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\How to advertise.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\How to advertise.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ibiza Summerhouse Megamix 2006 seed by www p2p-world dl am rar.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ibiza Summerhouse Megamix 2006 seed by www p2p-world dl am rar.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ibiza Summerhouse Megamix 2006 seed by www p2p-world dl am rar.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inked S02E12 WS DSR XviD-THOR [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inked S02E12 WS DSR XviD-THOR [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inked S02E12 WS DSR XviD-THOR [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inspectah Deck-The Resident Patient-2006-FTD.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inspectah Deck-The Resident Patient-2006-FTD.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inspectah Deck-The Resident Patient-2006-FTD.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\International media.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\International media.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\International media.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\IRC chat.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\IRC chat.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\IRC chat.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jana Cova M&amp;B Photosets.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jana Cova M&amp;B Photosets.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jana Cova M&amp;B Photosets.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a02572/web.exe Infected: Trojan-Clicker.Win32.Small.fh skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/Counter.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/web.exe Infected: Trojan-Clicker.Win32.Small.fh skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/Xeyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/VerifierBug.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968 ZIP: infected - 5 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968 CryptFF.b: infected - 5 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.zip.bac_a02256/web.exe Infected: Trojan-Clicker.Win32.Small.fh skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.zip.bac_a02256 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.zip.bac_a02256 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02432/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02432/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02432 ZIP: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02432 CryptFF.b: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02748/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02748/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02748 ZIP: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02748 CryptFF.b: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jenna Jameson M&amp;B Photosets.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jenna Jameson M&amp;B Photosets.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jenna Jameson M&amp;B Photosets.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jethro Tull-A Little Light Music(Darkside RG).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jethro Tull-A Little Light Music(Darkside RG).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jethro Tull-A Little Light Music(Darkside RG).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kamaitachi no Yoru x 3 JPN PS2DVD-Caravan.zip.bac_a02572/S

#10 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:06:26 AM

Posted 31 July 2006 - 12:22 PM

Hi

You are making progress :thumbsup: Those files are in Trend quarantine and not active.

Kaspersky scan report cuts off. Can you please re-send it? You may need several replies for that, that's ok.

Send also C:\Look2Me-Destroyer.txt (open that file in Notepad, copy/paste its contents here).
Microsoft MVP Consumer Security
Posted Image

Posted Image

#11 saturniid

saturniid
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 31 July 2006 - 04:03 PM

KASPERSKY ON-LINE SCANNER REPORT
Monday, July 31, 2006 12:07:39 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 31/07/2006
Kaspersky Anti-Virus database records: 211069
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
Z:\

Scan Statistics:
Total number of scanned objects: 123134
Number of viruses found: 44
Number of infected objects: 563
Number of suspicious objects: 10
Duration of the scan process: 01:41:30

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CASClient.zip/cas2stub.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CASClient.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/MTE3NDI6ODoxNg.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/drsmartload849a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip/drsmartload46a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/drsmartload45a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Games.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Games.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Games.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Music.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Music.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Music.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\ Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\# Scary Movie 4 UNRATED DVDRip XviD.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\# Scary Movie 4 UNRATED DVDRip XviD.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\# Scary Movie 4 UNRATED DVDRip XviD.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'David Guetta Vs The Egg - Love Dont Let Me Go (Walking Away) [2006][Other][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'David Guetta Vs The Egg - Love Dont Let Me Go (Walking Away) [2006][Other][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'David Guetta Vs The Egg - Love Dont Let Me Go (Walking Away) [2006][Other][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Janet jackson ft nelly - call on me - xvid [2006][][www bitmp3 com] .avi.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Janet jackson ft nelly - call on me - xvid [2006][][www bitmp3 com] .avi.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Janet jackson ft nelly - call on me - xvid [2006][][www bitmp3 com] .avi.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Paul Hardcastle - Jazzmasters V - Retail [2006][Jazz][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Paul Hardcastle - Jazzmasters V - Retail [2006][Jazz][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'Paul Hardcastle - Jazzmasters V - Retail [2006][Jazz][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Dancetraxxx 05 - Retail [2006][Dance][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Dancetraxxx 05 - Retail [2006][Dance][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Dancetraxxx 05 - Retail [2006][Dance][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Manumission Ibiza Classics Collection[3CDs] [2006][Other][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Manumission Ibiza Classics Collection[3CDs] [2006][Other][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Manumission Ibiza Classics Collection[3CDs] [2006][Other][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Miami Vice - OST [2006][Soundtrack][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Miami Vice - OST [2006][Soundtrack][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Miami Vice - OST [2006][Soundtrack][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Reggae.CH Volume 2 [2006][Reggae][www bitmp3 com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Reggae.CH Volume 2 [2006][Reggae][www bitmp3 com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\'VA - Reggae.CH Volume 2 [2006][Reggae][www bitmp3 com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\+-Demonoid com-+ Miami Vice 2006 New Wallpapers Posters 1849021 7696.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\+-Demonoid com-+ Miami Vice 2006 New Wallpapers Posters 1849021 7696.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\+-Demonoid com-+ Miami Vice 2006 New Wallpapers Posters 1849021 7696.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\=Demonoid com= -Lady In The Water 2006 Wallpapers posters 1849021 7696.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\=Demonoid com= -Lady In The Water 2006 Wallpapers posters 1849021 7696.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\=Demonoid com= -Lady In The Water 2006 Wallpapers posters 1849021 7696.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\A0015299.exe.bac_a02748 Infected: not-a-virus:AdWare.Win32.WebRebates.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\A0015300.exe.bac_a02748 Infected: not-a-virus:AdWare.Win32.WebRebates.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\A0015453.exe.bac_a02748 Infected: not-a-virus:AdWare.Win32.WebRebates.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\A0020753.exe.bac_a02744 Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\About CNET Networks.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\About CNET Networks.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\About CNET Networks.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\AbsoluteUninstaller v1.52 WInaLL+Serial.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\AbsoluteUninstaller v1.52 WInaLL+Serial.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\AbsoluteUninstaller v1.52 WInaLL+Serial.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Advanced search.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Advanced search.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Advanced search.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ahead Nero v7 2 3 2b with Keymaker.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ahead Nero v7 2 3 2b with Keymaker.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ahead Nero v7 2 3 2b with Keymaker.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Air America Radio - The Al Franken Show 072706 [mp3].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Air America Radio - The Al Franken Show 072706 [mp3].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Air America Radio - The Al Franken Show 072706 [mp3].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All RSS feeds.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All RSS feeds.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All RSS feeds.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\All Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Animated Gifs rar.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Animated Gifs rar.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Animated Gifs rar.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Aquaman S01E01 Pilot SCREENER XviD-iND [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Aquaman S01E01 Pilot SCREENER XviD-iND [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Aquaman S01E01 Pilot SCREENER XviD-iND [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-1717d1a8-2041a53a.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-1717d1a8-2041a53a.RB0.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-1717d1a8-2041a53a.RB0.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-4c34df20-4f2b55ae.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-4c34df20-4f2b55ae.RB0.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-4c34df20-4f2b55ae.RB0.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6024832b-207bd30b.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6024832b-207bd30b.RB0.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6024832b-207bd30b.RB0.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6572b74b-7dff0ca2.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6572b74b-7dff0ca2.RB0.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6572b74b-7dff0ca2.RB0.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6cae5a2f-45f56bb5.RB1.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6cae5a2f-45f56bb5.RB1.bac_a03968 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\archive.jar-6cae5a2f-45f56bb5.RB1.bac_a03968 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Audio & Video Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Audio & Video Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Audio & Video Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\BlazingTools Perfect Keylogger 1.6.0.0.zip.bac_a02256/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\BlazingTools Perfect Keylogger 1.6.0.0.zip.bac_a02256 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\BlazingTools Perfect Keylogger 1.6.0.0.zip.bac_a02256 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Bleach - 90.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Bleach - 90.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Bleach - 90.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Boffo Tinseltowns Bombs And Blockbusters WS HBO Special DSR XviD-THOR [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Boffo Tinseltowns Bombs And Blockbusters WS HBO Special DSR XviD-THOR [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Boffo Tinseltowns Bombs And Blockbusters WS HBO Special DSR XviD-THOR [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Browse categories.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Browse categories.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Browse categories.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Buddhism As An Education - Master Chin Kung.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Buddhism As An Education - Master Chin Kung.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Buddhism As An Education - Master Chin Kung.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Business & Productivity.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Business & Productivity.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Business & Productivity.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 1st Image set.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 1st Image set.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 1st Image set.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 2nd Pic Set.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 2nd Pic Set.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 2nd Pic Set.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 4th Pic set.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 4th Pic set.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cafferine - 4th Pic set.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Chat & E-mail.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Chat & E-mail.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Chat & E-mail.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cigarettes And Alcohol 40 Modern Anthems [UK] (Jamgood).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cigarettes And Alcohol 40 Modern Anthems [UK] (Jamgood).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cigarettes And Alcohol 40 Modern Anthems [UK] (Jamgood).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968 ZIP: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-5b3646cb-2d4c2ddf.RB0.bac_a03968 CryptFF.b: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968 ZIP: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\classload.jar-7d9192de-2679ac9b.RB0.bac_a03968 CryptFF.b: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Clerks2 Xvid LRC www.wicked-torrents.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Clerks2 Xvid LRC www.wicked-torrents.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Clerks2 Xvid LRC www.wicked-torrents.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Channel.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Channel.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Channel.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Download.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Download.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Download.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET News.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET News.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET News.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Reviews.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Reviews.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Reviews.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Shopper.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Shopper.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET Shopper.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET TV.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET TV.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\CNET TV.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Compare Prices.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Compare Prices.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Compare Prices.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cool Edit Pro v1.2a - Full.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cool Edit Pro v1.2a - Full.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Cool Edit Pro v1.2a - Full.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Copyright policy.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Copyright policy.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Copyright policy.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968 ZIP: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.RB0.bac_a03968 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.zip.bac_a02740/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.zip.bac_a02740/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.zip.bac_a02740 ZIP: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count.jar-5980c178-53abc016.zip.bac_a02740 CryptFF.b: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968/Beyond.class Infected: Trojan.Java.Needy.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968/BlackBox.class Infected: Trojan.Java.ClassLoader.m skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968 ZIP: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\count3.jar-5e65f553-59b27c0b.RB0.bac_a03968 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/Counter.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/VerifierBug.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/Xeyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968/web.exe Infected: Trojan-Downloader.Win32.Small.amq skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968 ZIP: infected - 5 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\counter.jpg-649c2a9-1a20a76d.RB0.bac_a03968 CryptFF.b: infected - 5 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dan Brown Collection ( Da Vinci Code, Angels &amp; Demons, Deception Point).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dan Brown Collection ( Da Vinci Code, Angels &amp; Demons, Deception Point).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dan Brown Collection ( Da Vinci Code, Angels &amp; Demons, Deception Point).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Derby Stallion P PSP JAP [solops2.com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Derby Stallion P PSP JAP [solops2.com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Derby Stallion P PSP JAP [solops2.com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Design Tools.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Design Tools.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Design Tools.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Desktop Enhancements.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Desktop Enhancements.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Desktop Enhancements.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Developer Tools.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Developer Tools.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Developer Tools.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Devil Wear Prada TS XviD-xNiGELx.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Devil Wear Prada TS XviD-xNiGELx.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Devil Wear Prada TS XviD-xNiGELx.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Digital Photography.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Digital Photography.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Digital Photography.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Discworld The Game + Sound fix for 2000 XP + Walkthru.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Discworld The Game + Sound fix for 2000 XP + Walkthru.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Discworld The Game + Sound fix for 2000 XP + Walkthru.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dita Von Teese M&amp;B Photosets.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dita Von Teese M&amp;B Photosets.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dita Von Teese M&amp;B Photosets.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dog Bites Man S01E07 DSR XviD-THOR [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dog Bites Man S01E07 DSR XviD-THOR [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Dog Bites Man S01E07 DSR XviD-THOR [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Easy CD-DA Extractor Professional v10 0 0 Build 1-RES-crk.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Easy CD-DA Extractor Professional v10 0 0 Build 1-RES-crk.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Easy CD-DA Extractor Professional v10 0 0 Build 1-RES-crk.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Equipe du Jeudi 27 Juillet 2006 FRENCH EBOOK.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Equipe du Jeudi 27 Juillet 2006 FRENCH EBOOK.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Equipe du Jeudi 27 Juillet 2006 FRENCH EBOOK.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Erica Campbell M&amp;B Photosets.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Erica Campbell M&amp;B Photosets.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Erica Campbell M&amp;B Photosets.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Firmtools -Album Creator- Pro v3 4.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Firmtools -Album Creator- Pro v3 4.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Firmtools -Album Creator- Pro v3 4.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\For Dummies Collection.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\For Dummies Collection.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\For Dummies Collection.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Forgot password.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Forgot password.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Forgot password.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Formula One 06 PS2DVD-Allstars.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Formula One 06 PS2DVD-Allstars.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Formula One 06 PS2DVD-Allstars.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Free MP3s.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Free MP3s.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Free MP3s.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Full Speed Fast Internet Accelerator CRACKED.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Full Speed Fast Internet Accelerator CRACKED.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Full Speed Fast Internet Accelerator CRACKED.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ghost Raider 2006 Nicolas Cage Wallpapers posters O-Demonoid com-O 1849021 7696.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ghost Raider 2006 Nicolas Cage Wallpapers posters O-Demonoid com-O 1849021 7696.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ghost Raider 2006 Nicolas Cage Wallpapers posters O-Demonoid com-O 1849021 7696.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Gold Digger - The FunAdventureFantasyScifi AmeriManga.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Gold Digger - The FunAdventureFantasyScifi AmeriManga.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Gold Digger - The FunAdventureFantasyScifi AmeriManga.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Harry Potter Books 1-6 (Ebook - English).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Harry Potter Books 1-6 (Ebook - English).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Harry Potter Books 1-6 (Ebook - English).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Help Center.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Help Center.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Help Center.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Home & Education.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Home & Education.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Home & Education.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\How to advertise.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\How to advertise.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\How to advertise.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ibiza Summerhouse Megamix 2006 seed by www p2p-world dl am rar.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ibiza Summerhouse Megamix 2006 seed by www p2p-world dl am rar.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Ibiza Summerhouse Megamix 2006 seed by www p2p-world dl am rar.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inked S02E12 WS DSR XviD-THOR [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inked S02E12 WS DSR XviD-THOR [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inked S02E12 WS DSR XviD-THOR [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inspectah Deck-The Resident Patient-2006-FTD.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inspectah Deck-The Resident Patient-2006-FTD.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Inspectah Deck-The Resident Patient-2006-FTD.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\International media.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\International media.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\International media.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\IRC chat.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\IRC chat.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\IRC chat.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jana Cova M&amp;B Photosets.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jana Cova M&amp;B Photosets.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jana Cova M&amp;B Photosets.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a02572/web.exe Infected: Trojan-Clicker.Win32.Small.fh skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/Counter.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/web.exe Infected: Trojan-Clicker.Win32.Small.fh skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/Worker.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/Xeyond.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968/VerifierBug.class Infected: Trojan.Java.Femad skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968 ZIP: infected - 5 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.RB0.bac_a03968 CryptFF.b: infected - 5 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.zip.bac_a02256/web.exe Infected: Trojan-Clicker.Win32.Small.fh skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.zip.bac_a02256 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\jar.jar-623472a5-5fcaa911.zip.bac_a02256 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02432/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02432/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02432 ZIP: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02432 CryptFF.b: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02748/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02748/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02748 ZIP: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\java.jar-8fba448-7092d788.zip.bac_a02748 CryptFF.b: infected - 2 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jenna Jameson M&amp;B Photosets.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jenna Jameson M&amp;B Photosets.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jenna Jameson M&amp;B Photosets.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jethro Tull-A Little Light Music(Darkside RG).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jethro Tull-A Little Light Music(Darkside RG).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Jethro Tull-A Little Light Music(Darkside RG).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kamaitachi no Yoru x 3 JPN PS2DVD-Caravan.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kamaitachi no Yoru x 3 JPN PS2DVD-Caravan.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kamaitachi no Yoru x 3 JPN PS2DVD-Caravan.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E01 HDTV XviD-VSS [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E01 HDTV XviD-VSS [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E01 HDTV XviD-VSS [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E02 HDTV XviD-VSS [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E02 HDTV XviD-VSS [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E02 HDTV XviD-VSS [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E03 HDTV XviD-FQM [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E03 HDTV XviD-FQM [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Kyle XY S01E03 HDTV XviD-FQM [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\L'Equipe Du 27 07 2006 E-book french.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\L'Equipe Du 27 07 2006 E-book french.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\L'Equipe Du 27 07 2006 E-book french.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\L'Equipe du 28 Juillet 2006 pdf.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\L'Equipe du 28 Juillet 2006 pdf.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\L'Equipe du 28 Juillet 2006 pdf.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lady In The Water 2006 TS maVen kvcd Jamgood(TUS Release).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lady In The Water 2006 TS maVen kvcd Jamgood(TUS Release).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lady In The Water 2006 TS maVen kvcd Jamgood(TUS Release).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Limewire Professional v4.12.4 RETAIL-Lz0.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Limewire Professional v4.12.4 RETAIL-Lz0.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Limewire Professional v4.12.4 RETAIL-Lz0.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\loaderadv596.jar-56641478-7adf9b70.zip.bac_a02748/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\loaderadv596.jar-56641478-7adf9b70.zip.bac_a02748/Counter.class Infected: Trojan.Java.ClassLoader.h skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\loaderadv596.jar-56641478-7adf9b70.zip.bac_a02748/Parser.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\loaderadv596.jar-56641478-7adf9b70.zip.bac_a02748 ZIP: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\loaderadv596.jar-56641478-7adf9b70.zip.bac_a02748 CryptFF.b: infected - 3 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lynda com - Aperture 1 1 Essential Training.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lynda com - Aperture 1 1 Essential Training.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lynda com - Aperture 1 1 Essential Training.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lynda com - Photoshop CS2 FAQs.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lynda com - Photoshop CS2 FAQs.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Lynda com - Photoshop CS2 FAQs.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mac Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mac Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mac Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Magnetic Energy - Free Energy pdf.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Magnetic Energy - Free Energy pdf.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Magnetic Energy - Free Energy pdf.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\McAfee AntiVirus 2006.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\McAfee AntiVirus 2006.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\McAfee AntiVirus 2006.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mininova Trackmania Nations Server.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mininova Trackmania Nations Server.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mininova Trackmania Nations Server.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mobile Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mobile Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Mobile Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\msjld.jar-6ecc4ec7-7c3b6b20.RB0.bac_a03968/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\msjld.jar-6ecc4ec7-7c3b6b20.RB0.bac_a03968/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\msjld.jar-6ecc4ec7-7c3b6b20.RB0.bac_a03968/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\msjld.jar-6ecc4ec7-7c3b6b20.RB0.bac_a03968/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\msjld.jar-6ecc4ec7-7c3b6b20.RB0.bac_a03968 ZIP: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\msjld.jar-6ecc4ec7-7c3b6b20.RB0.bac_a03968 CryptFF.b: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\My Super Ex-Girlfriend 2006 CAM VCD iNT-CAMERA[www tensiontorrent com].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\My Super Ex-Girlfriend 2006 CAM VCD iNT-CAMERA[www tensiontorrent com].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\My Super Ex-Girlfriend 2006 CAM VCD iNT-CAMERA[www tensiontorrent com].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\MythBusters S03E19 DSR XviD-CRNTV [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\MythBusters S03E19 DSR XviD-CRNTV [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\MythBusters S03E19 DSR XviD-CRNTV [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Napoleon Hill Think and Grow Rich 21st Century Edition.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Napoleon Hill Think and Grow Rich 21st Century Edition.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Napoleon Hill Think and Grow Rich 21st Century Edition.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Naruto 317 MQ Binktopia rar.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:

#12 saturniid

saturniid
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 31 July 2006 - 04:06 PM

C:\Documents and Settings\jpb\.housecall\Quarantine\Naruto 317 MQ Binktopia rar.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Naruto 317 MQ Binktopia rar.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nero 7 Premium-Plugins-&amp; Codecs-2006.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nero 7 Premium-Plugins-&amp; Codecs-2006.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nero 7 Premium-Plugins-&amp; Codecs-2006.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nero For Linux.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nero For Linux.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nero For Linux.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\New Riders Press Publish and Prosper Blogging for Your Business Jun 2006 eBook-BBL.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\New Riders Press Publish and Prosper Blogging for Your Business Jun 2006 eBook-BBL.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\New Riders Press Publish and Prosper Blogging for Your Business Jun 2006 eBook-BBL.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\NHUpdater.exe.bac_a02748 Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nod32 AntiVirus v2.51.28 + Patch.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nod32 AntiVirus v2.51.28 + Patch.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Nod32 AntiVirus v2.51.28 + Patch.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\O'Reilly Pack - 60 eBooks-(Demonoid com) 1975600 393.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\O'Reilly Pack - 60 eBooks-(Demonoid com) 1975600 393.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\O'Reilly Pack - 60 eBooks-(Demonoid com) 1975600 393.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Obie Trice Second Rounds on Me 2006 MVP from www torrent-zentrale 6x to.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Obie Trice Second Rounds on Me 2006 MVP from www torrent-zentrale 6x to.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Obie Trice Second Rounds on Me 2006 MVP from www torrent-zentrale 6x to.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Opie &amp; Anthony 2006-07-27-O&amp;A (JB-64kCF) mp3.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Opie &amp; Anthony 2006-07-27-O&amp;A (JB-64kCF) mp3.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Opie &amp; Anthony 2006-07-27-O&amp;A (JB-64kCF) mp3.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\over 200 WindowsXP Wallpaper 3.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\over 200 WindowsXP Wallpaper 3.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\over 200 WindowsXP Wallpaper 3.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Painkiller Hell Wars XBOX DVD NTSC ENG BY DME.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Painkiller Hell Wars XBOX DVD NTSC ENG BY DME.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Painkiller Hell Wars XBOX DVD NTSC ENG BY DME.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Partnership opportunities.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Partnership opportunities.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Partnership opportunities.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\PC Starter Kit.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\PC Starter Kit.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\PC Starter Kit.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Pianist - Hentai DVD+VHS - By ZeRaTuL avi.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Pianist - Hentai DVD+VHS - By ZeRaTuL avi.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Pianist - Hentai DVD+VHS - By ZeRaTuL avi.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Privacy policy.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Privacy policy.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Privacy policy.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Private Pirate Magazine 93.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Private Pirate Magazine 93.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Private Pirate Magazine 93.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Professional Poker Tour S01E04 DSR XviD-ORENJi [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Professional Poker Tour S01E04 DSR XviD-ORENJi [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Professional Poker Tour S01E04 DSR XviD-ORENJi [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Project Runway S03E03 REAL DSR XviD-ORENJi [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Project Runway S03E03 REAL DSR XviD-ORENJi [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Project Runway S03E03 REAL DSR XviD-ORENJi [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Release 1.0.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Release 1.0.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Release 1.0.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Rock Star Supernova S02E08 PDTV XviD-BamHD [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Rock Star Supernova S02E08 PDTV XviD-BamHD [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Rock Star Supernova S02E08 PDTV XviD-BamHD [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Rod Stewart - 32 albums inc covers.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Rod Stewart - 32 albums inc covers.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Rod Stewart - 32 albums inc covers.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Roller Coaster Tycoon 2 iso + no-cd crack[English].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Roller Coaster Tycoon 2 iso + no-cd crack[English].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Roller Coaster Tycoon 2 iso + no-cd crack[English].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Runes of Ragnan (from Z-Cult FM).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Runes of Ragnan (from Z-Cult FM).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Runes of Ragnan (from Z-Cult FM).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Scary Movie 4 UNRATED DVDRip XviD - DiAMOND.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Scary Movie 4 UNRATED DVDRip XviD - DiAMOND.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Scary Movie 4 UNRATED DVDRip XviD - DiAMOND.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Scary Movie 4 UNRATED DVDRip XviD-DiAMOND.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Scary Movie 4 UNRATED DVDRip XviD-DiAMOND.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Scary Movie 4 UNRATED DVDRip XviD-DiAMOND.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Search Cloud.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Search Cloud.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Search Cloud.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Security & Spyware.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Security & Spyware.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Security & Spyware.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Sexy Girl Wallpapers.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Sexy Girl Wallpapers.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Sexy Girl Wallpapers.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Show all of today &rarr;.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Show all of today &rarr;.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Show all of today &rarr;.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Silent Hill The Movie 2006 Amazing Posters And Art Works- Demonoid com - 1849021 7696.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Silent Hill The Movie 2006 Amazing Posters And Art Works- Demonoid com - 1849021 7696.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Silent Hill The Movie 2006 Amazing Posters And Art Works- Demonoid com - 1849021 7696.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\SmartComputing - September 2006.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\SmartComputing - September 2006.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\SmartComputing - September 2006.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Spiderman3 2007 Wallpapers posters-[[Demonoid com]] 1849021 7696.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Spiderman3 2007 Wallpapers posters-[[Demonoid com]] 1849021 7696.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Spiderman3 2007 Wallpapers posters-[[Demonoid com]] 1849021 7696.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\SpongeBob Squarepants - Battle for Bikini Bottom (PC).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\SpongeBob Squarepants - Battle for Bikini Bottom (PC).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\SpongeBob Squarepants - Battle for Bikini Bottom (PC).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Spyware Removal.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Spyware Removal.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Spyware Removal.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Street Fighter III Third Strike [NTSC-JAP] PS2.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Street Fighter III Third Strike [NTSC-JAP] PS2.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Street Fighter III Third Strike [NTSC-JAP] PS2.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Subliminal Entertainment - Pleasure Center.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Subliminal Entertainment - Pleasure Center.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Subliminal Entertainment - Pleasure Center.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Submit Software.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Submit Software.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Submit Software.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Sugar Rush S02E08 WS PDTV XviD-RiVER [eztv].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Sugar Rush S02E08 WS PDTV XviD-RiVER [eztv].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Sugar Rush S02E08 WS PDTV XviD-RiVER [eztv].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Superman Returns XViD TS-maVenwww.mega-bits.com.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Superman Returns XViD TS-maVenwww.mega-bits.com.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Superman Returns XViD TS-maVenwww.mega-bits.com.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tekken Dark Resurrection (USA )(PSP).zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tekken Dark Resurrection (USA )(PSP).zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tekken Dark Resurrection (USA )(PSP).zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tekken Dark Resurrection EUR (846MB) rar.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tekken Dark Resurrection EUR (846MB) rar.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tekken Dark Resurrection EUR (846MB) rar.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Terms of use.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Terms of use.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Terms of use.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tetris Unlimited [Multilanguage 23].zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tetris Unlimited [Multilanguage 23].zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\Tetris Unlimited [Multilanguage 23].zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\The Ant Bully PS2DVD-EMiNENT.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\The Ant Bully PS2DVD-EMiNENT.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\The Ant Bully PS2DVD-EMiNENT.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\The Bit Torrent Bible rar.zip.bac_a02572/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\The Bit Torrent Bible rar.zip.bac_a02572 ZIP: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\The Bit Torrent Bible rar.zip.bac_a02572 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\v2.0.4d.cab.bac_a02748/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\v2.0.4d.cab.bac_a02748/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\v2.0.4d.cab.bac_a02748/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\v2.0.4d.cab.bac_a02748/navapp.exe Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\v2.0.4d.cab.bac_a02748 CAB: infected - 4 skipped
C:\Documents and Settings\jpb\.housecall\Quarantine\v2.0.4d.cab.bac_a02748 CryptFF.b: infected - 4 skipped
C:\Documents and Settings\jpb\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Inbox/09 Jan 2006 22:46 from Mail Delivery System:Mail delivery failed.eml/[From joeb@mapleblock.com][Date Mon, 9 Jan 2006 16:46:26 -0600]/UNNAMED/file.scr Infected: Net-Worm.Win32.Mytob.i skipped
C:\Documents and Settings\jpb\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Inbox/09 Jan 2006 22:46 from Mail Delivery System:Mail delivery failed.eml/[From joeb@mapleblock.com][Date Mon, 9 Jan 2006 16:46:26 -0600]/UNNAMED Infected: Net-Worm.Win32.Mytob.i skipped
C:\Documents and Settings\jpb\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Inbox/09 Jan 2006 22:46 from Mail Delivery System:Mail delivery failed.eml Infected: Net-Worm.Win32.Mytob.i skipped
C:\Documents and Settings\jpb\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Inbox/14 Jan 2006 07:11 from Mail Delivery System:Mail delivery failed.eml/[From joeb@mapleblock.com][Date Sat, 14 Jan 2006 01:11:36 -0600]/UNNAMED/file.scr Infected: Net-Worm.Win32.Mytob.i skipped
C:\Documents and Settings\jpb\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Inbox/14 Jan 2006 07:11 from Mail Delivery System:Mail delivery failed.eml/[From joeb@mapleblock.com][Date Sat, 14 Jan 2006 01:11:36 -0600]/UNNAMED Infected: Net-Worm.Win32.Mytob.i skipped
C:\Documents and Settings\jpb\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Inbox/14 Jan 2006 07:11 from Mail Delivery System:Mail delivery failed.eml Infected: Net-Worm.Win32.Mytob.i skipped
C:\Documents and Settings\jpb\Application Data\Microsoft\Outlook\outlook.pst Mail MS Mail: infected - 6 skipped
C:\Documents and Settings\jpb\Local Settings\Temporary Internet Files\Content.IE5\RO1MTZ1A\popup[1].html Infected: Trojan-Clicker.HTML.Agent.a skipped
C:\Documents and Settings\jpb\mc-110-12-0000137.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\Documents and Settings\jpb\mc-110-12-0000137.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\Documents and Settings\jpb\mc-110-12-0000137.exe NSIS: infected - 2 skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Program Files\Online Services\kyze.html Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP155\A0033133.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP155\A0033133.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP155\A0033133.exe CAB: infected - 2 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP156\A0033211.exe Infected: Trojan-Downloader.Win32.VB.aiy skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP156\A0033216.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034314.exe Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034382.exe Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034383.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034385.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034387.exe Infected: not-a-virus:AdWare.Win32.CASClient.f skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034388.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034389.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034390.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034391.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034392.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034393.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034394.dll Infected: not-a-virus:AdWare.Win32.Agent.e skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034395.dll Infected: not-a-virus:AdWare.Win32.Agent.e skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034396.dll Infected: not-a-virus:AdWare.Win32.BHO.ao skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034449.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034449.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034449.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034450.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034525.exe Infected: Trojan-Downloader.Win32.Adload.dh skipped
C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\WINDOWS\pf78.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw skipped
C:\WINDOWS\pf78.exe/data0003 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\pf78.exe/data0006 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\pf78.exe/data0007 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\pf78.exe NSIS: infected - 4 skipped
C:\WINDOWS\srvhuxjeye.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.BHO.ao skipped
C:\WINDOWS\srvhuxjeye.exe/stream Infected: not-a-virus:AdWare.Win32.BHO.ao skipped
C:\WINDOWS\srvhuxjeye.exe NSIS: infected - 2 skipped
C:\WINDOWS\srvkxropzx.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.ep skipped
C:\WINDOWS\srvkxropzx.exe NSIS: infected - 1 skipped
C:\WINDOWS\ssqbn.exe/data0002 Infected: Trojan-Downloader.Win32.Small.ajc skipped
C:\WINDOWS\ssqbn.exe/data0003 Infected: Trojan-Downloader.Win32.Small.ajc skipped
C:\WINDOWS\ssqbn.exe NSIS: infected - 2 skipped
C:\WINDOWS\SYSTEM32\bez6n4r21.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped
C:\WINDOWS\SYSTEM32\VSL05.exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped
C:\WINDOWS\SYSTEM32\VSL05.exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped
C:\WINDOWS\SYSTEM32\VSL05.exe NSIS: infected - 2 skipped

Scan process completed.

#13 saturniid

saturniid
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 31 July 2006 - 04:07 PM

Look2Me-Destroyer V1.0.12

Scanning for infected files.....
Scan started at 7/31/2006 8:48:16 AM

Infected! C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034384.dll

Attempting to delete infected files...

Attempting to delete: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034384.dll
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034384.dll Deleted successfully!

Making registry repairs.


Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{D62AB5F3-4B9F-4509-8B00-A21E839046B2}"
HKCR\Clsid\{D62AB5F3-4B9F-4509-8B00-A21E839046B2}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B04173F7-ABE6-43A1-BA1E-E6DFC80BEFDC}"
HKCR\Clsid\{B04173F7-ABE6-43A1-BA1E-E6DFC80BEFDC}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{CD209D09-128B-4D7E-AFC6-5D60DD7E2A5D}"
HKCR\Clsid\{CD209D09-128B-4D7E-AFC6-5D60DD7E2A5D}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

#14 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:06:26 AM

Posted 01 August 2006 - 03:01 AM

Hi

Open Outlook, log in to your account and go to inbox

Delete mails dated as below:

Date Mon, 9 Jan 2006 16:46:26 -0600
Date Sat, 14 Jan 2006 01:11:36 -0600

Empty Deleted Items folders

Boot in safe mode -> http://www.pchell.com/support/safemode.shtml

Empty this folder (delete all files in that directory):

C:\Documents and Settings\jpb\.housecall\Quarantine\

Delete these:

C:\Documents and Settings\jpb\mc-110-12-0000137.exe
C:\Program Files\Online Services\kyze.html
C:\WINDOWS\Downloaded Program Files\popcaploader.dll
C:\WINDOWS\pf78.exe
C:\WINDOWS\srvhuxjeye.exe
C:\WINDOWS\srvkxropzx.exe
C:\WINDOWS\ssqbn.exe
C:\WINDOWS\SYSTEM32\bez6n4r21.exe
C:\WINDOWS\SYSTEM32\VSL05.exe

Empty Recycle Bin.

Reboot

Re-scan with kaspersky

Send:

- a fresh HijackThis log
- kaspersky report
Microsoft MVP Consumer Security
Posted Image

Posted Image

#15 saturniid

saturniid
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:26 AM

Posted 01 August 2006 - 10:22 AM

Logfile of HijackThis v1.99.1
Scan saved at 11:09:03 AM, on 8/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Ewido\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
C:\Program Files\SoftPerfect Personal Firewall\fw.exe
C:\Ewido\ewido anti-spyware 4.0\ewido.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\unzipped\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R3 - Default URLSearchHook is missing
O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPKbho.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Easy PDF Creator] C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SoftPerfect Personal Firewall] C:\Program Files\SoftPerfect Personal Firewall\fw.exe
O4 - HKLM\..\Run: [!ewido] "C:\Ewido\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CK

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Tuesday, August 01, 2006 10:21:37 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 1/08/2006
Kaspersky Anti-Virus database records: 211340
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
E:\
Z:\

Scan Statistics:
Total number of scanned objects: 122588
Number of viruses found: 22
Number of infected objects: 43
Number of suspicious objects: 10
Duration of the scan process: 01:36:47

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CASClient.zip/cas2stub.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CASClient.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/MTE3NDI6ODoxNg.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/drsmartload849a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip/drsmartload46a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/drsmartload45a7i.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip ZIP: suspicious - 1 skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP155\A0033133.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP155\A0033133.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP155\A0033133.exe CAB: infected - 2 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP156\A0033211.exe Infected: Trojan-Downloader.Win32.VB.aiy skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP156\A0033216.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034314.exe Infected: not-a-virus:AdWare.Win32.NavExcel.h skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034382.exe Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034383.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034385.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034387.exe Infected: not-a-virus:AdWare.Win32.CASClient.f skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034388.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034389.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034390.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034391.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034392.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034393.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034394.dll Infected: not-a-virus:AdWare.Win32.Agent.e skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034395.dll Infected: not-a-virus:AdWare.Win32.Agent.e skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034396.dll Infected: not-a-virus:AdWare.Win32.BHO.ao skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034449.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034449.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP158\A0034449.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034788.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034788.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034788.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034789.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034789.exe/data0003 Infected: Trojan.Win32.VB.tg skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034789.exe/data0006 Infected: Trojan.Win32.VB.tg skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034789.exe/data0007 Infected: Trojan.Win32.VB.tg skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034789.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034790.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.BHO.ao skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034790.exe/stream Infected: not-a-virus:AdWare.Win32.BHO.ao skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034790.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034791.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.ep skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034791.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034792.exe/data0002 Infected: Trojan-Downloader.Win32.Small.ajc skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034792.exe/data0003 Infected: Trojan-Downloader.Win32.Small.ajc skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034792.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034793.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034794.exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034794.exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP159\A0034794.exe NSIS: infected - 2 skipped

Scan process completed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users