Gå til innhold

HJT og SAS logg - trenger en sjekk!


Anbefalte innlegg

Har kjør en CCleaner + SAS i sikkerhetsmodus. Har en HJT-logg her som jeg vil gjerne finner mer ut av :)

 

HJT-logg:

Klikk for å se/fjerne spoilerteksten nedenfor

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 03:48:16, on 03.02.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\BCMSMMSG.exe

C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe

C:\Programfiler\LogMeIn\LogMeInSystray.exe

C:\Programfiler\QuickTime\qttask.exe

C:\Programfiler\iTunes\iTunesHelper.exe

C:\Programfiler\Fellesfiler\Error Safe\erscw.exe

C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\Messenger\msmsgs.exe

C:\Programfiler\AnyDVD\AnyDVD.exe

C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\Logitech\MouseWare\system\em_exec.exe

C:\WINDOWS\system32\svchost.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\RunDll32.exe

C:\DOCUME~1\HVARDK~1\LOKALE~1\Temp\Set3.tmp

C:\DOCUME~1\HVARDK~1\LOKALE~1\Temp\Set3.tmp

E:\clean_box\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILE...s0p0O2t8dizZHOC

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=wKX1ILE...ccR6flAnJF1NpUE

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O3 - Toolbar: (no name) - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - (no file)

O4 - HKLM\..\Run: [bCMSMMSG] BCMSMMSG.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe

O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Programfiler\LogMeIn\LogMeInSystray.exe"

O4 - HKLM\..\Run: [FreeBBAccess] C:\Program Files\FBB\FreeBBAccess\FreeBBAccess.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [erscw] C:\Programfiler\Fellesfiler\Error Safe\erscw.exe -c

O4 - HKLM\..\Run: [WlanUI] "C:\Programfiler\3COM\3Com Wireless 108 Mbps 11g USB Utility \WlanUI.exe" -nogui

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [AnyDVD] C:\Programfiler\AnyDVD\AnyDVD.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [Error Safe] "C:\Programfiler\Error Safe Free\ers.exe" /min

O4 - HKCU\..\Run: [AdwareProtector] C:\Programfiler\Error Safe\AdwareProtector.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Programfiler\Video Add-on\isfmntr.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Google Search - res://c:\programfiler\google\GoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: &Translate English Word - res://c:\programfiler\google\GoogleToolbar2.dll/cmwordtrans.html

O8 - Extra context menu item: Backward Links - res://c:\programfiler\google\GoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programfiler\google\GoogleToolbar2.dll/cmcache.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://c:\programfiler\google\GoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate Page into English - res://c:\programfiler\google\GoogleToolbar2.dll/cmtrans.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programfiler\nordicbetMPP\MPPoker.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O15 - Trusted Zone: http://www.download.com

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0046C4.dat

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: 3Com Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe

O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe

 

--

End of file - 7160 bytes

 

SAS_logg:

 

Klikk for å se/fjerne spoilerteksten nedenfor

SUPERAntiSpyware Scan Log

http://www.superantispyware.com

 

Generated 02/02/2008 at 06:11 PM

 

Application Version : 3.9.1008

 

Core Rules Database Version : 3394

Trace Rules Database Version: 1386

 

Scan type : Complete Scan

Total Scan Time : 00:25:52

 

Memory items scanned : 207

Memory threats detected : 0

Registry items scanned : 5391

Registry threats detected : 738

File items scanned : 27182

File threats detected : 354

 

Malware.VirusProtect

[VirusProtect 3.8] C:\PROGRAMFILER\VIRUSPROTECT 3.8\VIRUSPROTECT 3.8.EXE

C:\PROGRAMFILER\VIRUSPROTECT 3.8\VIRUSPROTECT 3.8.EXE

HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\VirusProtect 3.8.exe 3.8

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\Control

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\gdSunfeg

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\InprocServer32

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\InprocServer32#InprocServer32

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\InprocServer32#ThreadingModel

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\MiscStatus

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\MiscStatus\1

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\omtFah

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\ProgID

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\RwVqqSyQVe

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\szZcwulWlvk

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\ToolboxBitmap32

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\TypeLib

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\UcXilulPysmr

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\Version

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\VersionIndependentProgID

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\wjwq

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\wtImonnayggvp

HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\xkunxwc

HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}

HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0

HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0

HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0\win32

HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0\FLAGS

HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0\HELPDIR

HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}

HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}\ProxyStubClsid

HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}\ProxyStubClsid32

HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}\TypeLib

HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}\TypeLib#Version

HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}

HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}\ProxyStubClsid

HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}\ProxyStubClsid32

HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}\TypeLib

HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}\TypeLib#Version

HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}

HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}\ProxyStubClsid

HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}\ProxyStubClsid32

HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}\TypeLib

HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}\TypeLib#Version

HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}

HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}\ProxyStubClsid

HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}\ProxyStubClsid32

HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}\TypeLib

HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}\TypeLib#Version

HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}

HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}\ProxyStubClsid

HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}\ProxyStubClsid32

HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}\TypeLib

HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}\TypeLib#Version

HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}

HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}\ProxyStubClsid

HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}\ProxyStubClsid32

HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}\TypeLib

HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}\TypeLib#Version

HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}

HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}\ProxyStubClsid

HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}\ProxyStubClsid32

HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}\TypeLib

HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}\TypeLib#Version

HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}

HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}\ProxyStubClsid

HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}\ProxyStubClsid32

HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}\TypeLib

HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}\TypeLib#Version

HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}

HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}\ProxyStubClsid

HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}\ProxyStubClsid32

HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}\TypeLib

HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}\TypeLib#Version

HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}

HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}\ProxyStubClsid

HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}\ProxyStubClsid32

HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}\TypeLib

HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}\TypeLib#Version

HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}

HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}\ProxyStubClsid

HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}\ProxyStubClsid32

HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}\TypeLib

HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}\TypeLib#Version

HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}

HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}\ProxyStubClsid

HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}\ProxyStubClsid32

HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}\TypeLib

HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}\TypeLib#Version

HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}

HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}\ProxyStubClsid

HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}\ProxyStubClsid32

HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}\TypeLib

HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}\TypeLib#Version

HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}

HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}\ProxyStubClsid

HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}\ProxyStubClsid32

HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}\TypeLib

HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}\TypeLib#Version

HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}

HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}\ProxyStubClsid

HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}\ProxyStubClsid32

HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}\TypeLib

HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}\TypeLib#Version

HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}

HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}\ProxyStubClsid

HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}\ProxyStubClsid32

HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}\TypeLib

HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}\TypeLib#Version

HKLM\Software\VirusProtect 3.8

HKLM\Software\VirusProtect 3.8#refid

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#UninstallString

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#DisplayIcon

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#DisplayVersion

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#NSIS:StartMenuDir

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#URLInfoAbout

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#Publisher

HKLM\Software\Microsoft\Windows\CurrentVersion\Run#VirusProtect 3.8 [ "C:\Programfiler\VirusProtect 3.8\VirusProtect 3.8.exe" /h ]

C:\Programfiler\VirusProtect 3.8\blacklist.txt

C:\Programfiler\VirusProtect 3.8\ignored.lst

C:\Programfiler\VirusProtect 3.8\Lang\English.ini

C:\Programfiler\VirusProtect 3.8\Lang

C:\Programfiler\VirusProtect 3.8\Logs

C:\Programfiler\VirusProtect 3.8\msvcp71.dll

C:\Programfiler\VirusProtect 3.8\msvcr71.dll

C:\Programfiler\VirusProtect 3.8\Quarantine

C:\Programfiler\VirusProtect 3.8\uninst.exe

C:\Programfiler\VirusProtect 3.8\VirusProtect 3.8.url

C:\Programfiler\VirusProtect 3.8\vp.dat

C:\Programfiler\VirusProtect 3.8\vpp.ini

C:\Programfiler\VirusProtect 3.8

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\PROGRAMDATA\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\VIRUSPROTECT 3.8.LNK

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\START-MENY\PROGRAMMER\VIRUSPROTECT 3.8\UNINSTALL VIRUSPROTECT 3.8.LNK

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\START-MENY\PROGRAMMER\VIRUSPROTECT 3.8\VIRUSPROTECT 3.8.LNK

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\START-MENY\VIRUSPROTECT 3.8.LNK

C:\WINDOWS\Prefetch\VIRUSPROTECT 3.8.EXE-2E7F597A.pf

 

Adware.Zango Toolbar/Hb

HKLM\Software\Classes\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}

HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}

HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}

HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\InprocServer32

HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\InprocServer32#ThreadingModel

HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\ProgID

HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\Programmable

HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\TypeLib

HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\VersionIndependentProgID

C:\PROGRAMFILER\ZANGO\BIN\10.0.314.0\HOSTIE.DLL

HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07AA283A-43D7-4CBE-A064-32A21112D94D}

HKCR\HostIE.Bho.1

HKCR\HostIE.Bho.1\CLSID

HKCR\HostIE.Bho

HKCR\HostIE.Bho\CLSID

HKCR\HostIE.Bho\CurVer

HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}

HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0

HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0

HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\win32

HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\FLAGS

HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\HELPDIR

HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}

HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\InprocServer32

HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\InprocServer32#ThreadingModel

HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\ProgID

HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\Programmable

HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\TypeLib

HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\VersionIndependentProgID

HKCR\HbCoreSrv.DynamicProp

HKCR\HbCoreSrv.DynamicProp\CLSID

HKCR\HbCoreSrv.DynamicProp\CurVer

HKCR\HbCoreSrv.DynamicProp.1

HKCR\HbCoreSrv.DynamicProp.1\CLSID

HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}

HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}\ProxyStubClsid

HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}\ProxyStubClsid32

HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}\TypeLib

HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}\TypeLib#Version

HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}

HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}\ProxyStubClsid

HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}\ProxyStubClsid32

HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}\TypeLib

HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}\TypeLib#Version

HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}

HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}\ProxyStubClsid

HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}\ProxyStubClsid32

HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}\TypeLib

HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}\TypeLib#Version

HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}

HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\ProxyStubClsid

HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\ProxyStubClsid32

HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\TypeLib

HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\TypeLib#Version

HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}

HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\ProxyStubClsid

HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\ProxyStubClsid32

HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\TypeLib

HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\TypeLib#Version

HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}

HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\ProxyStubClsid

HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\ProxyStubClsid32

HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\TypeLib

HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\TypeLib#Version

HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}

HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\ProxyStubClsid

HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\ProxyStubClsid32

HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\TypeLib

HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\TypeLib#Version

HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}

HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\ProxyStubClsid

HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\ProxyStubClsid32

HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\TypeLib

HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\TypeLib#Version

HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}

HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}\ProxyStubClsid

HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}\ProxyStubClsid32

HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}\TypeLib

HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}\TypeLib#Version

HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}

HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\ProxyStubClsid

HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\ProxyStubClsid32

HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\TypeLib

HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\TypeLib#Version

HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}

HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}\ProxyStubClsid

HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}\ProxyStubClsid32

HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}\TypeLib

HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}\TypeLib#Version

HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}

HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}\ProxyStubClsid

HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}\ProxyStubClsid32

HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}\TypeLib

HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}\TypeLib#Version

HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}

HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\ProxyStubClsid

HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\ProxyStubClsid32

HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\TypeLib

HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\TypeLib#Version

HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}

HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\ProxyStubClsid

HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\ProxyStubClsid32

HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\TypeLib

HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\TypeLib#Version

HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}

HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\ProxyStubClsid

HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\ProxyStubClsid32

HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\TypeLib

HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\TypeLib#Version

HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}

HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}\ProxyStubClsid

HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}\ProxyStubClsid32

HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}\TypeLib

HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}\TypeLib#Version

HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}

HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}\ProxyStubClsid

HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}\ProxyStubClsid32

HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}\TypeLib

HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}\TypeLib#Version

HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}

HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\ProxyStubClsid

HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\ProxyStubClsid32

HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\TypeLib

HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\TypeLib#Version

HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}

HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\ProxyStubClsid

HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\ProxyStubClsid32

HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\TypeLib

HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\TypeLib#Version

HKCR\CoreSrv.CoreServices

HKCR\CoreSrv.CoreServices\CLSID

HKCR\CoreSrv.CoreServices\CurVer

HKCR\CoreSrv.CoreServices.1

HKCR\CoreSrv.CoreServices.1\CLSID

HKCR\CoreSrv.LfgAx

HKCR\CoreSrv.LfgAx\CLSID

HKCR\CoreSrv.LfgAx\CurVer

HKCR\CoreSrv.LfgAx.1

HKCR\CoreSrv.LfgAx.1\CLSID

HKCR\HBMain.CommBand

HKCR\HBMain.CommBand\CLSID

HKCR\HBMain.CommBand\CurVer

HKCR\HBMain.CommBand.1

HKCR\HBMain.CommBand.1\CLSID

HKCR\hbr.HbMain

HKCR\hbr.HbMain\CLSID

HKCR\hbr.HbMain\CurVer

HKCR\hbr.HbMain.1

HKCR\hbr.HbMain.1\CLSID

HKCR\HostOL.MailAnim

HKCR\HostOL.MailAnim\CLSID

HKCR\HostOL.MailAnim\CurVer

HKCR\HostOL.MailAnim.1

HKCR\HostOL.MailAnim.1\CLSID

HKCR\HostOL.WebmailSend

HKCR\HostOL.WebmailSend\CLSID

HKCR\HostOL.WebmailSend\CurVer

HKCR\HostOL.WebmailSend.1

HKCR\HostOL.WebmailSend.1\CLSID

HKCR\InstIE.HbInstObj

HKCR\InstIE.HbInstObj\CLSID

HKCR\InstIE.HbInstObj\CurVer

HKCR\InstIE.HbInstObj.1

HKCR\InstIE.HbInstObj.1\CLSID

HKCR\Srv.CoreServices

HKCR\Srv.CoreServices\CLSID

HKCR\Srv.CoreServices\CurVer

HKCR\Srv.CoreServices.1

HKCR\Srv.CoreServices.1\CLSID

HKCR\Toolbar.HtmlMenuUI

HKCR\Toolbar.HtmlMenuUI\CLSID

HKCR\Toolbar.HtmlMenuUI\CurVer

HKCR\Toolbar.HtmlMenuUI.1

HKCR\Toolbar.HtmlMenuUI.1\CLSID

HKCR\Toolbar.ToolbarCtl

HKCR\Toolbar.ToolbarCtl\CLSID

HKCR\Toolbar.ToolbarCtl\CurVer

HKCR\Toolbar.ToolbarCtl.1

HKCR\Toolbar.ToolbarCtl.1\CLSID

HKCR\Zango.DesktopFlash

HKCR\Zango.DesktopFlash\CLSID

HKCR\Zango.DesktopFlash\CurVer

HKCR\Zango.DesktopFlash.1

HKCR\Zango.DesktopFlash.1\CLSID

HKCR\ZangoAX.ClientDetector

HKCR\ZangoAX.ClientDetector\CLSID

HKCR\ZangoAX.ClientDetector\CurVer

HKCR\ZangoAX.ClientDetector.1

HKCR\ZangoAX.ClientDetector.1\CLSID

HKCR\ZangoAX.UserProfiles

HKCR\ZangoAX.UserProfiles\CLSID

HKCR\ZangoAX.UserProfiles\CurVer

HKCR\ZangoAX.UserProfiles.1

HKCR\ZangoAX.UserProfiles.1\CLSID

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\Control

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\InprocServer32

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\InprocServer32#ThreadingModel

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\MiscStatus

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\MiscStatus\1

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\ProgID

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\Programmable

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\ToolboxBitmap32

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\TypeLib

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\Version

HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\VersionIndependentProgID

HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}

HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\InprocServer32

HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\InprocServer32#ThreadingModel

HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\ProgID

HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\Programmable

HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\TypeLib

HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\VersionIndependentProgID

HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}

HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\InprocServer32

HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\InprocServer32#ThreadingModel

HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\ProgID

HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\Programmable

HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\TypeLib

HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\VersionIndependentProgID

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\Control

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\InprocServer32

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\InprocServer32#ThreadingModel

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\MiscStatus

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\MiscStatus\1

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\ProgID

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\Programmable

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\ToolboxBitmap32

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\TypeLib

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\Version

HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\VersionIndependentProgID

HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}

HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\LocalServer32

HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\ProgID

HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\Programmable

HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\TypeLib

HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\VersionIndependentProgID

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\Control

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\InprocServer32

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\InprocServer32#ThreadingModel

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\ProgID

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\Programmable

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\ToolboxBitmap32

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\TypeLib

HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\VersionIndependentProgID

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}#AppID

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Control

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Implemented Categories

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\InprocServer32

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\InprocServer32#ThreadingModel

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\MiscStatus

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\MiscStatus\1

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\ProgID

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Programmable

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\ToolboxBitmap32

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\TypeLib

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Version

HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\VersionIndependentProgID

HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}

HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\InprocServer32

HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\InprocServer32#ThreadingModel

HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\ProgID

HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\Programmable

HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\TypeLib

HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\VersionIndependentProgID

HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}

HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}#AppID

HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\LocalServer32

HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\ProgID

HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\Programmable

HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\TypeLib

HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\VersionIndependentProgID

HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}

HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}\Implemented Categories

HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}\Implemented Categories\{A87F4ED6-CCC0-47C2-92EB-B3AD853B5D5F}

HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}

HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\InprocServer32

HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\InprocServer32#ThreadingModel

HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\ProgID

HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\Programmable

HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\TypeLib

HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\VersionIndependentProgID

HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}

HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\InprocServer32

HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\InprocServer32#ThreadingModel

HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\ProgID

HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\TypeLib

HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\VersionIndependentProgID

HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}

HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\InprocServer32

HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\InprocServer32#ThreadingModel

HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\ProgID

HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\Programmable

HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\TypeLib

HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\VersionIndependentProgID

HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}

HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0

HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0

HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\win32

HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\FLAGS

HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\HELPDIR

HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}

HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0

HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0

HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\win32

HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\FLAGS

HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\HELPDIR

HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}

HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0

HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0

HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\win32

HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\FLAGS

HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\HELPDIR

HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}

HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0

HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0

HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\win32

HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\FLAGS

HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\HELPDIR

HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}

HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0

HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0

HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0\win32

HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0\FLAGS

HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0\HELPDIR

HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}

HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0

HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0

HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\win32

HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\FLAGS

HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\HELPDIR

HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}

HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0

HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0

HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0\win32

HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0\FLAGS

HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0\HELPDIR

HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}

HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\ProxyStubClsid

HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\ProxyStubClsid32

HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\TypeLib

HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\TypeLib#Version

HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}

HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\ProxyStubClsid

HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\ProxyStubClsid32

HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\TypeLib

HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\TypeLib#Version

HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}

HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\ProxyStubClsid

HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\ProxyStubClsid32

HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\TypeLib

HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\TypeLib#Version

HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}

HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}\ProxyStubClsid

HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}\ProxyStubClsid32

HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}\TypeLib

HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}\TypeLib#Version

HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}

HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\ProxyStubClsid

HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\ProxyStubClsid32

HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\TypeLib

HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\TypeLib#Version

HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}

HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\ProxyStubClsid

HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\ProxyStubClsid32

HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\TypeLib

HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\TypeLib#Version

HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}

HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\ProxyStubClsid

HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\ProxyStubClsid32

HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\TypeLib

HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\TypeLib#Version

HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}

HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\ProxyStubClsid

HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\ProxyStubClsid32

HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\TypeLib

HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\TypeLib#Version

HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}

HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid

HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid32

HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib

HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib#Version

HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}

HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\ProxyStubClsid

HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\ProxyStubClsid32

HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\TypeLib

HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\TypeLib#Version

HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}

HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\ProxyStubClsid

HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\ProxyStubClsid32

HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\TypeLib

HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\TypeLib#Version

HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}

HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\ProxyStubClsid

HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\ProxyStubClsid32

HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\TypeLib

HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\TypeLib#Version

HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}

HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\ProxyStubClsid

HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\ProxyStubClsid32

HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\TypeLib

HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\TypeLib#Version

HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}

HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\ProxyStubClsid

HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\ProxyStubClsid32

HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\TypeLib

HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\TypeLib#Version

HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}

HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\ProxyStubClsid

HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\ProxyStubClsid32

HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\TypeLib

HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\TypeLib#Version

HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}

HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\ProxyStubClsid

HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\ProxyStubClsid32

HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\TypeLib

HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\TypeLib#Version

HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}

HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\ProxyStubClsid

HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\ProxyStubClsid32

HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\TypeLib

HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\TypeLib#Version

HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}

HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\ProxyStubClsid

HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\ProxyStubClsid32

HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\TypeLib

HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\TypeLib#Version

HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}

HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\ProxyStubClsid

HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\ProxyStubClsid32

HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\TypeLib

HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\TypeLib#Version

HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}

HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\ProxyStubClsid

HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\ProxyStubClsid32

HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\TypeLib

HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\TypeLib#Version

HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}

HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\ProxyStubClsid

HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\ProxyStubClsid32

HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\TypeLib

HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\TypeLib#Version

HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}

HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\ProxyStubClsid

HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\ProxyStubClsid32

HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\TypeLib

HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\TypeLib#Version

HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}

HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\ProxyStubClsid

HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\ProxyStubClsid32

HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\TypeLib

HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\TypeLib#Version

HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}

HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\ProxyStubClsid

HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\ProxyStubClsid32

HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\TypeLib

HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\TypeLib#Version

HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}

HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\ProxyStubClsid

HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\ProxyStubClsid32

HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\TypeLib

HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\TypeLib#Version

HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}

HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid

HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid32

HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib

HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib#Version

HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}

HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid

HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid32

HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib

HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib#Version

HKCR\AppId\ZangoSA_df.exe

HKCR\AppId\ZangoSA_df.exe#AppID

HKCR\AppId\{DBF00E12-281C-4dc8-A7EC-1FF45182439B}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayIcon

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#UninstallString

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayVersion

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#HelpLink

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#Publisher

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#URLInfoAbout

 

Trojan.Smitfraud Variant

HKLM\Software\Classes\CLSID\{3750da11-9b0c-4a75-9c8a-bbcbfcd1ccea}

HKCR\CLSID\{3750DA11-9B0C-4A75-9C8A-BBCBFCD1CCEA}

HKCR\CLSID\{3750DA11-9B0C-4A75-9C8A-BBCBFCD1CCEA}\InProcServer32

HKCR\CLSID\{3750DA11-9B0C-4A75-9C8A-BBCBFCD1CCEA}\InProcServer32#ThreadingModel

C:\WINDOWS\SYSTEM32\FFTKTMK.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{3750da11-9b0c-4a75-9c8a-bbcbfcd1ccea}

 

Adware.Vundo Variant

HKLM\Software\Classes\CLSID\{51EB01ED-205E-4818-B024-AFACA970EC37}

HKCR\CLSID\{51EB01ED-205E-4818-B024-AFACA970EC37}

HKCR\CLSID\{51EB01ED-205E-4818-B024-AFACA970EC37}\InprocServer32

HKCR\CLSID\{51EB01ED-205E-4818-B024-AFACA970EC37}\InprocServer32#ThreadingModel

C:\WINDOWS\SYSTEM32\OPPPP.DLL

Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\opppp

 

Unclassified.Unknown Origin

HKLM\Software\Classes\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}

HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}

HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}

HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}\InprocServer32

HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}\InprocServer32#ThreadingModel

C:\DOCUME~1\HVARDK~1\LOKALE~1\TEMP\~DP146.DLL

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\~DP146.DLL

 

Adware.Vundo-Variant/Small-A

HKLM\Software\Classes\CLSID\{8dbdc4a8-b382-48a0-9a87-1c72b0c6635a}

HKCR\CLSID\{8DBDC4A8-B382-48A0-9A87-1C72B0C6635A}

HKCR\CLSID\{8DBDC4A8-B382-48A0-9A87-1C72B0C6635A}\InprocServer32

HKCR\CLSID\{8DBDC4A8-B382-48A0-9A87-1C72B0C6635A}\InprocServer32#ThreadingModel

C:\WINDOWS\SYSTEM32\KBXGFNIG.DLL

C:\WINDOWS\SYSTEM32\AEVKGHRP.DLL

C:\WINDOWS\SYSTEM32\BDPTHQVQ.DLL

C:\WINDOWS\SYSTEM32\CUSBAHJM.DLL

C:\WINDOWS\SYSTEM32\FHMBKLMS.DLL

C:\WINDOWS\SYSTEM32\FNYFAOTR.DLL

C:\WINDOWS\SYSTEM32\GQYSPPWE.DLL

C:\WINDOWS\SYSTEM32\GUMFMDUB.DLL

C:\WINDOWS\SYSTEM32\IQQJVSWP.DLL

C:\WINDOWS\SYSTEM32\KJFAYNPX.DLL

C:\WINDOWS\SYSTEM32\LQUVGAON.DLL

C:\WINDOWS\SYSTEM32\MJBNLIIB.DLL

C:\WINDOWS\SYSTEM32\NJQUNGLS.DLL

C:\WINDOWS\SYSTEM32\ONKMUQMD.DLL

C:\WINDOWS\SYSTEM32\QXDGKEXT.DLL

C:\WINDOWS\SYSTEM32\RXSKREGS.DLL

C:\WINDOWS\SYSTEM32\WDCREEVW.DLL

C:\WINDOWS\SYSTEM32\WKIXDUUE.DLL

C:\WINDOWS\SYSTEM32\WMDDTQEB.DLL

C:\WINDOWS\SYSTEM32\XVGJUNPO.DLL

C:\WINDOWS\SYSTEM32\YPUFYKGB.DLL

 

Adware.HotBar/SpamBlockerUtility (Low Risk)

HKLM\Software\Classes\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Control

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Implemented Categories

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Implemented Categories\{00021494-0000-0000-C000-000000000046}

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\InprocServer32

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\InprocServer32#ThreadingModel

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Instance

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Instance#CLSID

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Instance\InitPropertyBag

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Instance\InitPropertyBag#Url

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\MiscStatus

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\MiscStatus\1

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\ProgID

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Programmable

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\ToolboxBitmap32

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\TypeLib

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Version

HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\VersionIndependentProgID

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}

 

Adware.Starware

HKCR\CLSID\{45A4902E-4479-4EAE-A186-8D0F7E4C78DE}

HKCR\CLSID\{45A4902E-4479-4EAE-A186-8D0F7E4C78DE}\InprocServer32

HKCR\CLSID\{45A4902E-4479-4EAE-A186-8D0F7E4C78DE}\InprocServer32#ThreadingModel

HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}

HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}\Implemented Categories

HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}\Implemented Categories\{00021493-0000-0000-C000-000000000046}

HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}\InprocServer32

HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}\InprocServer32#ThreadingModel

HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}

HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}\Implemented Categories

HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}\Implemented Categories\{00021494-0000-0000-C000-000000000046}

HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}\InprocServer32

HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}\InprocServer32#ThreadingModel

HKCR\CLSID\{9FB3908C-6565-4CB0-95F8-E9F85258723C}

HKCR\CLSID\{9FB3908C-6565-4CB0-95F8-E9F85258723C}\InprocServer32

HKCR\CLSID\{9FB3908C-6565-4CB0-95F8-E9F85258723C}\InprocServer32#ThreadingModel

 

Adware.180solutions/ZangoSearch

C:\Programfiler\Zango\bin\10.0.314.0\arrow.ico

C:\Programfiler\Zango\bin\10.0.314.0\copyright.txt

C:\Programfiler\Zango\bin\10.0.314.0\CoreSrv.dll

C:\Programfiler\Zango\bin\10.0.314.0\dBenderC.dll

C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\components\npclntax.xpt

C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\components

C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\install.rdf

C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\plugins\npclntax_ZangoSA.dll

C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\plugins

C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions

C:\Programfiler\Zango\bin\10.0.314.0\firefox

C:\Programfiler\Zango\bin\10.0.314.0\HostOE.dll

C:\Programfiler\Zango\bin\10.0.314.0\HostOL.dll

C:\Programfiler\Zango\bin\10.0.314.0\InstIE.dll

C:\Programfiler\Zango\bin\10.0.314.0\link.ico

C:\Programfiler\Zango\bin\10.0.314.0\OEAddOn.exe

C:\Programfiler\Zango\bin\10.0.314.0\Srv.exe

C:\Programfiler\Zango\bin\10.0.314.0\Toolbar.dll

C:\Programfiler\Zango\bin\10.0.314.0\Wallpaper.dll

C:\Programfiler\Zango\bin\10.0.314.0\ZangoSAAX.dll

C:\Programfiler\Zango\bin\10.0.314.0\ZangoSADF.exe

C:\Programfiler\Zango\bin\10.0.314.0\ZangoSAHook.dll

C:\Programfiler\Zango\bin\10.0.314.0\ZangoUnInstaller.exe

C:\Programfiler\Zango\bin\10.0.314.0

C:\Programfiler\Zango\bin

C:\Programfiler\Zango

C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Reset Cursor.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Customer Support Center.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Games!.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Library.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Screensavers!.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Uninstall Instructions.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Videos!.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Zango

HKLM\Software\Zango

HKLM\Software\Zango\Install

HKLM\Software\Zango\Install#IE

HKLM\Software\Zango\Install#OL

HKLM\Software\Zango\Install#WT

HKLM\Software\Zango\Install#WP

HKLM\Software\Zango\Install#Install_Dir

HKLM\Software\Zango\Install#Installed_From

HKLM\Software\Zango\Install#SA

HKLM\Software\Zango\Install\CmpMap

HKLM\Software\Zango\Install\CmpMap#IE

HKLM\Software\Zango\Install\CmpMap#OL

HKLM\Software\Zango\Install\CmpMap#WT

HKLM\Software\Zango\Install\CmpMap#WP

HKLM\Software\Zango\Install\CmpMap#SA

HKLM\Software\Zango\Zango

HKLM\Software\Zango\Zango\Install

HKLM\Software\Zango\Zango\Install#StartInstall

HKLM\Software\Zango\Zango\Install#cookies_flag

HKLM\Software\Zango\Zango\Install#IID

HKLM\Software\Zango\Zango\Install#IID_prv

HKLM\Software\Zango\Zango\Install#PrevVer

HKLM\Software\Zango\Zango\Install#CurrentVer

HKLM\Software\Zango\Zango\Install#CreateDate

HKLM\Software\Zango\Zango\Install#CreateDateDW

HKLM\Software\Zango\Zango\Install#icons_flag

HKLM\Software\Zango\Zango\Install#HbHostOEPath

HKLM\Software\Zango\Zango\MachineInfo

HKLM\Software\Zango\Zango\MachineInfo#CID

HKLM\Software\Zango\Zango\MachineInfo#CID_prv

HKLM\Software\Zango\Zango\PI

HKLM\Software\Zango\Zango\PI\3.2

HKLM\Software\Zango\Zango\PI\3.2#PID00

HKLM\Software\Zango\Zango\Updates

HKLM\Software\Zango\Zango\Updates#InstallDate

C:\WINDOWS\Prefetch\SRV.EXE-1E1C9A5F.pf

 

Trojan.Error Safe Free

C:\Programfiler\Error Safe Free

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: Setup Version

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: App Path

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#InstallLocation

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: Icon Group

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: User

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#UninstallString

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#QuietUninstallString

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Publisher

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#URLInfoAbout

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#HelpLink

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#URLUpdateInfo

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#NoModify

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#NoRepair

 

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007

HKCR\CLSID\{_CLSID_WAShellExecuteCheck}

HKCR\CLSID\{_CLSID_WAShellExecuteCheck}#AppID

HKCR\CLSID\{_CLSID_WAShellExecuteCheck}\LocalServer32

HKCR\CLSID\{_CLSID_WAShellExecuteCheck}\Programmable

HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}

HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0

HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0

HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0\win32

HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0\FLAGS

HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0\HELPDIR

HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}

HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}\ProxyStubClsid

HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}\ProxyStubClsid32

HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}\TypeLib

HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}\TypeLib#Version

 

Trojan.Security Toolbar

C:\Documents and Settings\All Users\Start-meny\Online Security Guide.url

C:\Documents and Settings\All Users\Start-meny\Security Troubleshooting.url

 

Trojan.ErrorSafe

C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Avisntallerer ErrorSafe.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Error Safe på nett.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Error Safe.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Ta kontakt med kundestøtten.lnk

C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\ERS64.EXE

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\NI.ERSH_0001_N68E0602\SETUP.EXE

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\NI.UERSH_0001_N91M2407\SETUP.EXE

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\PROGRAMDATA\ERRORSAFEFREEINSTALL_NO[1].EXE

C:\WINDOWS\SYSTEM32\ERRORSAFESETUP.EXE

 

Malware.SpyLocked

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#UninstallString

 

Trojan.Media-Codec/V4

C:\Programfiler\Video Add-on\isfmm.exe

C:\Programfiler\Video Add-on\ot.ico

C:\Programfiler\Video Add-on\ts.ico

C:\Programfiler\Video Add-on\uninst.exe

C:\Programfiler\Video Add-on

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#ProductionEnvironment

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayName

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#Publisher

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#UninstallString

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayIcon

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayVersion

HKCR\multimediaControls.chl

HKCR\multimediaControls.chl\CLSID

 

Adware.Tracking Cookie

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@2o7[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][10].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][11].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][13].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][4].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][5].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][6].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][7].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][8].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][9].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adbrite[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adinterax[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adrevolver[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adserver[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adtech[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adultadworld[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adultfriendfinder[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@advertising[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@advertising[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@advertising[3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@advertising[4].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@amsterdamlivexxx[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@apmebf[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@atdmt[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@bizadverts[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@camsexnow[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@casalemedia[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@casalemedia[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@casalemedia[3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@casalemedia[5].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@cassava[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@clicktorrent[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@countercentral[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@cpvfeed[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@doubleclick[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@drivecleaner[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@eroticlick[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@fastclick[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@fastclick[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@freepornlessons[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@fuckeduphandjobs[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@hitbox[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@indexstats[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@indextools[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@indextools[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@jays-xxx-links[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@jesextender[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][4].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][5].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][7].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@mediaplex[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@partner2profit[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@partypoker[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@popularscreensavers[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@porn365[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@pornenmeer[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@pornotube[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@questionmarket[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@realmedia[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@revenue[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@revsci[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@serving-sys[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@serving-sys[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@serving-sys[3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@serving-sys[4].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@sexlive2u[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@sextv1[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@socialmedia[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@specificclick[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@spylog[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@spylog[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@starware[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@statcounter[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@statcounter[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@tacoda[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@toplist[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][10].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][11].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][12].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][13].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][14].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][15].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][16].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][17].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][18].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][19].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][20].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][21].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][22].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][23].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][24].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][25].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][26].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][27].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][28].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][29].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][30].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][31].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][32].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][4].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][5].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][6].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][7].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][8].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][9].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@tradedoubler[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@usenext[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@whatpornsite[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@winantivirus[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@xxx[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@yourmedia[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@zedo[1].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@zedo[2].txt

C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@zedo[3].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@2o7[2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@adtech[2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@advertising[2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@atdmt[2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@atwola[1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@doubleclick[1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@drivecleaner[1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@mediaplex[1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@serving-sys[2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@specificclick[1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@spylog[1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@statcounter[1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@tacoda[2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@tradedoubler[2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@tribalfusion[1].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@winantivirus[2].txt

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@zedo[2].txt

 

Browser Hijacker.Favorites

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\FAVORITTER\ONLINE SECURITY TEST.URL

 

Trojan.Unclassifed/LAF-Variant

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\LAF1.EXE

 

Trojan.WinAntiSpyware/WinAntiVirus 2006

C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\PROGRAMDATA\WINANTIVIRUSPRO2006FREEINSTALL_NO[1].EXE

C:\PROGRAMFILER\ERROR SAFE\WASFFNT.EXE

C:\WINDOWS\Prefetch\WASFFNT.EXE-15C2DB2C.pf

 

Trojan.WinFixer

C:\PROGRAMFILER\ERROR SAFE\ADWAREPROTECTOR.EXE

C:\WINDOWS\Prefetch\ADWAREPROTECTOR.EXE-0D4334C9.pf

 

Adware.Vundo-Variant

C:\WINDOWS\SYSTEM32\BBWPCFPJ.DLL

C:\WINDOWS\SYSTEM32\NOEEIHEG.DLL

C:\WINDOWS\SYSTEM32\RYVWJAVA.DLL

C:\WINDOWS\SYSTEM32\WUWGSLDX.DLL

 

Trace.Known Threat Sources

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C1MJ41QN\g_head_top[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C5IF8T6F\g_bottom[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\SH2RSPMJ\bt_scan[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\452NCHEV\box[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C1MJ41QN\bt_buy_now[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\452NCHEV\footer_bg[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C5IF8T6F\header_bg_top[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C1MJ41QN\top_box_bg[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\SH2RSPMJ\header2_bg[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\452NCHEV\circle[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\APSNW7UN\scns[1].gif

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\CZKZYV8B\order[1].htm

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\CZKZYV8B\updates.errorsafe[1].0&ac=e33a0991-c63b-4319-841a-d1dde52e0b99&oid=3941993&suspicious=0&appid=ERSH&em=060f0b07000d032402161a190d5208441a0119

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temporary Internet Files\Content.IE5\9AKUM5FG\dbver[1].dat

 

Lenke til kommentar
Videoannonse
Annonse

Start hjt, velg "Do a system scan only", sett merke framfor følgende linjer og klikk Fix checked:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILE...s0p0O2t8dizZHOC

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=wKX1ILE...ccR6flAnJF1NpUE

O3 - Toolbar: (no name) - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - (no file)

O4 - HKLM\..\Run: [FreeBBAccess] C:\Program Files\FBB\FreeBBAccess\FreeBBAccess.exe

O4 - HKLM\..\Run: [erscw] C:\Programfiler\Fellesfiler\Error Safe\erscw.exe -c

O4 - HKCU\..\Run: [Error Safe] "C:\Programfiler\Error Safe Free\ers.exe" /min

O4 - HKCU\..\Run: [AdwareProtector] C:\Programfiler\Error Safe\AdwareProtector.exe

O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Programfiler\Video Add-on\isfmntr.exe

O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0046C4.dat

 

 

Hent Combofix, og legg det på skrivebordet

 

Kjør combofix.exe, og følg veiledningen.

 

Post loggfilen fra combofix (c:\combofix.txt)

Lenke til kommentar

HJT-logg her: Tusen riktig takk for hjelpen ;)

 

 

 

ComboFix 08-02.03.1 - Håvard Karlsnes 2008-02-03 11:07:00.1 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.687 [GMT 1:00]

Running from: E:\clean_box\ComboFix.exe

* Created a new restore point

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\All Users\Programdata\Microsoft\Network\Downloader\qmgr0.dat

C:\Documents and Settings\All Users\Programdata\Microsoft\Network\Downloader\qmgr1.dat

C:\Documents and Settings\Håvard Karlsnes\err.log

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\BrowserSearch\BrowserSearch.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\BrowserSearch\BrowserSearch.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Configurator\Configurator.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Configurator\Configurator.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ErrorSearch\ErrorSearchOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ErrorSearch\ErrorSearchOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Games\GamesOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Games\GamesOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\PitchLayout.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\PitchLayout.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\ToolbarLayout.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\ToolbarLayout.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\WeatherLayout.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\WeatherLayout.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Manager\ManagerOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Manager\ManagerOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Movies\MoviesOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Movies\MoviesOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Reference\ReferenceOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Reference\ReferenceOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\RelatedSearch\RelatedSearchOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\RelatedSearch\RelatedSearchOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Screensavers\ScreensaversOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Screensavers\ScreensaversOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\SearchAssistPlus\SearchAssistPlusOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\SearchAssistPlus\SearchAssistPlusOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\SearchMatch\SearchMatchOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\SearchMatch\SearchMatchOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Tem1CA.tmp

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Toolbar\TBProductsOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Toolbar\TBProductsOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ToolbarLogo\ToolbarLogoOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ToolbarLogo\ToolbarLogoOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ToolbarSearch\ToolbarSearchOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ToolbarSearch\ToolbarSearchOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\TravelSearch\TravelSearchOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\TravelSearch\TravelSearchOptions.xml.backup

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Weather\AlertArchive.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Weather\WeatherOptions.xml

C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Weather\WeatherOptions.xml.backup

C:\Programfiler\screensavers.com

C:\Programfiler\screensavers.com\SSSInst\bin\iebyterange.xml

C:\Programfiler\screensavers.com\SSSInst\bin\iebyterange.xml.backup

C:\Programfiler\screensavers.com\SSSInst\bin\SSSInst.dll

C:\Programfiler\screensavers.com\SSSInst\bin\SSSUninst.exe

C:\Programfiler\screensavers.com\Wallpaper\swpstart.exe

C:\Programfiler\Starware316

C:\Programfiler\Starware316\brand.bmp

C:\Programfiler\Starware316\icons\star_16.ico

C:\Programfiler\Starware316\Starware316Config.xml

C:\Programfiler\Starware316\Starware316Uninstall.exe

C:\WINDOWS\cookies.ini

C:\WINDOWS\system32\__c0022960.dat

C:\WINDOWS\system32\__c002324A.dat

C:\WINDOWS\system32\__c0023F21.dat

C:\WINDOWS\system32\__c0025266.dat

C:\WINDOWS\system32\__c0035220.dat

C:\WINDOWS\system32\__c0042E52.dat

C:\WINDOWS\system32\__c005A092.dat

C:\WINDOWS\system32\__c00617C2.dat

C:\WINDOWS\system32\__c0062AF.dat

C:\WINDOWS\system32\__c00659D1.dat

C:\WINDOWS\system32\__c006B7C4.dat

C:\WINDOWS\system32\__c008142E.dat

C:\WINDOWS\system32\__c0083DF9.dat

C:\WINDOWS\system32\__c0093A96.dat

C:\WINDOWS\system32\__c00A7BBD.dat

C:\WINDOWS\system32\__c00AB340.dat

C:\WINDOWS\system32\__c00B72F6.dat

C:\WINDOWS\system32\__c00B9EC9.dat

C:\WINDOWS\system32\__c00BBDE3.dat

C:\WINDOWS\system32\__c00CAE57.dat

C:\WINDOWS\system32\__c00CDC9A.dat

C:\WINDOWS\system32\__c00D8C69.dat

C:\WINDOWS\system32\__c00DC910.dat

C:\WINDOWS\system32\__c00DAAF9.dat

C:\WINDOWS\system32\__c00E4516.dat

C:\WINDOWS\system32\__c00E8490.dat

C:\WINDOWS\system32\__c00EE5D8.dat

C:\WINDOWS\system32\adfqpqka.dll

C:\WINDOWS\system32\anybsrtr.dll

C:\WINDOWS\system32\bysmiaxi.dll

C:\WINDOWS\system32\dafcegct.ini

C:\WINDOWS\system32\eqatritn.dll

C:\WINDOWS\system32\ewitpejo.dll

C:\WINDOWS\system32\fbakuitx.dll

C:\WINDOWS\system32\ffocvoaj.ini

C:\WINDOWS\system32\fpwbtigl.dll

C:\WINDOWS\system32\fsbfoomh.ini

C:\WINDOWS\system32\fvylxubw.dll

C:\WINDOWS\system32\gcryyxmh.dll

C:\WINDOWS\system32\gilmnolm.dll

C:\WINDOWS\system32\gnirnoln.dll

C:\WINDOWS\system32\gotacqyb.dll

C:\WINDOWS\system32\hbbrlfun.dll

C:\WINDOWS\system32\hfvilfiy.dll

C:\WINDOWS\system32\hhxotdht.ini

C:\WINDOWS\system32\icefiapm.dll

C:\WINDOWS\system32\ifirbybi.dll

C:\WINDOWS\system32\jimulupb.dll

C:\WINDOWS\system32\jiygqrog.dll

C:\WINDOWS\system32\jmcwqjhm.dll

C:\WINDOWS\system32\ltyhphuk.dll

C:\WINDOWS\system32\mcrh.tmp

C:\WINDOWS\system32\mlkwvgjx.dll

C:\WINDOWS\system32\mucaapsh.dll

C:\WINDOWS\system32\nbimopne.dll

C:\WINDOWS\system32\niyvildk.dll

C:\WINDOWS\system32\npmiyyny.dll

C:\WINDOWS\system32\nsqaodtt.dll

C:\WINDOWS\system32\nvewgeyx.dll

C:\WINDOWS\system32\ofobggvs.dll

C:\WINDOWS\system32\ojkuroeu.dll

C:\WINDOWS\system32\onbivsvy.dll

C:\WINDOWS\system32\plminead.dll

C:\WINDOWS\system32\ppppo.bak1

C:\WINDOWS\system32\ppppo.bak2

C:\WINDOWS\system32\ppppo.ini

C:\WINDOWS\system32\ppppo.ini2

C:\WINDOWS\system32\ppppo.tmp

C:\WINDOWS\system32\purfepoy.dll

C:\WINDOWS\system32\qaggbhwl.dll

C:\WINDOWS\system32\qejvnscf.dll

C:\WINDOWS\system32\qlmfjybd.dll

C:\WINDOWS\system32\qtrecgki.ini

C:\WINDOWS\system32\quswmoja.dll

C:\WINDOWS\system32\qvqhtpdb.ini

C:\WINDOWS\system32\rerjgdgn.dll

C:\WINDOWS\system32\rmyltmsb.dll

C:\WINDOWS\system32\slmqasrf.dll

C:\WINDOWS\system32\ssyiidrw.ini

C:\WINDOWS\system32\storxjsk.dll

C:\WINDOWS\system32\taqanqyr.ini

C:\WINDOWS\system32\tlsgcyny.dll

C:\WINDOWS\system32\uikdvjsp.dll

C:\WINDOWS\system32\wbhcjpgl.dll

C:\WINDOWS\system32\wcsyavsh.dll

C:\WINDOWS\system32\wgpmbwbf.ini

C:\WINDOWS\system32\whwashbi.dll

C:\WINDOWS\system32\wjyarwha.dll

C:\WINDOWS\system32\xjmexarb.dll

C:\WINDOWS\system32\xlktnfdx.dll

C:\WINDOWS\system32\yrasgtrk.dll

C:\WINDOWS\system32\yyoiiucd.dll

 

----- BITS: Possible infected sites -----

 

hxxp://www.download.windowsupdate.com

.

((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))

.

 

2008-02-03 01:19 . 2008-02-03 01:24 1,355 --a------ C:\WINDOWS\imsins.BAK

2008-02-02 18:58 . 2008-02-02 18:58 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\vlc

2008-02-02 17:18 . 2008-02-02 21:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste

2008-02-02 17:18 . 2008-02-02 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord

2008-02-02 17:15 . 2008-02-02 18:58 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Mine dokumenter

2008-02-02 17:15 . 2006-06-23 16:23 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter

2008-02-02 17:15 . 2008-02-02 20:36 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask

2008-02-02 17:11 . 2008-02-02 19:10 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2008-02-02 17:10 . 2008-02-02 17:10 <DIR> d-------- C:\Programfiler\CCleaner

2008-01-29 00:05 . 2008-02-03 01:02 <DIR> d-------- C:\Programfiler\DivX

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-02-03 10:02 --------- d-----w C:\Programfiler\Fellesfiler\Ahead

2008-02-03 00:51 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2008-02-03 00:49 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec

2008-02-02 23:58 --------- d-----w C:\Programfiler\LimeWire

2008-02-02 18:01 --------- d-----w C:\Programfiler\BitLord

2008-02-02 17:49 --------- d-----w C:\Programfiler\Yahoo!

2008-02-02 15:50 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP

2008-01-31 08:29 --------- d-----w C:\Documents and Settings\All Users\Programdata\ZangoSA

2007-12-15 02:03 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help

2006-09-05 19:00 1,362,977 ----a-w C:\Programfiler\BitLord_1.01.exe

2006-09-01 18:38 5,361,664 ----a-w C:\Programfiler\NordicBetMPP_PW1.exe

2006-07-27 13:09 1,701,471 ----a-w C:\Programfiler\kart2.pdf

2006-07-19 00:59 3,762,888 ----a-w C:\Programfiler\pokerheaven.exe

2006-07-15 00:14 359,112 ----a-w C:\Programfiler\LimeWireWin.exe

2006-07-14 23:34 9,350,344 ----a-w C:\Programfiler\MSN_Messenger.EXE

2006-07-14 16:17 12,766,208 ----a-w C:\Programfiler\MP10Setup.exe

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]

"MSMSGS"="C:\Programfiler\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]

"AnyDVD"="C:\Programfiler\AnyDVD\AnyDVD.exe" [2006-10-15 18:03 497664]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe" [ ]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BCMSMMSG"="BCMSMMSG.exe" [2003-02-24 17:34 122880 C:\WINDOWS\BCMSMMSG.exe]

"SunJavaUpdateSched"="C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 36975]

"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 08:50 19968 C:\WINDOWS\LOGI_MWX.EXE]

"QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2006-10-30 20:06 282624]

"iTunesHelper"="C:\Programfiler\iTunes\iTunesHelper.exe" [2006-09-25 14:54 229952]

"GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

R0 esff;esff;C:\WINDOWS\system32\drivers\esff.sys [2005-10-07 11:49]

R0 wasfsd;wasfsd;C:\WINDOWS\system32\drivers\wasfsd.sys [2006-11-09 14:48]

S3 AR5523;3Com OfficeConnect Wireless 108Mbps 11g USB Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys []

 

.

Contents of the 'Scheduled Tasks' folder

"2007-11-22 18:16:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"

- C:\Programfiler\Apple Software Update\SoftwareUpdate.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-02-03 11:11:00

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\Programfiler\Logitech\MouseWare\system\em_exec.exe

C:\WINDOWS\system32\wdfmgr.exe

C:\Programfiler\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2008-02-03 11:13:12 - machine was rebooted

ComboFix-quarantined-files.txt 2008-02-03 10:13:08

.

2008-02-03 00:25:08 --- E O F ---

 

 

 

Lenke til kommentar

Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt.

Dra deretter fila over Combofix-iconet. Combofix vil starte igjen. Post loggen.

File::

C:\WINDOWS\imsins.BAK

C:\WINDOWS\system32\drivers\esff.sys

 

Folder::

C:\Documents and Settings\All Users\Programdata\ZangoSA

 

Er denne noe du kjenner til: C:\Programfiler\pokerheaven.exe

 

Er dette MSN eller et annet prog?: C\Programfiler\MSN_Messenger.EXE

Lenke til kommentar

har nettopp installert NOD32 som fant

C:\WINDOWS\system32\drivers\esff.sys

 

og slettet denne. Også en del andre småting. Mulig de påvirker Combifix-prosessen under..

Legger ut ferdig logg fra NOD32 av hva som er fjernet etter hvert.

 

 

Får forresten opp en feil i combofix.exe. Regner med at filene er allerede slettet kanskje?

Fjernet esff.sys fra listen og prøvde på nytt. Likevel samme feil.

 

 

 

"CFScript Name Error"

"Were you trying to run CFScript?"

"The name, CFScript apperas to be incorrectly spelt"

Endret av mogie
Lenke til kommentar

takk :blush: leste litt fort..

 

 

ComboFix:

Klikk for å se/fjerne spoilerteksten nedenfor

ComboFix 08-02.03.1 - Håvard Karlsnes 2008-02-03 14:46:27.4 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.657 [GMT 1:00]

Running from: C:\Documents and Settings\Håvard Karlsnes\Skrivebord\ComboFix.exe

Command switches used :: C:\Documents and Settings\Håvard Karlsnes\Skrivebord\CFScript.txt

* Created a new restore point

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

 

FILE

C:\WINDOWS\imsins.BAK

C:\WINDOWS\system32\drivers\esff.sys

.

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\All Users\Programdata\ZangoSA

C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSA.dat

C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSA_gdf.dat

C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSA_kyf.dat

C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSAEula.mht

C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSAAbout.mht

C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSAau.dat

C:\WINDOWS\imsins.BAK

 

.

((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))

.

 

2008-02-03 14:02 . 2008-02-03 14:02 0 --a------ C:\WINDOWS\system32\REN4C.tmp

2008-02-03 14:02 . 2008-02-03 14:02 0 --a------ C:\WINDOWS\system32\REN4B.tmp

2008-02-03 13:02 . 2008-02-03 14:35 <DIR> d-------- C:\Programfiler\Opera

2008-02-03 11:55 . 2008-02-03 11:49 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys

2008-02-03 11:55 . 2008-02-03 11:49 298,104 --a------ C:\WINDOWS\system32\imon.dll

2008-02-03 11:55 . 2008-02-03 11:49 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys

2008-02-03 11:49 . 2008-02-03 13:01 <DIR> d-------- C:\Programfiler\ESET

2008-02-03 11:23 . 2008-02-03 11:23 <DIR> d-------- C:\Nero7

2008-02-03 11:13 . 2008-02-03 11:13 <DIR> d-------- C:\Documents and Settings\HÕvard Karlsnes\Lokale innstillinger

2008-02-02 18:58 . 2008-02-02 18:58 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\vlc

2008-02-02 17:18 . 2008-02-02 21:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste

2008-02-02 17:18 . 2008-02-02 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord

2008-02-02 17:15 . 2008-02-02 18:58 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Mine dokumenter

2008-02-02 17:15 . 2006-06-23 16:23 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler

2008-02-02 17:15 . 2008-02-03 14:18 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter

2008-02-02 17:15 . 2008-02-02 20:36 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask

2008-02-02 17:11 . 2008-02-03 11:29 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\Håvard Karlsnes\Programdata\SUPERAntiSpyware.com

2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2008-02-02 17:10 . 2008-02-02 17:10 <DIR> d-------- C:\Programfiler\CCleaner

2008-01-29 00:05 . 2008-02-03 01:02 <DIR> d-------- C:\Programfiler\DivX

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-02-03 12:53 --------- d-----w C:\Programfiler\QuickTime

2008-02-03 11:15 --------- d-----w C:\Programfiler\Fellesfiler\Error Safe

2008-02-03 10:02 --------- d-----w C:\Programfiler\Fellesfiler\Ahead

2008-02-03 00:51 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared

2008-02-03 00:49 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec

2008-02-02 23:58 --------- d-----w C:\Programfiler\LimeWire

2008-02-02 18:01 --------- d-----w C:\Programfiler\BitLord

2008-02-02 17:49 --------- d-----w C:\Programfiler\Yahoo!

2008-02-02 15:50 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP

2008-01-30 14:00 --------- d-----w C:\Documents and Settings\Håvard Karlsnes\Programdata\dvdcss

2007-12-15 02:03 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help

2007-11-26 22:26 90,089 --sh--w C:\WINDOWS\system32\ikllm.tmp

2007-11-13 01:52 6,956 --sh--w C:\WINDOWS\system32\tuxbc.tmp

2007-11-07 09:30 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll

2007-11-06 21:29 6,695 --sh--w C:\WINDOWS\system32\rtstv.tmp

2006-09-01 18:38 5,361,664 ----a-w C:\Programfiler\NordicBetMPP_PW1.exe

2006-07-27 13:09 1,701,471 ----a-w C:\Programfiler\kart2.pdf

2006-07-14 16:17 12,766,208 ----a-w C:\Programfiler\MP10Setup.exe

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]

"AnyDVD"="C:\Programfiler\AnyDVD\AnyDVD.exe" [2006-10-15 18:03 497664]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe" [ ]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BCMSMMSG"="BCMSMMSG.exe" [2003-02-24 17:34 122880 C:\WINDOWS\BCMSMMSG.exe]

"GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016]

"nod32kui"="C:\Programfiler\Eset\nod32kui.exe" [2008-02-03 11:49 949376]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

R0 wasfsd;wasfsd;C:\WINDOWS\system32\drivers\wasfsd.sys [2006-11-09 14:48]

S0 esff;esff;C:\WINDOWS\system32\drivers\esff.sys []

S3 AR5523;3Com OfficeConnect Wireless 108Mbps 11g USB Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys []

 

.

Contents of the 'Scheduled Tasks' folder

"2007-11-22 18:16:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"

- C:\Programfiler\Apple Software Update\SoftwareUpdate.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-02-03 14:47:09

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-02-03 14:47:38

ComboFix-quarantined-files.txt 2008-02-03 13:47:22

ComboFix2.txt 2008-02-03 13:18:25

ComboFix3.txt 2008-02-03 12:15:30

ComboFix4.txt 2008-02-03 10:13:12

.

2008-02-03 00:25:08 --- E O F ---

 

 

NOD32 fant en mengde. Den rotet seg "selvsagt" inn i sikkerhetsgjenopprettings-delen av C:\. Men den fant og mer i /system32 etter hver og. Mulig det ikke var så lurt å kjøre NOD32 alikevel før jeg er ferdig med dette?

 

Klikk for å se/fjerne spoilerteksten nedenfor

Scan performed at: 2008-02-03 12:01

Date: 3.2.2008 Time: 12:01:54

Anti-Stealth technology is enabled.

Scanned disks, folders and files: C:; C:\WINDOWS\system32\drivers\esff.sys

C:\pagefile.sys - error opening (File locked) [4]

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{008B1723-BC8E-42A1-9D07-6C33765D827F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{01DD00A2-59F3-443D-98D2-18FBE37D7B67} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{024A4E95-B73C-436D-829C-0E552B6393CD} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{036D5C39-95D9-4831-BF41-6B0F75510ADA} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{056ED072-231B-4D5B-B1CC-3B50ACFC114D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{05E64C50-B890-4DC7-AE44-9AFD05418910} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{064B2F6F-A41A-4038-A25C-EF873BD419EF} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{06EF34B4-4334-4AD3-945D-78BFA4BEAC7E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{073F0D27-16B7-47BE-9793-1F63D52AEE4E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{081CB0D6-9F98-48BB-AD1E-05697ED2262A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{08407F67-7A2B-4100-B5D5-176BC2D2B904} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{08C26FFB-54D5-4EE4-AF9C-A30079837246} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{099395DC-006E-4278-8292-29561232A84C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0B689E58-3720-4EE4-A191-55AF4D70CE26} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0DEFAA49-778C-47F5-9AAA-CB6957C6FE3F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0E58E60B-C665-4B2B-8A9B-94AC76C5FF5F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0FEE1C87-B1EF-4E97-9195-B12F866A1580} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0FF9B4BD-1845-48FE-BC79-815F5E197C81} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0AA4F299-5311-49D6-B7B6-1B83D9A550E9} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1090D1DD-1A68-4E4B-8D8F-647DD41BDE59} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{111B891B-35D6-4BC2-AFC7-0F9151B44E22} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1137ECDE-2F1B-4892-8BD8-92C280298000} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{130CF933-43DC-425F-A8C1-4AB27AF20F8D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{13A0BCD3-B2B7-4574-B26B-2D81C8D002E8} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{13ED4B3E-822B-49A5-A013-6D99BFAEDDFA} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{14DD271D-5B29-45C7-B3D5-E3B8BAA90A74} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{16279271-1C21-4930-B866-F98C83A9A9BD} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{16BDC0D5-B326-4E37-8355-F655333724D4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{17F728F6-7930-4C7C-90D4-C3AC7076EDB2} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{191CE0F5-DE35-4F2D-8F73-4CC9647E3330} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{19BED188-7B9A-4D99-906B-26B8DC4E7F44} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1A077C7A-57F6-44B7-80A5-5B648214819E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1A135101-EABF-4429-85D1-956B2955095A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1B241C1D-1466-4B3D-B0FB-DDA223CA407C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1D29C83D-2E35-4062-A929-D5157B539FA9} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1DCC3023-91D7-43A0-86C0-63C170092EFA} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1E195BFB-60A6-4BDF-B684-45AE8441B266} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1E56BDB9-FC6A-4406-AC5E-4C6AB496569C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1F02654D-BDE6-4FB4-9D56-3F1AE018EE4B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{20087D76-10E6-48BC-AC51-81654A7AB3C0} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{22FEC44C-6185-42AF-9FBF-E91013EB89B5} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{24854F3B-6217-4C71-B7D8-B856042CA956} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2612A77B-9319-419F-A0E6-FB86A5DDC072} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2667A55C-D790-4C3D-AA0B-4ABB184B1F5B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{26C0C316-042E-41DE-A741-B2071CCE4440} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2764724C-9763-4585-A6A7-D8561B27511B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{27DBEC64-0249-49A5-93C6-2B65B1427FFF} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2A5F77CC-8D06-45D2-9BED-2A17A6B0D21B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2AC4DC0D-FC17-4A72-BBA8-3138D2B9A499} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2E61063D-B955-4474-B28E-44828490F874} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2E75F3D4-B59B-4865-9E6D-AA5C484CFDEB} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2F31B153-4E4A-4110-BEE8-61C599699A4F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2FFA00FD-5350-4A39-A9BF-9CF402D07960} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2AA06100-DBA7-434A-AAAC-E8ECBAB8461B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{30722331-F080-4935-9825-FD1DBBC25FBE} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{30E170F5-198E-4FD4-B54D-EDF87BF2DACD} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{31B70DB8-C78C-41EA-82CE-0C22465A4DFF} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{32A052F0-20DB-4FC6-ADC1-8CD86F6DCEED} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3456E333-70AC-407C-A71E-6997244F28D7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{34C9E10F-82F4-4EB7-B0BF-2D8F66627BC3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{37C8ED4B-0651-442F-B121-B6FECB5E879B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{38F4BD13-E395-4968-AA83-B30717ED3061} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3907A71E-1C03-427F-9F80-CB6862DC32ED} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{39226931-BC4C-4B5B-90A6-D4D6C68F756E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{395B570B-E8CE-4E94-ADDB-45C24B9C788B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3A15C5CC-7DF3-4CA5-8A78-E5A86BE09E47} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3A21CC82-C79D-4E02-B10A-630080E8A427} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3B5000A5-DE75-46D9-A056-C23DFED7AC3F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3B650910-67DB-42D8-8A05-75ADAD160050} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3B6EDAB6-0C8E-4992-8FE5-C32F57C87903} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3DFDC176-2426-4C24-913A-54ED228B5C22} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3FB1CA39-90F3-4ABE-8272-2F925ED1965A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4003A749-8A3B-4C69-8ADF-AE17A65698AF} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{403E5571-06E7-4A10-9D99-D7AF4FFF5096} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{408FFCBC-EDCC-4AEA-8D26-B4EE92BC165E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{40E62CBE-17D3-4A4C-AF61-6BB885A81706} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{41FA8D52-CD11-4E17-B916-987F95227AF4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{41FB17EB-B3EF-4562-BD83-1A84EA2CFA9F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4208D1D4-F982-471C-A40E-E9BF9E979160} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4210D639-2051-45BA-8756-58BD987E5D18} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{42539C6B-0787-462C-A95B-9A0E9D6734F1} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4440AD69-CB02-4747-A1CC-B47B182F14B8} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{462076CA-F4FF-4156-AC35-5A6F94C211FC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4776A06F-3DD5-4299-9CE5-28716EB04296} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{47A70894-2366-4C92-8A4A-4A6700F6AF03} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{496AB62D-177D-48E4-8CED-4E21E2E0DB70} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4A8A3B99-DA90-4C9E-9471-D779EF1A17EC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4CF15E1C-6698-4609-AD51-4D9EC556FB60} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4CF9DDF2-C320-48B2-A7C6-3A46DBE65A67} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4D289000-BFA2-4FE0-B249-09497C9BA9AA} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4DAD41C4-E9A4-42C1-A004-C6A2E49DC056} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4E15F791-2321-4CE0-9B69-EBEEE005F05C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4E82FF73-5DE0-4D40-ACE6-895EE996C129} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4EBAE578-9CE1-4C09-AA26-3834F552D015} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4EE62AD1-6422-4757-A1D2-63E627FBC939} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4EE8B557-4B6B-4168-B525-0F6D4B1FFF53} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4F2C172C-7618-487D-B7F2-968A8DF5115E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4F79CA2C-91D6-4333-A87B-7B039B372636} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{509E1F18-8712-4ADB-A049-97F28B923A55} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{51D2B3DB-054E-48E4-8B6B-D3A0BFDB96A3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{52F040DD-27B9-45BC-924C-39D904D50FE2} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5354FA07-6429-4EDB-BE3E-AA627BD22B9A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5536834D-3CF0-4912-B74D-F09D3F4AACCD} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{558BBB88-BB43-4806-AA95-E198B123B407} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{560C24CB-5F87-404B-9632-5956E724E2AD} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5685C2E3-F0A1-44FB-96A7-0F8C7BB1BEB1} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5732C949-1794-4BF0-88D0-87196A266F58} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{58442B28-B0E2-48CD-9A80-8E8B4BF957A4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5876736D-C7CF-41DE-9AD7-713310A43328} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{58904820-B3E9-4E05-B192-CAAD746BDC61} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{595A6C0B-23B5-4AD0-B9BF-89414963E1A8} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5A22CF1F-C34F-4081-B655-9837FAD87CA7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5A6AA0EA-88B4-441D-AA21-8AC2DB18DB1D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5A81A196-2451-45CC-83DA-DFC860E00561} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5AD8BEBC-DAA5-4CF4-BC56-2DD5736933F4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5B1DFA2E-1B6C-432E-92D8-7E98964836A6} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5C486079-55D3-4DA5-A7B2-5401E80F36E3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5C90B513-6E1E-42D3-A351-F74188860DDB} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5D0069D3-8B45-4644-9A60-5B97A9B95CC2} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5E756729-B60C-4E8A-BF78-ECBC250C6C3F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5AAF69C7-491C-4948-BBEA-D19A65DC5C4A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6082B309-7689-41C3-B30E-EDB1A6620635} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{608631E3-E5F8-487E-8F5A-E0806BB21CAC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{60E1D2F4-417D-4661-858D-B79042013DF7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{61491A28-C625-44F9-A897-549027607AE7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{62128B22-DFFD-4723-80E8-F8B13922669E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{624A7E8F-55A9-4548-81CF-A22755B2043B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{655BF6CC-A94A-4261-A156-AB0A5F3E9733} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{65C4E1C7-EFFD-47D2-ABEC-B7398FDED112} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{66129F9C-12D2-4178-A781-78B248578A7C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{661AA243-A417-4712-9959-582F61300B6C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{66B504D1-8436-44E6-87AD-73E863478CE6} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6732345F-5107-4F07-B6D7-8FF1B93DFB3D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{679E3DCB-2B67-48AA-8025-807D161B868B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{686F0732-94D9-41EB-8220-64DAC7B35582} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{68F54ADC-8B81-4E80-8BE4-73DEBF23A853} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6B7A439E-6E79-49D2-AB66-1062EEB9963C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6BFA614A-82DB-4B24-9373-FEBB3690CE83} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6C8C86D1-7456-442A-A47C-44F3858300CA} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6CBF9D30-1D8F-44DA-B516-5C4FDF2F124F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6CD8DF42-D85E-451C-A732-35813C88156D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6E0116F9-0DEB-4018-A7E0-F3FAAC21CDD9} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6E5171E1-925C-4D9F-AD49-EFE92D2EA63F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6F728F73-C1C4-408F-B3F9-E5429737FD54} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6FBE61FE-767C-46EB-9AFE-E8B1F2D44038} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{71241DA0-C0BD-48D2-B282-664AD010ACFC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{75DC2900-0BA3-4B5D-A81A-950EF7DA8FE9} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{75E80A42-57AA-4DAA-A878-767D5B3FA956} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{76E31F0F-3243-4F23-A8A4-183F5207B4EC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{773EC171-D5BA-4A12-8A62-6FDC43BFE290} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{77C2D848-9441-447C-99C5-D5062D3DD37F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{78D34A78-1A2E-4BC4-AA06-B043D11D44F5} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7A420644-226A-4839-9F77-B13A70F8A079} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7A5DB546-D007-4F3C-9BF6-4D07B00AE0A5} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7B875E69-76CD-486B-8CFC-000FE299767B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7BDA2EDC-5F77-462E-8ED7-352DF68BCEB0} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7C439763-B18E-4DEF-BFD1-A7D677928583} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7CE65C08-8D46-43C9-939F-198014ED038F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7DAC6D12-7947-45A3-A93E-217A3436405C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7EA31C19-CDCF-4B15-9A07-DE7B917428F3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7FAEAAC1-D460-4BF0-88ED-E928347B25AF} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{807BA362-BD25-499B-9C3C-19A4610981C3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{815230BA-7E24-44EB-8B64-6F6DCCE10C1E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{82ACB026-BCD5-45E3-B994-5187CF39CC3B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8500C2CB-18C7-44D3-ACA0-4837D2516F34} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{85C584EC-C2E7-49D5-8901-36067E15F40B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8662FF23-3D96-4F4A-8B9D-435140D1FD1E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{866CC55C-72DB-4A67-A2C2-3C48EA6952AC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{867D2714-4009-425E-86A1-4C91E5928E33} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8755445B-1787-4CA7-A17C-E29DF86E4DC8} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8791321C-9578-4118-A2D2-CA9A7F535AB4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{896FA546-2CD5-48D2-912B-29F2EEC391E2} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8979223A-471B-443D-9DC2-9351FEB62935} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8A3FEC13-ACE6-479D-A7B6-E7D9443E58E5} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8A7C279A-9A69-4BB9-B2DA-61BB1871CDA8} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8C093ACA-72F7-4898-AD33-166013619EF7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8C89CF68-E0AF-4E16-897A-525AEB8183BB} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8DA2BFC1-1F96-449E-A686-9B3F46375548} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8E23F2AC-ABF0-4E26-AAE0-1582394D4030} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8E2E6603-15A5-45D4-BB60-F82E8979E792} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8E6AB398-A7CA-48C1-9D8B-30F2D4F78A6C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8ED92A9F-D33C-427B-9BBE-F8CF84CB30C4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8F568485-4DBD-4462-9A00-5DBD9FBF007A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{907AD658-1E6B-4F76-A37C-13131E1F493F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{91DF264A-D22F-452D-A431-9DAFDCE8327A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{91F26766-8FC1-455A-BA02-A458B273F3BE} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{930D3E40-0267-4B37-9C10-413186E4553A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9324686B-C645-4FC3-92CE-583FDDF507E9} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{93F8D128-7DA0-4F3F-811E-084CBDB3763E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{943A2F59-BE56-4656-BBD8-FC164BD3EC6A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9573009E-7DCC-42E2-8231-AE0C1309482E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9598DA1F-96FF-473D-B1BE-0FBD9CF34B5E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{96491F6C-A954-45B9-88A7-0D18D05DC6F9} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{96BA9ACA-069B-475C-A11F-637D44787D04} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{970109A1-895E-4CBD-8E66-893E63C11995} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{970C31B3-8DA6-4478-B0C2-E2A2C31DAEFC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{97126FBD-6027-4B4E-8901-008520720D8D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{97673E43-DD28-475D-A5B1-C7814586674F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{986DAFA7-D9DB-4875-A5EA-C64E944BA982} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9A2760DD-6689-4A8E-A587-739B1ADAF1A6} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9A4FA626-B348-4F06-AC96-7A02BC38C650} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9A700283-C1FD-489A-9CF2-787F4A6665CE} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9A727C33-E182-410E-9E70-3CC5D9A9478A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9B1FC09B-4EBB-4170-B0CB-9D699636AC69} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9B6EE683-B49A-4591-9B8D-AEB6FED56FB6} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9C2CB8FB-11D3-4F74-BDBF-61886E81F1EC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9CC491FF-2F6D-488F-9623-A92E5EB9C9D1} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9D610A2B-5827-4D71-9D23-537406FD0EBD} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9E9267DF-18DC-4CBB-8F8C-B7E3E402F8D1} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9F420C4B-E7A3-4D4D-AB7A-F583F3FF14E1} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9FF42B37-0881-4B57-A1DF-C072ABAE7DF3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9AA31B1D-CE09-481A-BC22-7C56F9F0F6A3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A127AED5-3A65-4345-838A-E53AA46927DB} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A148EAB8-35F2-4953-B813-C922D63C01F1} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A2293877-79F3-4FD2-B030-C8BA56C473E0} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A2D96DE9-E2B8-4D68-85CC-45846C711DB7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A3763911-BBD7-46D8-B17E-C64959EDEECD} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A3E8ACC2-1139-40CF-AF46-8E107F6934D9} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A51A1BC0-F888-4705-8B67-2105B07D8DF2} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A52240A8-E755-4347-AB2B-3C28260AC179} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A5F098AB-1B4C-4EC3-B44E-BBD37009795B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A73ACEE1-246B-4AF1-B1F3-B5D3ADD5A27F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A765C0A1-76F5-4C6C-A462-CFAE96456104} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A8C7EDCC-4F2E-4B8B-9213-012800964C15} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A908E77B-1E6D-4B1F-89D1-49B4E6594C89} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A95A2298-CF06-4D85-8CD6-38044E5815C8} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AB700E7A-37B2-4748-8066-93C75961D4C4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{ACAE2983-7637-4AD9-A393-0ACBC6F29412} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AE3F96DF-3CD8-4620-8E99-4F3057475C90} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AF84B881-191D-4335-9CBF-7D9CA139A29A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B081DD9D-A5FD-4947-A032-8AE32C257B87} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B0DF18B8-22A7-4600-8390-08ED3681E01C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B101CA8D-2A42-47A4-A973-38BFCED929C4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B21F620C-E16A-44C3-96C4-E46D18089227} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B52978AA-1DEC-45ED-9FD3-05D6E557D2BA} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B73BE9B3-B666-44C2-8F84-D7DE1E9C262E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B76673A2-EBCE-40CE-AF32-08E01B346B14} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B8152100-8F24-4658-8676-92D81E5DF693} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B81AF3E5-855B-4F2A-97C8-957E0CB18B38} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B980D3BC-92DB-415F-8F6C-8763197170C0} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BA4D7E26-5294-4995-A8D5-043990656627} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BA751B3F-1029-44A9-BE8A-B47C12248E0C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BB5C51A6-851F-4A82-813A-6A3BB18F23DB} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BBD366B5-2E11-4421-BB90-80726B77FDEF} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BBFB1986-5377-410A-87AD-632175FB10CE} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BD1C8E87-70E2-402F-A04F-F31F4A3EF0FA} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BDD4E128-59BE-4509-B8C5-6DF5182DED60} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BFE7896C-97CE-4DC0-A915-99106C950436} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BFFA4F92-9F8B-46CF-9CDA-C91D45544108} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C14D58CA-8468-4FA5-B61C-39BE6A500CC0} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C21C6949-7FE4-423E-8403-4706259A281F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C27EAFED-4EF2-48F1-8E4C-F69AB74C483B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C2CAF54A-6FD8-4BDB-A95F-C11466AA5A9D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C2EF71D9-71D4-4B52-AA2D-6A64009F4F80} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C374AE67-B308-4AA2-A5B3-A7EF8826E68F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C4862841-FF42-48CA-870D-14B33519B932} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C4A58A08-0A3D-4AFB-8865-42B91D615516} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C5418266-03E0-47D7-AA69-200407583ED4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C5543FF1-8D47-430F-BD70-C4AF76743385} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C5A05500-F577-4255-96A4-5EF4B5409C73} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C726584D-6633-4EC5-BECB-B89F2AC972B8} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C7D09B4A-2483-4B8D-A073-C5C7BD31E180} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C83E5705-B674-4461-96DF-979A266651A3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C92E0623-BD19-4879-849D-786B3EDC5756} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C9A34610-219B-4EC4-8FCA-816A7DD8A814} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CA3555BF-9619-4109-AF7F-A599F751CDCC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CA733AA1-9F13-48EA-BF5C-9A1155F628F5} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CAB5C4C3-D2EB-4E99-8D23-A4F6A3D3B36D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CC14497B-F986-4F85-80E7-EADC0B595750} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CC4A09F5-222B-41E8-A2CA-BF438C10350D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CDC0E1D2-ECC8-40EA-950C-0B59A49FE457} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CEDEBDCE-3D92-4FAF-82F3-78F27C99F5DC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CF4F5293-C4E4-4D16-9CCA-31D3F331B4B5} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CF981F48-6D20-4EF9-A931-1669DB78ABE4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CFC0FDC0-BA04-4881-B94C-2AD29ED1DABA} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CFFB1C87-9E01-4770-A8A3-19B1E71CDA8A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CAA130A3-372A-466C-8DCF-09284E70D40E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D2DCD2FF-9195-418C-BFA0-836A68D536AB} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D320F4A1-5BF1-4F38-88AD-3EF0B101B193} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D45CA94D-F06A-48C8-9376-2BC4DEA2E374} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D4C5F10A-AAE6-48A0-9E5A-0F39A23B5D49} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D52D5CF4-F444-47C8-A564-2984EA2EA0E9} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D6C40EE2-A107-4543-B58B-939E7880EEB0} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D8AB4C79-0383-4B16-A301-45512433EF46} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D8B48CF8-3B28-427D-9A83-35C99BD760BF} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D91BF3CC-5218-4E72-AF3C-2C82D40EAA1F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D939B013-B128-438F-B6FC-6F88E5B21B72} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DA109444-F044-4F43-81C3-704EE6802E5E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DA620C82-5F56-4ED1-A632-ED060F946237} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DB1DE5AD-11AD-4DED-8F02-00117BFBD33E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DB52A583-4D05-4D9A-8FEA-C3869F0026CD} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DBF17007-8DB8-498F-9A1A-C06A31F2D94B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DDE749EC-3D7C-4E63-A5CE-A0E200D3FF34} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DE7B8ADD-2841-4A82-B5CE-1F77B05D2937} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DE9DFD42-8C87-4A9A-A307-B9A45776945C} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DEACD288-9853-4B0E-BF84-28B6988F692E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DFC20BD6-0ACB-41FB-80B5-DD6C14C3DFA7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E195BE00-0BEE-437C-AE3C-6E94ADCD8BD0} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E2F7EA35-82F0-406B-8202-DAA22C6F1BF5} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E3AFACCA-9C34-4E20-9DB7-1CB303EABA0D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E404E7AB-0514-49D2-BA69-2131F30F3410} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E451BC95-41D6-435F-A8E7-A301F54CBA12} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E55AB43A-1742-4722-B86B-F3A3C89CB70E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E6E4F04B-40FD-4441-8376-1242022B67C3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E90171DD-844C-42BF-84F0-44F75C2C33B1} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E9A9E595-E66C-454B-98FB-1C1E9241E1C3} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EA2224BA-0CC0-42EA-9CD3-C94817C7AC36} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EC625808-A82B-4872-9AA2-96F80CCF5824} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{ED94A634-06E3-4889-BD02-33715730F64A} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EDA3C584-BC0D-4047-9EB7-7F2AAE6777A2} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EE61872B-4C3F-4E75-9BDE-CB14C31D8419} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EF3DAAA4-29F5-46FC-A178-93AF7C8FD3BB} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EF95D932-7672-4872-B0F0-58CD997F3EAE} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F0A30489-CE75-4ADE-BC9E-F444ED8282F0} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F0D76BB1-FD36-4BB5-A89F-385FF4CF395B} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F195CAA0-A6AB-4564-81BE-74162CEFBA73} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F1E324CD-5B79-4005-88EA-C897BAD4D827} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F1FFCE9D-4CC7-422F-BCCA-20E8DD104016} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F216B71F-4D10-4794-AF53-47786EF473D4} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F23F006D-C0AC-40AE-95BF-DCBD94E5750D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F286BA57-F3E2-4728-842E-66EEE7D53830} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F45E1D21-C28E-4B79-870D-854C7E824923} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F4711847-28A4-4A2D-911B-CF21E4E921A7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F6A2D1C3-A6A5-4438-B3F6-FABBA8D7C38F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FAEF6443-734C-4630-8D4A-A42E658EEFBC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FB5FB160-692D-4D10-B2AE-C9A3B40C5E20} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FB9F279B-7A55-4795-BBB3-62A60FD9952F} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FBC6181D-7D4D-4B25-B870-DA600D3DBF4E} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FCE901CB-4452-4EF9-A271-587911ACA548} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FD8AE61D-4F2C-4BBD-8F62-B3371812507D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FDF4161E-1DE9-43A5-9A8E-64A9607D9C83} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FE96D84E-17DD-407F-8FB6-365725F43888} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FEF7CDA3-B4FC-4946-9BB0-914554B1C295} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FEFD6B7F-BD11-4951-954A-1728B34EA89D} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FFB7B44D-DFC3-4087-AD71-FDE664F10385} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AA001D29-D8F8-41A7-860C-EF0C56B3E0CC} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AA7FEBAC-7D7B-433B-8EE5-154C10D7E644} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AAA6EF7F-DE9F-48CE-811B-F326BFCE67D7} - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »backup.db - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 19-02-18.SBU »ZIP »backup.db - error - password-protected file

C:\Documents and Settings\Håvard Karlsnes\NTUSER.DAT - error opening (File locked) [4]

C:\Documents and Settings\Håvard Karlsnes\ntuser.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4]

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temporary Internet Files\Content.IE5\XPH0ABLV\mosx1024[1] - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\Documents and Settings\Håvard Karlsnes\Programdata\setup_no[1].exe - probably a variant of Win32/Adware.RogueApp application

C:\Documents and Settings\LocalService\NTUSER.DAT - error opening (File locked) [4]

C:\Documents and Settings\LocalService\ntuser.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\LocalService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4]

C:\Documents and Settings\LocalService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\NetworkService\NTUSER.DAT - error opening (File locked) [4]

C:\Documents and Settings\NetworkService\ntuser.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\NetworkService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4]

C:\Documents and Settings\NetworkService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4]

C:\program files\fbb\freebbaccess\freebbaccess.exe - Win32/Dialer.Agent.AK application - deleted

C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/106-va-stacie_orrico_-_o_come_all_ye_faithful-b2r.mp3 - incorrect CRC checksum, the file may be damaged

C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/203-va-katarzyna_skrzynecka_-_oszaleli_anieli-b2r.mp3 - incorrect CRC checksum, the file may be damaged

C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/306-va-mel_and_kim_-_rockin_around_the_christmas_tree-b2r.mp3 - incorrect CRC checksum, the file may be damaged

C:\Programfiler\BitLord\Downloads\Classic.School.Girls.4.DANiSH.XXX.DVDRip.XviD-DKPORNA\dkp-csg4.rar »RAR »dkp-csg4.avi - next archive volume not found

C:\Programfiler\BitLord\Downloads\Prison.Break.S02E18.HDTV.XviD-XOR\xor-prison.break.218.rar »RAR »prison.break.s02e18.hdtv.xvid-xor.avi - next archive volume not found

C:\Programfiler\EA GAMES\Battlefield 2\pylib-2.3.4.zip »ZIP »test/testtar.tar »TAR - archive damaged

C:\Programfiler\Fellesfiler\Error Safe\erscw.exe - Win32/Adware.SystemDoctor application - deleted

C:\Programfiler\Fellesfiler\Error Safe\ESFF.exe - Win32/Adware.ErrorSafe application - deleted

C:\Programfiler\Fellesfiler\Error Safe\ESPChck.dll - Win32/Adware.ErrorSafe application - deleted

C:\QooBox\Quarantine\C\Programfiler\Screensavers.com\SSSInst\bin\SSSInst.dll.vir - Win32/Adware.Comet application - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\adfqpqka.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\anybsrtr.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\bysmiaxi.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\eqatritn.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\ewitpejo.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\fbakuitx.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\fpwbtigl.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\fvylxubw.dll.vir - Win32/BHO.NAV trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\gcryyxmh.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\gilmnolm.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\gnirnoln.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\gotacqyb.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\hbbrlfun.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\hfvilfiy.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\icefiapm.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\ifirbybi.dll.vir - Win32/BHO.NAV trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\jimulupb.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\jiygqrog.dll.vir - Win32/BHO.NAV trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\jmcwqjhm.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\ltyhphuk.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\mlkwvgjx.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\mucaapsh.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\nbimopne.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\niyvildk.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\npmiyyny.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\nsqaodtt.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\nvewgeyx.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\ofobggvs.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\ojkuroeu.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\onbivsvy.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\plminead.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\purfepoy.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\qaggbhwl.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\qejvnscf.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\qlmfjybd.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\quswmoja.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\rerjgdgn.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\rmyltmsb.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\slmqasrf.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\storxjsk.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\tlsgcyny.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\uikdvjsp.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\wbhcjpgl.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\wcsyavsh.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\whwashbi.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\wjyarwha.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\xjmexarb.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\xlktnfdx.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\yrasgtrk.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\yyoiiucd.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c0022960.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c002324A.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c0023F21.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c0025266.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c0035220.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c0042E52.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c005A092.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00617C2.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c0062AF.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00659D1.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c006B7C4.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c008142E.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c0083DF9.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c0093A96.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00A7BBD.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00AB340.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00B72F6.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00B9EC9.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00BBDE3.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00CAE57.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00CDC9A.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00D8C69.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00DAAF9.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00DC910.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00E4516.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00E8490.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\__c00EE5D8.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP229\A0109587.dll - a variant of Win32/Adware.Virtumonde application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109645.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109646.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109647.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109648.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109649.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109680.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109682.dll - a variant of Win32/Adware.Virtumonde application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109684.dll - a variant of Win32/Adware.Virtumonde application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109685.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP232\A0110682.dll - probably a variant of Win32/Adware.Virtumonde.FP application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP232\A0110683.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP232\A0111705.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP233\A0111738.exe - probably a variant of Win32/Adware.180Solutions application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP234\A0111784.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP234\A0111785.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP234\A0111786.dll - a variant of Win32/Adware.Virtumonde application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP237\A0111854.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP237\A0111855.dll - probably a variant of Win32/Adware.Virtumonde.FP application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP237\A0111856.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP237\A0111857.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP238\A0112854.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP239\A0112881.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP241\A0112964.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP241\A0112965.dll - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP241\A0112986.dll - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP241\A0113981.exe - Win32/Adware.180Solutions application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP243\A0114973.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP243\A0114974.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP244\A0114992.dll - Win32/TrojanDownloader.FakeAlert.C trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP247\A0116077.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP248\A0117077.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118101.exe - Win32/Adware.SystemDoctor application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118102.exe - Win32/Adware.ErrorSafe application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118103.dll - Win32/Adware.ErrorSafe application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118104.dll - Win32/Adware.ErrorSafe application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118105.dll - Win32/Adware.ErrorSafe application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118107.dll - Win32/Adware.ErrorSafe application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118110.sys - Win32/Rootkit.Agent.AF trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118120.exe - Win32/Adware.180Solutions application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118121.dll - probably a variant of Win32/Adware.Agent application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118138.exe - Win32/Adware.VirusProtectPro application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118149.dll - a variant of Win32/Adware.Virtumonde.FP application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118154.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118155.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118156.dll - a variant of Win32/BHO.G trojan

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118157.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118158.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118159.dll - a variant of Win32/BHO.G trojan

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118161.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118162.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118164.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118165.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118166.dll - Win32/Adware.Virtumonde application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118169.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118170.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118172.dll - probably a variant of Win32/Adware.HotBar application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118174.dll - Win32/Adware.HotBar application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118175.dll - Win32/Adware.HotBar application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118176.dll - probably a variant of Win32/Adware.HotBar application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118177.dll - Win32/Adware.Toolbar.ZangoBar application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118179.exe - Win32/Adware.HotBar application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118180.exe - probably a variant of Win32/Adware.HotBar application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118182.dll - probably a variant of Win32/Adware.HotBar application

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118184.exe - Win32/Adware.HotBar application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118185.dll - Win32/Adware.HotBar application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118198.exe - Win32/Adware.WinFixer application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118200.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118204.exe - Win32/Adware.WinFixer application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118207.dll - a variant of Win32/BHO.G trojan

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118208.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118209.dll - a variant of Win32/BHO.G trojan

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118210.dll - Win32/BHO.G trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118307.exe - a variant of Win32/TrojanDownloader.Dluca trojan

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119439.dll - Win32/Adware.Comet application - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119445.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119446.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119447.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119448.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119449.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119450.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119451.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119452.dll - Win32/BHO.NAV trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119453.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119454.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119455.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119456.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119457.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119458.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119459.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119460.dll - Win32/BHO.NAV trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119461.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119462.dll - Win32/BHO.NAV trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119463.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119464.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119465.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119466.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119467.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119468.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119469.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119470.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119471.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119472.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119473.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119474.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119475.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119476.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119477.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119478.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119479.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119480.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119481.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119482.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119483.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119484.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119485.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119486.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119487.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119488.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119489.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119490.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119491.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119492.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119493.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119494.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119495.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119496.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119497.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119498.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119499.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119500.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119501.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119502.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119503.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119504.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119505.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119506.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119507.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119508.rbf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119509.rbf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119510.rbf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119511.rbf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119512.rbf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119513.rbf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119514.rbf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119515.rbf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119516.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119517.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119518.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119519.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119520.EXE - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119521.old - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119522.old - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119523.lnk - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119524.lnk - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119525.lnk - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119526.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119527.VBS - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119528.VBS - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119529.VBS - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119530.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119531.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119532.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119533.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119534.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119535.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119536.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119537.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119538.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119539.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119540.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119541.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119542.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119543.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119544.sys - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119545.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119546.reg - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119547.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119548.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119549.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119550.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119551.cf - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119552.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119553.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119554.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119555.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119556.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119557.reg - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119558.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119559.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119560.com - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119561.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119562.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119563.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119564.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119565.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119566.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119567.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119568.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119569.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119570.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119571.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119572.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119573.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119574.lnk - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119575.lnk - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119576.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119577.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119578.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119579.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119580.sys - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119581.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119582.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119583.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119584.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119585.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119586.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119587.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119588.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119589.sys - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119590.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119591.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119592.reg - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119593.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119594.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119595.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119596.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119597.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119598.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119599.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119600.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119601.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119602.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119603.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119604.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119605.com - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119606.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119607.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119608.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119609.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119610.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119611.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119612.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119613.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119614.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119615.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119616.vbs - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119617.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119618.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119619.bat - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119620.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119621.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119622.dll - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119623.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119624.EXE - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119625.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119626.exe - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119627.ini - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119628.lnk - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\change.log - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\change.log.1 - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\change.log.2 - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\RestorePointSize - error opening [4]

C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\rp.log - error opening [4]

C:\WINDOWS\system32\fcosxxuf.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\fvplt.dll - a variant of Win32/TrojanDownloader.Dluca.CM trojan

C:\WINDOWS\system32\lvrehndg.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\nrclqgvc.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\qockwxnu.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\retbjnyp.dll - Win32/BHO.NAV trojan

Scanning interrupted by user!

Number of scanned files: 185290

Number of threats found: 185

Number of files cleaned: 184

Number of active threats: 1

Time of completion: 13:01:19 Total scanning time: 3565 sec (00:59:25)

 

Notes:

[4] File cannot be opened. It may be in use by another application or operating system.

 

 

Lenke til kommentar

Ønsker at du følger veiledning og ikke begynner å gjøre så mye annet. Du gjør selvfølgelig hva du vil, men det er lett at det kan oppstå uklarheter.

 

De fleste filene NOD fant er karantenefiler og filer i restore-mappa. Disse er ufarlig og vil bli fjernet på slutten av supporten :)

 

Opprett en ny CFScript.txt fil med følgende innhold og gjennta prosedyren:

File::

C:\WINDOWS\system32\drivers\wasfsd.sys

C:\WINDOWS\system32\REN4C.tmp

C:\WINDOWS\system32\REN4B.tmp

C:\WINDOWS\system32\ikllm.tmp

C:\WINDOWS\system32\tuxbc.tmp

C:\WINDOWS\system32\rtstv.tmp

 

Folder::

C:\Programfiler\Fellesfiler\Error Safe

C:\Programfiler\Fellesfiler\Symantec Shared

C:\Documents and Settings\All Users\Programdata\Symantec

 

Post loggen på ny.

 

Deretter:

Fjern karantenefilene i SAS

Fjern combofix ved å skrive combofix /u i kjør-feltet (Start->Kjør).

 

Restart PC-en

 

Kjør en full scan med ditt av-prog. (I denne sammenheng NOD).

 

Post HJT-logg (før du kjører hjt, forandrer du programnavnet, hijackthis, til noe annet eks. mogie) og fortell om NOD fortsatt finner noe og evt. hvor disse filene blir funnet.

Lenke til kommentar

HJT-logg:

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:52:06, on 03.02.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\BCMSMMSG.exe

C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe

C:\Programfiler\Eset\nod32kui.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Programfiler\Eset\nod32krn.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wuauclt.exe

E:\clean_box\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_03\bin\ssv.dll (file missing)

O4 - HKLM\..\Run: [bCMSMMSG] BCMSMMSG.exe

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKLM\..\Run: [nod32kui] "C:\Programfiler\Eset\nod32kui.exe" /WAITSERVICE

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: &Google Search - res://c:\programfiler\google\GoogleToolbar2.dll/cmsearch.html

O8 - Extra context menu item: &Translate English Word - res://c:\programfiler\google\GoogleToolbar2.dll/cmwordtrans.html

O8 - Extra context menu item: Backward Links - res://c:\programfiler\google\GoogleToolbar2.dll/cmbacklinks.html

O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programfiler\google\GoogleToolbar2.dll/cmcache.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Similar Pages - res://c:\programfiler\google\GoogleToolbar2.dll/cmsimilar.html

O8 - Extra context menu item: Translate Page into English - res://c:\programfiler\google\GoogleToolbar2.dll/cmtrans.html

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

O15 - Trusted Zone: http://www.download.com

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL

O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programfiler\Eset\nod32krn.exe

 

--

End of file - 4577 bytes

 

 

 

Kjører en NOD32.scan nå.. :)

Lenke til kommentar

NOD32-logg:

 

 

Scan performed at: 03.02.2008 15:57:37

Scanning Log

NOD32 version 2845 (20080202) NT

Operating memory - is OK

 

Date: 3.2.2008 Time: 15:57:44

Anti-Stealth technology is enabled.

Scanned disks, folders and files: C:

C:\pagefile.sys - error opening (File locked) [4]

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »backup.db - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 19-02-18.SBU »ZIP »backup.db - error - password-protected file

C:\Documents and Settings\Håvard Karlsnes\NTUSER.DAT - error opening (File locked) [4]

C:\Documents and Settings\Håvard Karlsnes\ntuser.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4]

C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\Håvard Karlsnes\Mine dokumenter\downloads\sinstaller2.exe »NSIS »SSSInst.dll - Win32/Adware.Comet application

C:\Documents and Settings\LocalService\NTUSER.DAT - error opening (File locked) [4]

C:\Documents and Settings\LocalService\ntuser.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\LocalService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4]

C:\Documents and Settings\LocalService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\NetworkService\NTUSER.DAT - error opening (File locked) [4]

C:\Documents and Settings\NetworkService\ntuser.dat.LOG - error opening (File locked) [4]

C:\Documents and Settings\NetworkService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4]

C:\Documents and Settings\NetworkService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4]

C:\Nero7\nero7premium\Nero-7.7.5.1_eng_update.exe »RAR »Cab\E4060BF5.cab »CAB »rootFEAA0A71.img »GZ - archive damaged

C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/106-va-stacie_orrico_-_o_come_all_ye_faithful-b2r.mp3 - incorrect CRC checksum, the file may be damaged

C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/203-va-katarzyna_skrzynecka_-_oszaleli_anieli-b2r.mp3 - incorrect CRC checksum, the file may be damaged

C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/306-va-mel_and_kim_-_rockin_around_the_christmas_tree-b2r.mp3 - incorrect CRC checksum, the file may be damaged

C:\Programfiler\BitLord\Downloads\Classic.School.Girls.4.DANiSH.XXX.DVDRip.XviD-DKPORNA\dkp-csg4.rar »RAR »dkp-csg4.avi - next archive volume not found

C:\Programfiler\BitLord\Downloads\Prison.Break.S02E18.HDTV.XviD-XOR\xor-prison.break.218.rar »RAR »prison.break.s02e18.hdtv.xvid-xor.avi - next archive volume not found

C:\Programfiler\EA GAMES\Battlefield 2\pylib-2.3.4.zip »ZIP »test/testtar.tar »TAR - archive damaged

C:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4]

C:\WINDOWS\SoftwareDistribution\EventCache\{776FD12B-FF70-43AA-A26F-0670143EA38A}.bin - error opening (File locked) [4]

C:\WINDOWS\system32\retbjnyp.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\ttdefvkw.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\ttochyoj.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\vevstteg.dll - a variant of Win32/Adware.Virtumonde application

C:\WINDOWS\system32\xorspwqc.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\ymtbahhh.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\yptvgjtx.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\ywomxuxx.dll - Win32/BHO.NAV trojan - deleted

C:\WINDOWS\system32\config\default - error opening (File locked) [4]

C:\WINDOWS\system32\config\default.LOG - error opening (File locked) [4]

C:\WINDOWS\system32\config\SAM - error opening (File locked) [4]

C:\WINDOWS\system32\config\SAM.LOG - error opening (File locked) [4]

C:\WINDOWS\system32\config\SECURITY - error opening (File locked) [4]

C:\WINDOWS\system32\config\SECURITY.LOG - error opening (File locked) [4]

C:\WINDOWS\system32\config\software - error opening (File locked) [4]

C:\WINDOWS\system32\config\software.LOG - error opening (File locked) [4]

C:\WINDOWS\system32\config\system - error opening (File locked) [4]

C:\WINDOWS\system32\config\system.LOG - error opening (File locked) [4]

Number of scanned files: 144066

Number of threats found: 9

Number of files cleaned: 8

Number of active threats: 1

Time of completion: 16:27:19 Total scanning time: 1775 sec (00:29:35)

 

Notes:

[4] File cannot be opened. It may be in use by another application or operating system.

 

 

 

 

 

Skal ha slettet alle karantenefilene i SAS. I brukeren administrator også. Merkelig at de står oppført likevel...

 

 

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »backup.db - error - password-protected file

C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 19-02-18.SBU »ZIP »backup.db - error - password-protected file

 

 

 

Som du ser i NOD32-loggen ble det finnet en :

 

 

C:\Documents and Settings\Håvard Karlsnes\Mine dokumenter\downloads\sinstaller2.exe »NSIS »SSSInst.dll - Win32/Adware.Comet application

 

 

 

som ikke ble fjernet. Denne har kanskje kobling mot en .ddl fil? (SSSInst.dll) el lign. og at den kjører nå?

 

Tusen hjertlig takk for hjelpen ennå :D Er nok "beste" tilfellet på lenge dette :p

Endret av mogie
Lenke til kommentar

sinstaller2.exe kan du fjerne manuelt fra Download-mappa di (mulig den må tas fra sikker modus).

 

Kunne godt tenkt meg å sett en ny combofix-logg. Last ned på ny og kjør.

Fortell også hvordan PC-en kjører.

Endret av norbat
Lenke til kommentar

Fjernet sinstaller.exe i safe-modus.

 

Fikk egentlig vite av laptopen var så og si ubrukelig siden den var så treg. Likevel har ikke jeg opplevd noe av dette. Så slik sett er den like rask som før... Det kan kanskje ha vært spesielle programmer som avgjør om PC-en jobbet sent, eller at malware ikke var aktiv ennå..

 

Uansett fungerer den flott nå :)

 

Ny ComboFix logg:

 

 

 

ComboFix 08-02.03.1 - Håvard Karlsnes 2008-02-03 17:25:36.6 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.697 [GMT 1:00]

Running from: E:\clean_box\ComboFix.exe

 

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

 

((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))

.

 

2008-02-03 17:21 . 2007-05-14 18:46 177,152 --a------ C:\utorrent.exe

2008-02-03 13:02 . 2008-02-03 14:35 <DIR> d-------- C:\Programfiler\Opera

2008-02-03 11:55 . 2008-02-03 11:49 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys

2008-02-03 11:55 . 2008-02-03 11:49 298,104 --a------ C:\WINDOWS\system32\imon.dll

2008-02-03 11:55 . 2008-02-03 11:49 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys

2008-02-03 11:49 . 2008-02-03 16:00 <DIR> d-------- C:\Programfiler\ESET

2008-02-03 11:23 . 2008-02-03 11:23 <DIR> d-------- C:\Nero7

2008-02-03 11:13 . 2008-02-03 11:13 <DIR> d-------- C:\Documents and Settings\HÕvard Karlsnes\Lokale innstillinger

2008-02-02 18:58 . 2008-02-02 18:58 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\vlc

2008-02-02 17:18 . 2008-02-03 17:15 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste

2008-02-02 17:18 . 2008-02-02 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord

2008-02-02 17:15 . 2008-02-02 18:58 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Mine dokumenter

2008-02-02 17:15 . 2006-06-23 16:23 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler

2008-02-02 17:15 . 2008-02-03 15:33 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger

2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter

2008-02-02 17:15 . 2008-02-02 20:36 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask

2008-02-02 17:11 . 2008-02-03 17:16 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware

2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard

2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\Håvard Karlsnes\Programdata\SUPERAntiSpyware.com

2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com

2008-02-02 17:10 . 2008-02-02 17:10 <DIR> d-------- C:\Programfiler\CCleaner

2008-01-29 00:05 . 2008-02-03 01:02 <DIR> d-------- C:\Programfiler\DivX

 

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-02-03 15:51 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help

2008-02-03 14:24 --------- d-----w C:\Programfiler\AnyDVD

2008-02-03 12:53 --------- d-----w C:\Programfiler\QuickTime

2008-02-03 10:02 --------- d-----w C:\Programfiler\Fellesfiler\Ahead

2008-02-02 23:58 --------- d-----w C:\Programfiler\LimeWire

2008-02-02 18:01 --------- d-----w C:\Programfiler\BitLord

2008-02-02 17:49 --------- d-----w C:\Programfiler\Yahoo!

2008-02-02 15:50 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP

2008-01-30 14:00 --------- d-----w C:\Documents and Settings\Håvard Karlsnes\Programdata\dvdcss

2007-11-07 09:30 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll

2006-09-01 18:38 5,361,664 ----a-w C:\Programfiler\NordicBetMPP_PW1.exe

2006-07-27 13:09 1,701,471 ----a-w C:\Programfiler\kart2.pdf

2006-07-14 16:17 12,766,208 ----a-w C:\Programfiler\MP10Setup.exe

.

 

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe" [ ]

"SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BCMSMMSG"="BCMSMMSG.exe" [2003-02-24 17:34 122880 C:\WINDOWS\BCMSMMSG.exe]

"nod32kui"="C:\Programfiler\Eset\nod32kui.exe" [2008-02-03 11:49 949376]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360]

 

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll

 

R3 SIWIO;SIWIO;C:\WINDOWS\TEMP\SiwIo.sys []

S0 esff;esff;C:\WINDOWS\system32\drivers\esff.sys []

S0 wasfsd;wasfsd;C:\WINDOWS\system32\drivers\wasfsd.sys []

S3 AR5523;3Com OfficeConnect Wireless 108Mbps 11g USB Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys []

 

*Newly Created Service* - SIWIO

.

Contents of the 'Scheduled Tasks' folder

"2007-11-22 18:16:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"

- C:\Programfiler\Apple Software Update\SoftwareUpdate.exe

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-02-03 17:27:38

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

**************************************************************************

.

Completion time: 2008-02-03 17:28:11

.

2008-02-03 00:25:08 --- E O F ---

 

 

 

Lenke til kommentar

Loggen ser fin ut. :thumbup:

 

Du kan fjerne combofix igjen med kommandoen combofix /u fra kjør-vinduet.

 

Du kan godt kjøre NOD igjen og se om det fortsatt sitter noen rester igjen i systemet. Gi gjerne tilbakemelding.

 

En ny runde med CCleaner samt sjekk om PC-en trenger en diskdefragmentering (tilbehør->systemverktøy->diskdefragementering) kan være en grei avslutning. :)

Lenke til kommentar
Loggen ser fin ut. :thumbup:

 

Du kan fjerne combofix igjen med kommandoen combofix /u fra kjør-vinduet.

 

Du kan godt kjøre NOD igjen og se om det fortsatt sitter noen rester igjen i systemet. Gi gjerne tilbakemelding.

 

En ny runde med CCleaner samt sjekk om PC-en trenger en diskdefragmentering (tilbehør->systemverktøy->diskdefragementering) kan være en grei avslutning. :)

 

Bra gjetta ;) har akkurat gjort det.

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...