m0g1e Skrevet 3. februar 2008 Del Skrevet 3. februar 2008 Har kjør en CCleaner + SAS i sikkerhetsmodus. Har en HJT-logg her som jeg vil gjerne finner mer ut av HJT-logg: Klikk for å se/fjerne spoilerteksten nedenfor Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 03:48:16, on 03.02.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\BCMSMMSG.exe C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe C:\Programfiler\LogMeIn\LogMeInSystray.exe C:\Programfiler\QuickTime\qttask.exe C:\Programfiler\iTunes\iTunesHelper.exe C:\Programfiler\Fellesfiler\Error Safe\erscw.exe C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\Messenger\msmsgs.exe C:\Programfiler\AnyDVD\AnyDVD.exe C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Programfiler\Logitech\MouseWare\system\em_exec.exe C:\WINDOWS\system32\svchost.exe C:\Programfiler\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\RunDll32.exe C:\DOCUME~1\HVARDK~1\LOKALE~1\Temp\Set3.tmp C:\DOCUME~1\HVARDK~1\LOKALE~1\Temp\Set3.tmp E:\clean_box\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILE...s0p0O2t8dizZHOC R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=wKX1ILE...ccR6flAnJF1NpUE R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O3 - Toolbar: (no name) - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - (no file) O4 - HKLM\..\Run: [bCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Programfiler\LogMeIn\LogMeInSystray.exe" O4 - HKLM\..\Run: [FreeBBAccess] C:\Program Files\FBB\FreeBBAccess\FreeBBAccess.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [erscw] C:\Programfiler\Fellesfiler\Error Safe\erscw.exe -c O4 - HKLM\..\Run: [WlanUI] "C:\Programfiler\3COM\3Com Wireless 108 Mbps 11g USB Utility \WlanUI.exe" -nogui O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [AnyDVD] C:\Programfiler\AnyDVD\AnyDVD.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Error Safe] "C:\Programfiler\Error Safe Free\ers.exe" /min O4 - HKCU\..\Run: [AdwareProtector] C:\Programfiler\Error Safe\AdwareProtector.exe O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Programfiler\Video Add-on\isfmntr.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Google Search - res://c:\programfiler\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\programfiler\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\programfiler\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programfiler\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\programfiler\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\programfiler\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Programfiler\nordicbetMPP\MPPoker.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O15 - Trusted Zone: http://www.download.com O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0046C4.dat O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O23 - Service: 3Com Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe -- End of file - 7160 bytes SAS_logg: Klikk for å se/fjerne spoilerteksten nedenfor SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 02/02/2008 at 06:11 PM Application Version : 3.9.1008 Core Rules Database Version : 3394 Trace Rules Database Version: 1386 Scan type : Complete Scan Total Scan Time : 00:25:52 Memory items scanned : 207 Memory threats detected : 0 Registry items scanned : 5391 Registry threats detected : 738 File items scanned : 27182 File threats detected : 354 Malware.VirusProtect [VirusProtect 3.8] C:\PROGRAMFILER\VIRUSPROTECT 3.8\VIRUSPROTECT 3.8.EXE C:\PROGRAMFILER\VIRUSPROTECT 3.8\VIRUSPROTECT 3.8.EXE HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\VirusProtect 3.8.exe 3.8 HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726} HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\Control HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\gdSunfeg HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\InprocServer32 HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\InprocServer32#InprocServer32 HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\InprocServer32#ThreadingModel HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\MiscStatus HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\MiscStatus\1 HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\omtFah HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\ProgID HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\RwVqqSyQVe HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\szZcwulWlvk HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\ToolboxBitmap32 HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\TypeLib HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\UcXilulPysmr HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\Version HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\VersionIndependentProgID HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\wjwq HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\wtImonnayggvp HKCR\CLSID\{B7C9058D-0F9C-32C0-83B6-740DFD8A6726}\xkunxwc HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6} HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0 HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0 HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0\win32 HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0\FLAGS HKCR\TypeLib\{3B8E549E-0C73-4AAB-8939-5EA2ED102CC6}\1.0\HELPDIR HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334} HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}\ProxyStubClsid HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}\ProxyStubClsid32 HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}\TypeLib HKCR\Interface\{21688E5D-A895-4B60-B127-B76607420334}\TypeLib#Version HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E} HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}\ProxyStubClsid HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}\ProxyStubClsid32 HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}\TypeLib HKCR\Interface\{40E563B2-61B2-4215-819A-A7E24CF8AA3E}\TypeLib#Version HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816} HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}\ProxyStubClsid HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}\ProxyStubClsid32 HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}\TypeLib HKCR\Interface\{45FBEFBF-E8B6-44A5-B0A1-A143E1A74816}\TypeLib#Version HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150} HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}\ProxyStubClsid HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}\ProxyStubClsid32 HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}\TypeLib HKCR\Interface\{5146B43E-B36D-4A2A-B617-CC05CC500150}\TypeLib#Version HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9} HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}\ProxyStubClsid HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}\ProxyStubClsid32 HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}\TypeLib HKCR\Interface\{5B8BED0F-5F18-4051-9908-C5C569A1AAE9}\TypeLib#Version HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24} HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}\ProxyStubClsid HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}\ProxyStubClsid32 HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}\TypeLib HKCR\Interface\{63667718-EBF2-4CAB-B1E8-994D41589C24}\TypeLib#Version HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E} HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}\ProxyStubClsid HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}\ProxyStubClsid32 HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}\TypeLib HKCR\Interface\{972F0BE3-976F-40B8-8EB4-88A25987416E}\TypeLib#Version HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A} HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}\ProxyStubClsid HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}\ProxyStubClsid32 HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}\TypeLib HKCR\Interface\{9F80EA2D-53CF-4AA5-A154-F4FBF1EF6A5A}\TypeLib#Version HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100} HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}\ProxyStubClsid HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}\ProxyStubClsid32 HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}\TypeLib HKCR\Interface\{A35F8FAC-755D-4F90-A5D3-F7E18D9EB100}\TypeLib#Version HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586} HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}\ProxyStubClsid HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}\ProxyStubClsid32 HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}\TypeLib HKCR\Interface\{C269F4C1-7558-4DFC-9FB6-4C149B482586}\TypeLib#Version HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE} HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}\ProxyStubClsid HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}\ProxyStubClsid32 HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}\TypeLib HKCR\Interface\{CE92A296-3142-493C-B64E-6ED73EAFB9AE}\TypeLib#Version HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138} HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}\ProxyStubClsid HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}\ProxyStubClsid32 HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}\TypeLib HKCR\Interface\{D7C0DF6C-91FF-48BD-AD98-E35769394138}\TypeLib#Version HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D} HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}\ProxyStubClsid HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}\ProxyStubClsid32 HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}\TypeLib HKCR\Interface\{D8EC2704-B249-4495-A7A4-A90857BDDF4D}\TypeLib#Version HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988} HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}\ProxyStubClsid HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}\ProxyStubClsid32 HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}\TypeLib HKCR\Interface\{D91E9F36-9E44-44AB-803C-0D941FDA7988}\TypeLib#Version HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6} HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}\ProxyStubClsid HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}\ProxyStubClsid32 HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}\TypeLib HKCR\Interface\{E0757BDD-69BE-4C3F-AFC6-50D6524FA9B6}\TypeLib#Version HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D} HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}\ProxyStubClsid HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}\ProxyStubClsid32 HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}\TypeLib HKCR\Interface\{F2F8C877-B06C-4B5E-95E7-AACFC9E8219D}\TypeLib#Version HKLM\Software\VirusProtect 3.8 HKLM\Software\VirusProtect 3.8#refid HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#UninstallString HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#DisplayIcon HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#DisplayVersion HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#NSIS:StartMenuDir HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#URLInfoAbout HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VirusProtect 3.8#Publisher HKLM\Software\Microsoft\Windows\CurrentVersion\Run#VirusProtect 3.8 [ "C:\Programfiler\VirusProtect 3.8\VirusProtect 3.8.exe" /h ] C:\Programfiler\VirusProtect 3.8\blacklist.txt C:\Programfiler\VirusProtect 3.8\ignored.lst C:\Programfiler\VirusProtect 3.8\Lang\English.ini C:\Programfiler\VirusProtect 3.8\Lang C:\Programfiler\VirusProtect 3.8\Logs C:\Programfiler\VirusProtect 3.8\msvcp71.dll C:\Programfiler\VirusProtect 3.8\msvcr71.dll C:\Programfiler\VirusProtect 3.8\Quarantine C:\Programfiler\VirusProtect 3.8\uninst.exe C:\Programfiler\VirusProtect 3.8\VirusProtect 3.8.url C:\Programfiler\VirusProtect 3.8\vp.dat C:\Programfiler\VirusProtect 3.8\vpp.ini C:\Programfiler\VirusProtect 3.8 C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\PROGRAMDATA\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\VIRUSPROTECT 3.8.LNK C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\START-MENY\PROGRAMMER\VIRUSPROTECT 3.8\UNINSTALL VIRUSPROTECT 3.8.LNK C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\START-MENY\PROGRAMMER\VIRUSPROTECT 3.8\VIRUSPROTECT 3.8.LNK C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\START-MENY\VIRUSPROTECT 3.8.LNK C:\WINDOWS\Prefetch\VIRUSPROTECT 3.8.EXE-2E7F597A.pf Adware.Zango Toolbar/Hb HKLM\Software\Classes\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D} HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D} HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D} HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\InprocServer32 HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\InprocServer32#ThreadingModel HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\ProgID HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\Programmable HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\TypeLib HKCR\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\VersionIndependentProgID C:\PROGRAMFILER\ZANGO\BIN\10.0.314.0\HOSTIE.DLL HKLM\Software\Microsoft\Internet Explorer\Toolbar#{07AA283A-43D7-4CBE-A064-32A21112D94D} HKCR\HostIE.Bho.1 HKCR\HostIE.Bho.1\CLSID HKCR\HostIE.Bho HKCR\HostIE.Bho\CLSID HKCR\HostIE.Bho\CurVer HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4} HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0 HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0 HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\win32 HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\FLAGS HKCR\TypeLib\{087C4054-0A2B-4F35-B0DB-BED3E21650F4}\1.0\HELPDIR HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94} HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\InprocServer32 HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\InprocServer32#ThreadingModel HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\ProgID HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\Programmable HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\TypeLib HKCR\CLSID\{1E0004EC-5DF0-48C7-A8F0-FBB0488A3D94}\VersionIndependentProgID HKCR\HbCoreSrv.DynamicProp HKCR\HbCoreSrv.DynamicProp\CLSID HKCR\HbCoreSrv.DynamicProp\CurVer HKCR\HbCoreSrv.DynamicProp.1 HKCR\HbCoreSrv.DynamicProp.1\CLSID HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C} HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}\ProxyStubClsid HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}\ProxyStubClsid32 HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}\TypeLib HKCR\Interface\{06784C15-B640-40F8-AEE8-3C1A3C7A899C}\TypeLib#Version HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978} HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}\ProxyStubClsid HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}\ProxyStubClsid32 HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}\TypeLib HKCR\Interface\{195EF37C-0FF4-4AEF-B51B-47D326F01978}\TypeLib#Version HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0} HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}\ProxyStubClsid HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}\ProxyStubClsid32 HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}\TypeLib HKCR\Interface\{1D5DF418-73EA-4B20-B0D1-5F9C6C949CB0}\TypeLib#Version HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D} HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\ProxyStubClsid HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\ProxyStubClsid32 HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\TypeLib HKCR\Interface\{30022029-2C17-4A99-87D2-A382C674A19D}\TypeLib#Version HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119} HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\ProxyStubClsid HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\ProxyStubClsid32 HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\TypeLib HKCR\Interface\{3A6691EA-C844-46F2-9237-1386A85CE119}\TypeLib#Version HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96} HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\ProxyStubClsid HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\ProxyStubClsid32 HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\TypeLib HKCR\Interface\{3D2E7662-85FB-4CC1-875C-A624B1AA5D96}\TypeLib#Version HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227} HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\ProxyStubClsid HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\ProxyStubClsid32 HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\TypeLib HKCR\Interface\{72FEEB09-BB27-46D3-A06D-930D4D544227}\TypeLib#Version HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD} HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\ProxyStubClsid HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\ProxyStubClsid32 HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\TypeLib HKCR\Interface\{736918FE-2349-4230-BA9A-1F23649E32AD}\TypeLib#Version HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A} HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}\ProxyStubClsid HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}\ProxyStubClsid32 HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}\TypeLib HKCR\Interface\{85E06077-C824-43D0-A8DC-5EFB17BC348A}\TypeLib#Version HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40} HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\ProxyStubClsid HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\ProxyStubClsid32 HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\TypeLib HKCR\Interface\{89D36231-6BD9-4E20-BBA0-FD28C3A83C40}\TypeLib#Version HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B} HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}\ProxyStubClsid HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}\ProxyStubClsid32 HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}\TypeLib HKCR\Interface\{972BC913-312C-44B7-AA91-4AE3EC2E264B}\TypeLib#Version HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3} HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}\ProxyStubClsid HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}\ProxyStubClsid32 HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}\TypeLib HKCR\Interface\{A0BA9F0F-BCEF-49CF-8A8E-D87E19E066F3}\TypeLib#Version HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93} HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\ProxyStubClsid HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\ProxyStubClsid32 HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\TypeLib HKCR\Interface\{A53762B6-30F7-469F-BA92-13D63CF09A93}\TypeLib#Version HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125} HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\ProxyStubClsid HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\ProxyStubClsid32 HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\TypeLib HKCR\Interface\{B24FF4F6-D327-4208-8840-68CCEF7D6125}\TypeLib#Version HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA} HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\ProxyStubClsid HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\ProxyStubClsid32 HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\TypeLib HKCR\Interface\{BD31DF26-7178-41F4-88DD-F16B82D827CA}\TypeLib#Version HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6} HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}\ProxyStubClsid HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}\ProxyStubClsid32 HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}\TypeLib HKCR\Interface\{C4DB76D5-B430-4652-8599-7CD2C8FE6CC6}\TypeLib#Version HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8} HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}\ProxyStubClsid HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}\ProxyStubClsid32 HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}\TypeLib HKCR\Interface\{E4662B0A-DA6B-4408-A73B-5A2BBB2B0CC8}\TypeLib#Version HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E} HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\ProxyStubClsid HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\ProxyStubClsid32 HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\TypeLib HKCR\Interface\{E977DE7C-34EA-4876-B333-207C4504589E}\TypeLib#Version HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A} HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\ProxyStubClsid HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\ProxyStubClsid32 HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\TypeLib HKCR\Interface\{F5FC30C3-68AD-451B-8BC1-8ABD98F2C69A}\TypeLib#Version HKCR\CoreSrv.CoreServices HKCR\CoreSrv.CoreServices\CLSID HKCR\CoreSrv.CoreServices\CurVer HKCR\CoreSrv.CoreServices.1 HKCR\CoreSrv.CoreServices.1\CLSID HKCR\CoreSrv.LfgAx HKCR\CoreSrv.LfgAx\CLSID HKCR\CoreSrv.LfgAx\CurVer HKCR\CoreSrv.LfgAx.1 HKCR\CoreSrv.LfgAx.1\CLSID HKCR\HBMain.CommBand HKCR\HBMain.CommBand\CLSID HKCR\HBMain.CommBand\CurVer HKCR\HBMain.CommBand.1 HKCR\HBMain.CommBand.1\CLSID HKCR\hbr.HbMain HKCR\hbr.HbMain\CLSID HKCR\hbr.HbMain\CurVer HKCR\hbr.HbMain.1 HKCR\hbr.HbMain.1\CLSID HKCR\HostOL.MailAnim HKCR\HostOL.MailAnim\CLSID HKCR\HostOL.MailAnim\CurVer HKCR\HostOL.MailAnim.1 HKCR\HostOL.MailAnim.1\CLSID HKCR\HostOL.WebmailSend HKCR\HostOL.WebmailSend\CLSID HKCR\HostOL.WebmailSend\CurVer HKCR\HostOL.WebmailSend.1 HKCR\HostOL.WebmailSend.1\CLSID HKCR\InstIE.HbInstObj HKCR\InstIE.HbInstObj\CLSID HKCR\InstIE.HbInstObj\CurVer HKCR\InstIE.HbInstObj.1 HKCR\InstIE.HbInstObj.1\CLSID HKCR\Srv.CoreServices HKCR\Srv.CoreServices\CLSID HKCR\Srv.CoreServices\CurVer HKCR\Srv.CoreServices.1 HKCR\Srv.CoreServices.1\CLSID HKCR\Toolbar.HtmlMenuUI HKCR\Toolbar.HtmlMenuUI\CLSID HKCR\Toolbar.HtmlMenuUI\CurVer HKCR\Toolbar.HtmlMenuUI.1 HKCR\Toolbar.HtmlMenuUI.1\CLSID HKCR\Toolbar.ToolbarCtl HKCR\Toolbar.ToolbarCtl\CLSID HKCR\Toolbar.ToolbarCtl\CurVer HKCR\Toolbar.ToolbarCtl.1 HKCR\Toolbar.ToolbarCtl.1\CLSID HKCR\Zango.DesktopFlash HKCR\Zango.DesktopFlash\CLSID HKCR\Zango.DesktopFlash\CurVer HKCR\Zango.DesktopFlash.1 HKCR\Zango.DesktopFlash.1\CLSID HKCR\ZangoAX.ClientDetector HKCR\ZangoAX.ClientDetector\CLSID HKCR\ZangoAX.ClientDetector\CurVer HKCR\ZangoAX.ClientDetector.1 HKCR\ZangoAX.ClientDetector.1\CLSID HKCR\ZangoAX.UserProfiles HKCR\ZangoAX.UserProfiles\CLSID HKCR\ZangoAX.UserProfiles\CurVer HKCR\ZangoAX.UserProfiles.1 HKCR\ZangoAX.UserProfiles.1\CLSID HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D} HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\Control HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\InprocServer32 HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\InprocServer32#ThreadingModel HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\MiscStatus HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\MiscStatus\1 HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\ProgID HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\Programmable HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\ToolboxBitmap32 HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\TypeLib HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\Version HKCR\CLSID\{1E5B2693-D348-4ca7-8364-4F5E51BF9C6D}\VersionIndependentProgID HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF} HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\InprocServer32 HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\InprocServer32#ThreadingModel HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\ProgID HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\Programmable HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\TypeLib HKCR\CLSID\{2E54AC53-EFA4-4831-A3F6-B47B1A1937CF}\VersionIndependentProgID HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67} HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\InprocServer32 HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\InprocServer32#ThreadingModel HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\ProgID HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\Programmable HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\TypeLib HKCR\CLSID\{5B2E150D-4C8A-40E4-8C36-DD9C02771C67}\VersionIndependentProgID HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E} HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\Control HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\InprocServer32 HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\InprocServer32#ThreadingModel HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\MiscStatus HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\MiscStatus\1 HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\ProgID HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\Programmable HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\ToolboxBitmap32 HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\TypeLib HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\Version HKCR\CLSID\{627D894A-8A77-416E-B522-432EAF2C818E}\VersionIndependentProgID HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E} HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\LocalServer32 HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\ProgID HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\Programmable HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\TypeLib HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\VersionIndependentProgID HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7} HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\Control HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\InprocServer32 HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\InprocServer32#ThreadingModel HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\ProgID HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\Programmable HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\ToolboxBitmap32 HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\TypeLib HKCR\CLSID\{8971CB48-9FCA-445A-BE77-E8E8A4CC9DF7}\VersionIndependentProgID HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554} HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}#AppID HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Control HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Implemented Categories HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\InprocServer32 HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\InprocServer32#ThreadingModel HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\MiscStatus HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\MiscStatus\1 HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\ProgID HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Programmable HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\ToolboxBitmap32 HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\TypeLib HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\Version HKCR\CLSID\{B0CB585F-3271-4E42-88D9-AE5C9330D554}\VersionIndependentProgID HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387} HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\InprocServer32 HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\InprocServer32#ThreadingModel HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\ProgID HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\Programmable HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\TypeLib HKCR\CLSID\{B88E4484-3FF6-4EA9-815B-A54FE20D4387}\VersionIndependentProgID HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF} HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}#AppID HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\LocalServer32 HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\ProgID HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\Programmable HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\TypeLib HKCR\CLSID\{BD937FFE-0352-4FDE-88F2-C30D1A9B25CF}\VersionIndependentProgID HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E} HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}\Implemented Categories HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}\Implemented Categories\{A87F4ED6-CCC0-47C2-92EB-B3AD853B5D5F} HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54} HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\InprocServer32 HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\InprocServer32#ThreadingModel HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\ProgID HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\Programmable HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\TypeLib HKCR\CLSID\{BFC08CFF-C737-4433-BD5A-0EE7EFCFEE54}\VersionIndependentProgID HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603} HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\InprocServer32 HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\InprocServer32#ThreadingModel HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\ProgID HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\TypeLib HKCR\CLSID\{D2221CCB-F2BB-4858-AAD4-57C754153603}\VersionIndependentProgID HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5} HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\InprocServer32 HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\InprocServer32#ThreadingModel HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\ProgID HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\Programmable HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\TypeLib HKCR\CLSID\{EA0B6A1A-6A59-4A58-9C41-9966504898A5}\VersionIndependentProgID HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189} HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0 HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0 HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\win32 HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\FLAGS HKCR\TypeLib\{08755390-F46D-4D09-968C-3430166B3189}\1.0\HELPDIR HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD} HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0 HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0 HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\win32 HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\FLAGS HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\HELPDIR HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB} HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0 HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0 HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\win32 HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\FLAGS HKCR\TypeLib\{229D2451-A617-4B30-B5E8-8138694240CB}\1.0\HELPDIR HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09} HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0 HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0 HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\win32 HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\FLAGS HKCR\TypeLib\{9720DE03-5820-4059-B4A4-639D5E52BD09}\1.0\HELPDIR HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D} HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0 HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0 HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0\win32 HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0\FLAGS HKCR\TypeLib\{AD71E48F-6F47-4B63-9312-FAE879541C4D}\1.0\HELPDIR HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6} HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0 HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0 HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\win32 HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\FLAGS HKCR\TypeLib\{CCC6E232-AA4C-4813-A019-9C14B27776B6}\1.0\HELPDIR HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F} HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0 HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0 HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0\win32 HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0\FLAGS HKCR\TypeLib\{DD1CB2D7-161D-4B84-AE5C-08D3FAED894F}\1.0\HELPDIR HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771} HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\ProxyStubClsid HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\ProxyStubClsid32 HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\TypeLib HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\TypeLib#Version HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C} HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\ProxyStubClsid HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\ProxyStubClsid32 HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\TypeLib HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\TypeLib#Version HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619} HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\ProxyStubClsid HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\ProxyStubClsid32 HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\TypeLib HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\TypeLib#Version HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3} HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}\ProxyStubClsid HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}\ProxyStubClsid32 HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}\TypeLib HKCR\Interface\{1985FCE1-4043-4346-AE70-D0A0CD90BDD3}\TypeLib#Version HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E} HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\ProxyStubClsid HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\ProxyStubClsid32 HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\TypeLib HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\TypeLib#Version HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299} HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\ProxyStubClsid HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\ProxyStubClsid32 HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\TypeLib HKCR\Interface\{2E623B96-B166-4C70-8169-820761794299}\TypeLib#Version HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091} HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\ProxyStubClsid HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\ProxyStubClsid32 HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\TypeLib HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\TypeLib#Version HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806} HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\ProxyStubClsid HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\ProxyStubClsid32 HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\TypeLib HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\TypeLib#Version HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A} HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid32 HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib#Version HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE} HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\ProxyStubClsid HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\ProxyStubClsid32 HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\TypeLib HKCR\Interface\{49155DAE-C471-40FA-98EE-B2B3CAD115CE}\TypeLib#Version HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD} HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\ProxyStubClsid HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\ProxyStubClsid32 HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\TypeLib HKCR\Interface\{4D783385-0DDA-4188-A529-C97DC3D67CBD}\TypeLib#Version HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3} HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\ProxyStubClsid HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\ProxyStubClsid32 HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\TypeLib HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\TypeLib#Version HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689} HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\ProxyStubClsid HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\ProxyStubClsid32 HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\TypeLib HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\TypeLib#Version HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F} HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\ProxyStubClsid HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\ProxyStubClsid32 HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\TypeLib HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\TypeLib#Version HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627} HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\ProxyStubClsid HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\ProxyStubClsid32 HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\TypeLib HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\TypeLib#Version HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19} HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\ProxyStubClsid HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\ProxyStubClsid32 HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\TypeLib HKCR\Interface\{6E10479B-31E8-4A3B-81B1-DDAF39097F19}\TypeLib#Version HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99} HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\ProxyStubClsid HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\ProxyStubClsid32 HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\TypeLib HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\TypeLib#Version HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392} HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\ProxyStubClsid HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\ProxyStubClsid32 HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\TypeLib HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\TypeLib#Version HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B} HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\ProxyStubClsid HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\ProxyStubClsid32 HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\TypeLib HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\TypeLib#Version HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1} HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\ProxyStubClsid HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\ProxyStubClsid32 HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\TypeLib HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\TypeLib#Version HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8} HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\ProxyStubClsid HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\ProxyStubClsid32 HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\TypeLib HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\TypeLib#Version HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9} HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\ProxyStubClsid HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\ProxyStubClsid32 HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\TypeLib HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\TypeLib#Version HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9} HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\ProxyStubClsid HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\ProxyStubClsid32 HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\TypeLib HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\TypeLib#Version HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F} HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\ProxyStubClsid HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\ProxyStubClsid32 HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\TypeLib HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\TypeLib#Version HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13} HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\ProxyStubClsid HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\ProxyStubClsid32 HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\TypeLib HKCR\Interface\{E420A65F-9984-4B8C-9FA9-1ED69D3B0A13}\TypeLib#Version HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791} HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid32 HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib#Version HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F} HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid32 HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib#Version HKCR\AppId\ZangoSA_df.exe HKCR\AppId\ZangoSA_df.exe#AppID HKCR\AppId\{DBF00E12-281C-4dc8-A7EC-1FF45182439B} HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayIcon HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#UninstallString HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#DisplayVersion HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#HelpLink HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#Publisher HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA#URLInfoAbout Trojan.Smitfraud Variant HKLM\Software\Classes\CLSID\{3750da11-9b0c-4a75-9c8a-bbcbfcd1ccea} HKCR\CLSID\{3750DA11-9B0C-4A75-9C8A-BBCBFCD1CCEA} HKCR\CLSID\{3750DA11-9B0C-4A75-9C8A-BBCBFCD1CCEA}\InProcServer32 HKCR\CLSID\{3750DA11-9B0C-4A75-9C8A-BBCBFCD1CCEA}\InProcServer32#ThreadingModel C:\WINDOWS\SYSTEM32\FFTKTMK.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{3750da11-9b0c-4a75-9c8a-bbcbfcd1ccea} Adware.Vundo Variant HKLM\Software\Classes\CLSID\{51EB01ED-205E-4818-B024-AFACA970EC37} HKCR\CLSID\{51EB01ED-205E-4818-B024-AFACA970EC37} HKCR\CLSID\{51EB01ED-205E-4818-B024-AFACA970EC37}\InprocServer32 HKCR\CLSID\{51EB01ED-205E-4818-B024-AFACA970EC37}\InprocServer32#ThreadingModel C:\WINDOWS\SYSTEM32\OPPPP.DLL Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\opppp Unclassified.Unknown Origin HKLM\Software\Classes\CLSID\{598F4775-6FB6-477B-9842-E0426824E077} HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077} HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077} HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}\InprocServer32 HKCR\CLSID\{598F4775-6FB6-477B-9842-E0426824E077}\InprocServer32#ThreadingModel C:\DOCUME~1\HVARDK~1\LOKALE~1\TEMP\~DP146.DLL C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\~DP146.DLL Adware.Vundo-Variant/Small-A HKLM\Software\Classes\CLSID\{8dbdc4a8-b382-48a0-9a87-1c72b0c6635a} HKCR\CLSID\{8DBDC4A8-B382-48A0-9A87-1C72B0C6635A} HKCR\CLSID\{8DBDC4A8-B382-48A0-9A87-1C72B0C6635A}\InprocServer32 HKCR\CLSID\{8DBDC4A8-B382-48A0-9A87-1C72B0C6635A}\InprocServer32#ThreadingModel C:\WINDOWS\SYSTEM32\KBXGFNIG.DLL C:\WINDOWS\SYSTEM32\AEVKGHRP.DLL C:\WINDOWS\SYSTEM32\BDPTHQVQ.DLL C:\WINDOWS\SYSTEM32\CUSBAHJM.DLL C:\WINDOWS\SYSTEM32\FHMBKLMS.DLL C:\WINDOWS\SYSTEM32\FNYFAOTR.DLL C:\WINDOWS\SYSTEM32\GQYSPPWE.DLL C:\WINDOWS\SYSTEM32\GUMFMDUB.DLL C:\WINDOWS\SYSTEM32\IQQJVSWP.DLL C:\WINDOWS\SYSTEM32\KJFAYNPX.DLL C:\WINDOWS\SYSTEM32\LQUVGAON.DLL C:\WINDOWS\SYSTEM32\MJBNLIIB.DLL C:\WINDOWS\SYSTEM32\NJQUNGLS.DLL C:\WINDOWS\SYSTEM32\ONKMUQMD.DLL C:\WINDOWS\SYSTEM32\QXDGKEXT.DLL C:\WINDOWS\SYSTEM32\RXSKREGS.DLL C:\WINDOWS\SYSTEM32\WDCREEVW.DLL C:\WINDOWS\SYSTEM32\WKIXDUUE.DLL C:\WINDOWS\SYSTEM32\WMDDTQEB.DLL C:\WINDOWS\SYSTEM32\XVGJUNPO.DLL C:\WINDOWS\SYSTEM32\YPUFYKGB.DLL Adware.HotBar/SpamBlockerUtility (Low Risk) HKLM\Software\Classes\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C} HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C} HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C} HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Control HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Implemented Categories HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Implemented Categories\{00021494-0000-0000-C000-000000000046} HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\InprocServer32 HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\InprocServer32#ThreadingModel HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Instance HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Instance#CLSID HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Instance\InitPropertyBag HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Instance\InitPropertyBag#Url HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\MiscStatus HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\MiscStatus\1 HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\ProgID HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Programmable HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\ToolboxBitmap32 HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\TypeLib HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\Version HKCR\CLSID\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}\VersionIndependentProgID HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C} Adware.Starware HKCR\CLSID\{45A4902E-4479-4EAE-A186-8D0F7E4C78DE} HKCR\CLSID\{45A4902E-4479-4EAE-A186-8D0F7E4C78DE}\InprocServer32 HKCR\CLSID\{45A4902E-4479-4EAE-A186-8D0F7E4C78DE}\InprocServer32#ThreadingModel HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95} HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}\Implemented Categories HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}\Implemented Categories\{00021493-0000-0000-C000-000000000046} HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}\InprocServer32 HKCR\CLSID\{4C1CAACF-1788-4613-A840-6BD943D4EE95}\InprocServer32#ThreadingModel HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14} HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}\Implemented Categories HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}\Implemented Categories\{00021494-0000-0000-C000-000000000046} HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}\InprocServer32 HKCR\CLSID\{9A7D6AD2-0881-451F-BB27-F5E2EE2C5B14}\InprocServer32#ThreadingModel HKCR\CLSID\{9FB3908C-6565-4CB0-95F8-E9F85258723C} HKCR\CLSID\{9FB3908C-6565-4CB0-95F8-E9F85258723C}\InprocServer32 HKCR\CLSID\{9FB3908C-6565-4CB0-95F8-E9F85258723C}\InprocServer32#ThreadingModel Adware.180solutions/ZangoSearch C:\Programfiler\Zango\bin\10.0.314.0\arrow.ico C:\Programfiler\Zango\bin\10.0.314.0\copyright.txt C:\Programfiler\Zango\bin\10.0.314.0\CoreSrv.dll C:\Programfiler\Zango\bin\10.0.314.0\dBenderC.dll C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\components\npclntax.xpt C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\components C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\install.rdf C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\plugins\npclntax_ZangoSA.dll C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions\plugins C:\Programfiler\Zango\bin\10.0.314.0\firefox\extensions C:\Programfiler\Zango\bin\10.0.314.0\firefox C:\Programfiler\Zango\bin\10.0.314.0\HostOE.dll C:\Programfiler\Zango\bin\10.0.314.0\HostOL.dll C:\Programfiler\Zango\bin\10.0.314.0\InstIE.dll C:\Programfiler\Zango\bin\10.0.314.0\link.ico C:\Programfiler\Zango\bin\10.0.314.0\OEAddOn.exe C:\Programfiler\Zango\bin\10.0.314.0\Srv.exe C:\Programfiler\Zango\bin\10.0.314.0\Toolbar.dll C:\Programfiler\Zango\bin\10.0.314.0\Wallpaper.dll C:\Programfiler\Zango\bin\10.0.314.0\ZangoSAAX.dll C:\Programfiler\Zango\bin\10.0.314.0\ZangoSADF.exe C:\Programfiler\Zango\bin\10.0.314.0\ZangoSAHook.dll C:\Programfiler\Zango\bin\10.0.314.0\ZangoUnInstaller.exe C:\Programfiler\Zango\bin\10.0.314.0 C:\Programfiler\Zango\bin C:\Programfiler\Zango C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Reset Cursor.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Customer Support Center.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Games!.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Library.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Screensavers!.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Uninstall Instructions.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Zango\Zango Videos!.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Zango HKLM\Software\Zango HKLM\Software\Zango\Install HKLM\Software\Zango\Install#IE HKLM\Software\Zango\Install#OL HKLM\Software\Zango\Install#WT HKLM\Software\Zango\Install#WP HKLM\Software\Zango\Install#Install_Dir HKLM\Software\Zango\Install#Installed_From HKLM\Software\Zango\Install#SA HKLM\Software\Zango\Install\CmpMap HKLM\Software\Zango\Install\CmpMap#IE HKLM\Software\Zango\Install\CmpMap#OL HKLM\Software\Zango\Install\CmpMap#WT HKLM\Software\Zango\Install\CmpMap#WP HKLM\Software\Zango\Install\CmpMap#SA HKLM\Software\Zango\Zango HKLM\Software\Zango\Zango\Install HKLM\Software\Zango\Zango\Install#StartInstall HKLM\Software\Zango\Zango\Install#cookies_flag HKLM\Software\Zango\Zango\Install#IID HKLM\Software\Zango\Zango\Install#IID_prv HKLM\Software\Zango\Zango\Install#PrevVer HKLM\Software\Zango\Zango\Install#CurrentVer HKLM\Software\Zango\Zango\Install#CreateDate HKLM\Software\Zango\Zango\Install#CreateDateDW HKLM\Software\Zango\Zango\Install#icons_flag HKLM\Software\Zango\Zango\Install#HbHostOEPath HKLM\Software\Zango\Zango\MachineInfo HKLM\Software\Zango\Zango\MachineInfo#CID HKLM\Software\Zango\Zango\MachineInfo#CID_prv HKLM\Software\Zango\Zango\PI HKLM\Software\Zango\Zango\PI\3.2 HKLM\Software\Zango\Zango\PI\3.2#PID00 HKLM\Software\Zango\Zango\Updates HKLM\Software\Zango\Zango\Updates#InstallDate C:\WINDOWS\Prefetch\SRV.EXE-1E1C9A5F.pf Trojan.Error Safe Free C:\Programfiler\Error Safe Free HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: Setup Version HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: App Path HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#InstallLocation HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: Icon Group HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Inno Setup: User HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#UninstallString HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#QuietUninstallString HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#Publisher HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#URLInfoAbout HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#HelpLink HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#URLUpdateInfo HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#NoModify HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1#NoRepair Trojan.WinAntiSpyware/WinAntiVirus 2006/2007 HKCR\CLSID\{_CLSID_WAShellExecuteCheck} HKCR\CLSID\{_CLSID_WAShellExecuteCheck}#AppID HKCR\CLSID\{_CLSID_WAShellExecuteCheck}\LocalServer32 HKCR\CLSID\{_CLSID_WAShellExecuteCheck}\Programmable HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6} HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0 HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0 HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0\win32 HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0\FLAGS HKCR\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}\1.0\HELPDIR HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096} HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}\ProxyStubClsid HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}\ProxyStubClsid32 HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}\TypeLib HKCR\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}\TypeLib#Version Trojan.Security Toolbar C:\Documents and Settings\All Users\Start-meny\Online Security Guide.url C:\Documents and Settings\All Users\Start-meny\Security Troubleshooting.url Trojan.ErrorSafe C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Avisntallerer ErrorSafe.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Error Safe på nett.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Error Safe.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version\Ta kontakt med kundestøtten.lnk C:\Documents and Settings\All Users\Start-meny\Programmer\Error Safe Unregistered Version C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\ERS64.EXE C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\NI.ERSH_0001_N68E0602\SETUP.EXE C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\NI.UERSH_0001_N91M2407\SETUP.EXE C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\PROGRAMDATA\ERRORSAFEFREEINSTALL_NO[1].EXE C:\WINDOWS\SYSTEM32\ERRORSAFESETUP.EXE Malware.SpyLocked HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#UninstallString Trojan.Media-Codec/V4 C:\Programfiler\Video Add-on\isfmm.exe C:\Programfiler\Video Add-on\ot.ico C:\Programfiler\Video Add-on\ts.ico C:\Programfiler\Video Add-on\uninst.exe C:\Programfiler\Video Add-on HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#ProductionEnvironment HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#Publisher HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#UninstallString HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayIcon HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayVersion HKCR\multimediaControls.chl HKCR\multimediaControls.chl\CLSID Adware.Tracking Cookie C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@2o7[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][10].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][11].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][13].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][4].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][5].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][6].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][7].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][8].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][9].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adbrite[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adinterax[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adrevolver[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adserver[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adtech[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adultadworld[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@adultfriendfinder[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@advertising[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@advertising[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@advertising[3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@advertising[4].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@amsterdamlivexxx[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@apmebf[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@atdmt[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@bizadverts[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@camsexnow[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@casalemedia[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@casalemedia[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@casalemedia[3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@casalemedia[5].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@cassava[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@clicktorrent[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@countercentral[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@cpvfeed[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@doubleclick[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@drivecleaner[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@eroticlick[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@fastclick[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@fastclick[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@freepornlessons[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@fuckeduphandjobs[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@hitbox[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@indexstats[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@indextools[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@indextools[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@jays-xxx-links[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@jesextender[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][4].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][5].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][7].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@mediaplex[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@partner2profit[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@partypoker[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@popularscreensavers[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@porn365[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@pornenmeer[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@pornotube[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@questionmarket[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@realmedia[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@revenue[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@revsci[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@serving-sys[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@serving-sys[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@serving-sys[3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@serving-sys[4].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@sexlive2u[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@sextv1[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@socialmedia[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@specificclick[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@spylog[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@spylog[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@starware[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@statcounter[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@statcounter[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@tacoda[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@toplist[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][10].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][11].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][12].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][13].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][14].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][15].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][16].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][17].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][18].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][19].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][20].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][21].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][22].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][23].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][24].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][25].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][26].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][27].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][28].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][29].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][30].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][31].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][32].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][4].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][5].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][6].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][7].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][8].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][9].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@tradedoubler[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@usenext[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@whatpornsite[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@winantivirus[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][3].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@xxx[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@yourmedia[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@zedo[1].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@zedo[2].txt C:\Documents and Settings\Håvard Karlsnes\Cookies\håvard karlsnes@zedo[3].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@2o7[2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@adtech[2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@advertising[2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@atdmt[2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@atwola[1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@doubleclick[1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@drivecleaner[1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@mediaplex[1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@serving-sys[2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@specificclick[1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@spylog[1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@statcounter[1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@tacoda[2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard [email protected][1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@tradedoubler[2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@tribalfusion[1].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@winantivirus[2].txt C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Cookies\håvard karlsnes@zedo[2].txt Browser Hijacker.Favorites C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\FAVORITTER\ONLINE SECURITY TEST.URL Trojan.Unclassifed/LAF-Variant C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\LOKALE INNSTILLINGER\TEMP\LAF1.EXE Trojan.WinAntiSpyware/WinAntiVirus 2006 C:\DOCUMENTS AND SETTINGS\HåVARD KARLSNES\PROGRAMDATA\WINANTIVIRUSPRO2006FREEINSTALL_NO[1].EXE C:\PROGRAMFILER\ERROR SAFE\WASFFNT.EXE C:\WINDOWS\Prefetch\WASFFNT.EXE-15C2DB2C.pf Trojan.WinFixer C:\PROGRAMFILER\ERROR SAFE\ADWAREPROTECTOR.EXE C:\WINDOWS\Prefetch\ADWAREPROTECTOR.EXE-0D4334C9.pf Adware.Vundo-Variant C:\WINDOWS\SYSTEM32\BBWPCFPJ.DLL C:\WINDOWS\SYSTEM32\NOEEIHEG.DLL C:\WINDOWS\SYSTEM32\RYVWJAVA.DLL C:\WINDOWS\SYSTEM32\WUWGSLDX.DLL Trace.Known Threat Sources C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C1MJ41QN\g_head_top[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C5IF8T6F\g_bottom[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\SH2RSPMJ\bt_scan[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\452NCHEV\box[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C1MJ41QN\bt_buy_now[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\452NCHEV\footer_bg[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C5IF8T6F\header_bg_top[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\C1MJ41QN\top_box_bg[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\SH2RSPMJ\header2_bg[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\452NCHEV\circle[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\APSNW7UN\scns[1].gif C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\CZKZYV8B\order[1].htm C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temp\Temporary Internet Files\Content.IE5\CZKZYV8B\updates.errorsafe[1].0&ac=e33a0991-c63b-4319-841a-d1dde52e0b99&oid=3941993&suspicious=0&appid=ERSH&em=060f0b07000d032402161a190d5208441a0119 C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temporary Internet Files\Content.IE5\9AKUM5FG\dbver[1].dat Lenke til kommentar
norbat Skrevet 3. februar 2008 Del Skrevet 3. februar 2008 Start hjt, velg "Do a system scan only", sett merke framfor følgende linjer og klikk Fix checked: R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILE...s0p0O2t8dizZHOC R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=wKX1ILE...ccR6flAnJF1NpUE O3 - Toolbar: (no name) - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - (no file) O4 - HKLM\..\Run: [FreeBBAccess] C:\Program Files\FBB\FreeBBAccess\FreeBBAccess.exe O4 - HKLM\..\Run: [erscw] C:\Programfiler\Fellesfiler\Error Safe\erscw.exe -c O4 - HKCU\..\Run: [Error Safe] "C:\Programfiler\Error Safe Free\ers.exe" /min O4 - HKCU\..\Run: [AdwareProtector] C:\Programfiler\Error Safe\AdwareProtector.exe O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Programfiler\Video Add-on\isfmntr.exe O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0046C4.dat Hent Combofix, og legg det på skrivebordet Kjør combofix.exe, og følg veiledningen. Post loggfilen fra combofix (c:\combofix.txt) Lenke til kommentar
m0g1e Skrevet 3. februar 2008 Forfatter Del Skrevet 3. februar 2008 HJT-logg her: Tusen riktig takk for hjelpen ComboFix 08-02.03.1 - Håvard Karlsnes 2008-02-03 11:07:00.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.687 [GMT 1:00] Running from: E:\clean_box\ComboFix.exe * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Programdata\Microsoft\Network\Downloader\qmgr0.dat C:\Documents and Settings\All Users\Programdata\Microsoft\Network\Downloader\qmgr1.dat C:\Documents and Settings\Håvard Karlsnes\err.log C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316 C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\BrowserSearch\BrowserSearch.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\BrowserSearch\BrowserSearch.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Configurator\Configurator.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Configurator\Configurator.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ErrorSearch\ErrorSearchOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ErrorSearch\ErrorSearchOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Games\GamesOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Games\GamesOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\PitchLayout.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\PitchLayout.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\ToolbarLayout.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\ToolbarLayout.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\WeatherLayout.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Layouts\WeatherLayout.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Manager\ManagerOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Manager\ManagerOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Movies\MoviesOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Movies\MoviesOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Reference\ReferenceOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Reference\ReferenceOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\RelatedSearch\RelatedSearchOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\RelatedSearch\RelatedSearchOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Screensavers\ScreensaversOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Screensavers\ScreensaversOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\SearchAssistPlus\SearchAssistPlusOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\SearchAssistPlus\SearchAssistPlusOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\SearchMatch\SearchMatchOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\SearchMatch\SearchMatchOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Tem1CA.tmp C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Toolbar\TBProductsOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Toolbar\TBProductsOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ToolbarLogo\ToolbarLogoOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ToolbarLogo\ToolbarLogoOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ToolbarSearch\ToolbarSearchOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\ToolbarSearch\ToolbarSearchOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\TravelSearch\TravelSearchOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\TravelSearch\TravelSearchOptions.xml.backup C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Weather\AlertArchive.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Weather\WeatherOptions.xml C:\Documents and Settings\Håvard Karlsnes\Programdata\Starware316\Weather\WeatherOptions.xml.backup C:\Programfiler\screensavers.com C:\Programfiler\screensavers.com\SSSInst\bin\iebyterange.xml C:\Programfiler\screensavers.com\SSSInst\bin\iebyterange.xml.backup C:\Programfiler\screensavers.com\SSSInst\bin\SSSInst.dll C:\Programfiler\screensavers.com\SSSInst\bin\SSSUninst.exe C:\Programfiler\screensavers.com\Wallpaper\swpstart.exe C:\Programfiler\Starware316 C:\Programfiler\Starware316\brand.bmp C:\Programfiler\Starware316\icons\star_16.ico C:\Programfiler\Starware316\Starware316Config.xml C:\Programfiler\Starware316\Starware316Uninstall.exe C:\WINDOWS\cookies.ini C:\WINDOWS\system32\__c0022960.dat C:\WINDOWS\system32\__c002324A.dat C:\WINDOWS\system32\__c0023F21.dat C:\WINDOWS\system32\__c0025266.dat C:\WINDOWS\system32\__c0035220.dat C:\WINDOWS\system32\__c0042E52.dat C:\WINDOWS\system32\__c005A092.dat C:\WINDOWS\system32\__c00617C2.dat C:\WINDOWS\system32\__c0062AF.dat C:\WINDOWS\system32\__c00659D1.dat C:\WINDOWS\system32\__c006B7C4.dat C:\WINDOWS\system32\__c008142E.dat C:\WINDOWS\system32\__c0083DF9.dat C:\WINDOWS\system32\__c0093A96.dat C:\WINDOWS\system32\__c00A7BBD.dat C:\WINDOWS\system32\__c00AB340.dat C:\WINDOWS\system32\__c00B72F6.dat C:\WINDOWS\system32\__c00B9EC9.dat C:\WINDOWS\system32\__c00BBDE3.dat C:\WINDOWS\system32\__c00CAE57.dat C:\WINDOWS\system32\__c00CDC9A.dat C:\WINDOWS\system32\__c00D8C69.dat C:\WINDOWS\system32\__c00DC910.dat C:\WINDOWS\system32\__c00DAAF9.dat C:\WINDOWS\system32\__c00E4516.dat C:\WINDOWS\system32\__c00E8490.dat C:\WINDOWS\system32\__c00EE5D8.dat C:\WINDOWS\system32\adfqpqka.dll C:\WINDOWS\system32\anybsrtr.dll C:\WINDOWS\system32\bysmiaxi.dll C:\WINDOWS\system32\dafcegct.ini C:\WINDOWS\system32\eqatritn.dll C:\WINDOWS\system32\ewitpejo.dll C:\WINDOWS\system32\fbakuitx.dll C:\WINDOWS\system32\ffocvoaj.ini C:\WINDOWS\system32\fpwbtigl.dll C:\WINDOWS\system32\fsbfoomh.ini C:\WINDOWS\system32\fvylxubw.dll C:\WINDOWS\system32\gcryyxmh.dll C:\WINDOWS\system32\gilmnolm.dll C:\WINDOWS\system32\gnirnoln.dll C:\WINDOWS\system32\gotacqyb.dll C:\WINDOWS\system32\hbbrlfun.dll C:\WINDOWS\system32\hfvilfiy.dll C:\WINDOWS\system32\hhxotdht.ini C:\WINDOWS\system32\icefiapm.dll C:\WINDOWS\system32\ifirbybi.dll C:\WINDOWS\system32\jimulupb.dll C:\WINDOWS\system32\jiygqrog.dll C:\WINDOWS\system32\jmcwqjhm.dll C:\WINDOWS\system32\ltyhphuk.dll C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\mlkwvgjx.dll C:\WINDOWS\system32\mucaapsh.dll C:\WINDOWS\system32\nbimopne.dll C:\WINDOWS\system32\niyvildk.dll C:\WINDOWS\system32\npmiyyny.dll C:\WINDOWS\system32\nsqaodtt.dll C:\WINDOWS\system32\nvewgeyx.dll C:\WINDOWS\system32\ofobggvs.dll C:\WINDOWS\system32\ojkuroeu.dll C:\WINDOWS\system32\onbivsvy.dll C:\WINDOWS\system32\plminead.dll C:\WINDOWS\system32\ppppo.bak1 C:\WINDOWS\system32\ppppo.bak2 C:\WINDOWS\system32\ppppo.ini C:\WINDOWS\system32\ppppo.ini2 C:\WINDOWS\system32\ppppo.tmp C:\WINDOWS\system32\purfepoy.dll C:\WINDOWS\system32\qaggbhwl.dll C:\WINDOWS\system32\qejvnscf.dll C:\WINDOWS\system32\qlmfjybd.dll C:\WINDOWS\system32\qtrecgki.ini C:\WINDOWS\system32\quswmoja.dll C:\WINDOWS\system32\qvqhtpdb.ini C:\WINDOWS\system32\rerjgdgn.dll C:\WINDOWS\system32\rmyltmsb.dll C:\WINDOWS\system32\slmqasrf.dll C:\WINDOWS\system32\ssyiidrw.ini C:\WINDOWS\system32\storxjsk.dll C:\WINDOWS\system32\taqanqyr.ini C:\WINDOWS\system32\tlsgcyny.dll C:\WINDOWS\system32\uikdvjsp.dll C:\WINDOWS\system32\wbhcjpgl.dll C:\WINDOWS\system32\wcsyavsh.dll C:\WINDOWS\system32\wgpmbwbf.ini C:\WINDOWS\system32\whwashbi.dll C:\WINDOWS\system32\wjyarwha.dll C:\WINDOWS\system32\xjmexarb.dll C:\WINDOWS\system32\xlktnfdx.dll C:\WINDOWS\system32\yrasgtrk.dll C:\WINDOWS\system32\yyoiiucd.dll ----- BITS: Possible infected sites ----- hxxp://www.download.windowsupdate.com . ((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 ))))))))))))))))))))))))))))))) . 2008-02-03 01:19 . 2008-02-03 01:24 1,355 --a------ C:\WINDOWS\imsins.BAK 2008-02-02 18:58 . 2008-02-02 18:58 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\vlc 2008-02-02 17:18 . 2008-02-02 21:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste 2008-02-02 17:18 . 2008-02-02 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord 2008-02-02 17:15 . 2008-02-02 18:58 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Mine dokumenter 2008-02-02 17:15 . 2006-06-23 16:23 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter 2008-02-02 17:15 . 2008-02-02 20:36 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask 2008-02-02 17:11 . 2008-02-02 19:10 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2008-02-02 17:10 . 2008-02-02 17:10 <DIR> d-------- C:\Programfiler\CCleaner 2008-01-29 00:05 . 2008-02-03 01:02 <DIR> d-------- C:\Programfiler\DivX . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-03 10:02 --------- d-----w C:\Programfiler\Fellesfiler\Ahead 2008-02-03 00:51 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared 2008-02-03 00:49 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec 2008-02-02 23:58 --------- d-----w C:\Programfiler\LimeWire 2008-02-02 18:01 --------- d-----w C:\Programfiler\BitLord 2008-02-02 17:49 --------- d-----w C:\Programfiler\Yahoo! 2008-02-02 15:50 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP 2008-01-31 08:29 --------- d-----w C:\Documents and Settings\All Users\Programdata\ZangoSA 2007-12-15 02:03 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help 2006-09-05 19:00 1,362,977 ----a-w C:\Programfiler\BitLord_1.01.exe 2006-09-01 18:38 5,361,664 ----a-w C:\Programfiler\NordicBetMPP_PW1.exe 2006-07-27 13:09 1,701,471 ----a-w C:\Programfiler\kart2.pdf 2006-07-19 00:59 3,762,888 ----a-w C:\Programfiler\pokerheaven.exe 2006-07-15 00:14 359,112 ----a-w C:\Programfiler\LimeWireWin.exe 2006-07-14 23:34 9,350,344 ----a-w C:\Programfiler\MSN_Messenger.EXE 2006-07-14 16:17 12,766,208 ----a-w C:\Programfiler\MP10Setup.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360] "MSMSGS"="C:\Programfiler\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208] "AnyDVD"="C:\Programfiler\AnyDVD\AnyDVD.exe" [2006-10-15 18:03 497664] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe" [ ] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCMSMMSG"="BCMSMMSG.exe" [2003-02-24 17:34 122880 C:\WINDOWS\BCMSMMSG.exe] "SunJavaUpdateSched"="C:\Programfiler\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03 36975] "Logitech Utility"="Logi_MwX.Exe" [2003-12-17 08:50 19968 C:\WINDOWS\LOGI_MWX.EXE] "QuickTime Task"="C:\Programfiler\QuickTime\qttask.exe" [2006-10-30 20:06 282624] "iTunesHelper"="C:\Programfiler\iTunes\iTunesHelper.exe" [2006-09-25 14:54 229952] "GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll R0 esff;esff;C:\WINDOWS\system32\drivers\esff.sys [2005-10-07 11:49] R0 wasfsd;wasfsd;C:\WINDOWS\system32\drivers\wasfsd.sys [2006-11-09 14:48] S3 AR5523;3Com OfficeConnect Wireless 108Mbps 11g USB Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys [] . Contents of the 'Scheduled Tasks' folder "2007-11-22 18:16:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Programfiler\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-03 11:11:00 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Programfiler\Logitech\MouseWare\system\em_exec.exe C:\WINDOWS\system32\wdfmgr.exe C:\Programfiler\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe . ************************************************************************** . Completion time: 2008-02-03 11:13:12 - machine was rebooted ComboFix-quarantined-files.txt 2008-02-03 10:13:08 . 2008-02-03 00:25:08 --- E O F --- Lenke til kommentar
norbat Skrevet 3. februar 2008 Del Skrevet 3. februar 2008 Åpne notisblokk og kopier inn det som står i fet skrift under, lagre fila på skrivebordet som CFScript.txt. Dra deretter fila over Combofix-iconet. Combofix vil starte igjen. Post loggen. File:: C:\WINDOWS\imsins.BAK C:\WINDOWS\system32\drivers\esff.sys Folder:: C:\Documents and Settings\All Users\Programdata\ZangoSA Er denne noe du kjenner til: C:\Programfiler\pokerheaven.exe Er dette MSN eller et annet prog?: C\Programfiler\MSN_Messenger.EXE Lenke til kommentar
m0g1e Skrevet 3. februar 2008 Forfatter Del Skrevet 3. februar 2008 (endret) har nettopp installert NOD32 som fant C:\WINDOWS\system32\drivers\esff.sys og slettet denne. Også en del andre småting. Mulig de påvirker Combifix-prosessen under.. Legger ut ferdig logg fra NOD32 av hva som er fjernet etter hvert. Får forresten opp en feil i combofix.exe. Regner med at filene er allerede slettet kanskje? Fjernet esff.sys fra listen og prøvde på nytt. Likevel samme feil. "CFScript Name Error" "Were you trying to run CFScript?" "The name, CFScript apperas to be incorrectly spelt" Endret 3. februar 2008 av mogie Lenke til kommentar
norbat Skrevet 3. februar 2008 Del Skrevet 3. februar 2008 Dobbeltsjekk at fila er lagret som CFScript og at filendelsen er .txt Lenke til kommentar
m0g1e Skrevet 3. februar 2008 Forfatter Del Skrevet 3. februar 2008 takk leste litt fort.. ComboFix: Klikk for å se/fjerne spoilerteksten nedenfor ComboFix 08-02.03.1 - Håvard Karlsnes 2008-02-03 14:46:27.4 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.657 [GMT 1:00] Running from: C:\Documents and Settings\Håvard Karlsnes\Skrivebord\ComboFix.exe Command switches used :: C:\Documents and Settings\Håvard Karlsnes\Skrivebord\CFScript.txt * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE C:\WINDOWS\imsins.BAK C:\WINDOWS\system32\drivers\esff.sys . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Programdata\ZangoSA C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSA.dat C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSA_gdf.dat C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSA_kyf.dat C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSAEula.mht C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSAAbout.mht C:\Documents and Settings\All Users\Programdata\ZangoSA\ZangoSAau.dat C:\WINDOWS\imsins.BAK . ((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 ))))))))))))))))))))))))))))))) . 2008-02-03 14:02 . 2008-02-03 14:02 0 --a------ C:\WINDOWS\system32\REN4C.tmp 2008-02-03 14:02 . 2008-02-03 14:02 0 --a------ C:\WINDOWS\system32\REN4B.tmp 2008-02-03 13:02 . 2008-02-03 14:35 <DIR> d-------- C:\Programfiler\Opera 2008-02-03 11:55 . 2008-02-03 11:49 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys 2008-02-03 11:55 . 2008-02-03 11:49 298,104 --a------ C:\WINDOWS\system32\imon.dll 2008-02-03 11:55 . 2008-02-03 11:49 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys 2008-02-03 11:49 . 2008-02-03 13:01 <DIR> d-------- C:\Programfiler\ESET 2008-02-03 11:23 . 2008-02-03 11:23 <DIR> d-------- C:\Nero7 2008-02-03 11:13 . 2008-02-03 11:13 <DIR> d-------- C:\Documents and Settings\HÕvard Karlsnes\Lokale innstillinger 2008-02-02 18:58 . 2008-02-02 18:58 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\vlc 2008-02-02 17:18 . 2008-02-02 21:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste 2008-02-02 17:18 . 2008-02-02 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord 2008-02-02 17:15 . 2008-02-02 18:58 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Mine dokumenter 2008-02-02 17:15 . 2006-06-23 16:23 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler 2008-02-02 17:15 . 2008-02-03 14:18 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter 2008-02-02 17:15 . 2008-02-02 20:36 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask 2008-02-02 17:11 . 2008-02-03 11:29 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\Håvard Karlsnes\Programdata\SUPERAntiSpyware.com 2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2008-02-02 17:10 . 2008-02-02 17:10 <DIR> d-------- C:\Programfiler\CCleaner 2008-01-29 00:05 . 2008-02-03 01:02 <DIR> d-------- C:\Programfiler\DivX . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-03 12:53 --------- d-----w C:\Programfiler\QuickTime 2008-02-03 11:15 --------- d-----w C:\Programfiler\Fellesfiler\Error Safe 2008-02-03 10:02 --------- d-----w C:\Programfiler\Fellesfiler\Ahead 2008-02-03 00:51 --------- d-----w C:\Programfiler\Fellesfiler\Symantec Shared 2008-02-03 00:49 --------- d-----w C:\Documents and Settings\All Users\Programdata\Symantec 2008-02-02 23:58 --------- d-----w C:\Programfiler\LimeWire 2008-02-02 18:01 --------- d-----w C:\Programfiler\BitLord 2008-02-02 17:49 --------- d-----w C:\Programfiler\Yahoo! 2008-02-02 15:50 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP 2008-01-30 14:00 --------- d-----w C:\Documents and Settings\Håvard Karlsnes\Programdata\dvdcss 2007-12-15 02:03 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help 2007-11-26 22:26 90,089 --sh--w C:\WINDOWS\system32\ikllm.tmp 2007-11-13 01:52 6,956 --sh--w C:\WINDOWS\system32\tuxbc.tmp 2007-11-07 09:30 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll 2007-11-06 21:29 6,695 --sh--w C:\WINDOWS\system32\rtstv.tmp 2006-09-01 18:38 5,361,664 ----a-w C:\Programfiler\NordicBetMPP_PW1.exe 2006-07-27 13:09 1,701,471 ----a-w C:\Programfiler\kart2.pdf 2006-07-14 16:17 12,766,208 ----a-w C:\Programfiler\MP10Setup.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360] "AnyDVD"="C:\Programfiler\AnyDVD\AnyDVD.exe" [2006-10-15 18:03 497664] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe" [ ] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCMSMMSG"="BCMSMMSG.exe" [2003-02-24 17:34 122880 C:\WINDOWS\BCMSMMSG.exe] "GrooveMonitor"="C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016] "nod32kui"="C:\Programfiler\Eset\nod32kui.exe" [2008-02-03 11:49 949376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll R0 wasfsd;wasfsd;C:\WINDOWS\system32\drivers\wasfsd.sys [2006-11-09 14:48] S0 esff;esff;C:\WINDOWS\system32\drivers\esff.sys [] S3 AR5523;3Com OfficeConnect Wireless 108Mbps 11g USB Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys [] . Contents of the 'Scheduled Tasks' folder "2007-11-22 18:16:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Programfiler\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-03 14:47:09 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-02-03 14:47:38 ComboFix-quarantined-files.txt 2008-02-03 13:47:22 ComboFix2.txt 2008-02-03 13:18:25 ComboFix3.txt 2008-02-03 12:15:30 ComboFix4.txt 2008-02-03 10:13:12 . 2008-02-03 00:25:08 --- E O F --- NOD32 fant en mengde. Den rotet seg "selvsagt" inn i sikkerhetsgjenopprettings-delen av C:\. Men den fant og mer i /system32 etter hver og. Mulig det ikke var så lurt å kjøre NOD32 alikevel før jeg er ferdig med dette? Klikk for å se/fjerne spoilerteksten nedenfor Scan performed at: 2008-02-03 12:01 Date: 3.2.2008 Time: 12:01:54 Anti-Stealth technology is enabled. Scanned disks, folders and files: C:; C:\WINDOWS\system32\drivers\esff.sys C:\pagefile.sys - error opening (File locked) [4] C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{008B1723-BC8E-42A1-9D07-6C33765D827F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{01DD00A2-59F3-443D-98D2-18FBE37D7B67} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{024A4E95-B73C-436D-829C-0E552B6393CD} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{036D5C39-95D9-4831-BF41-6B0F75510ADA} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{056ED072-231B-4D5B-B1CC-3B50ACFC114D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{05E64C50-B890-4DC7-AE44-9AFD05418910} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{064B2F6F-A41A-4038-A25C-EF873BD419EF} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{06EF34B4-4334-4AD3-945D-78BFA4BEAC7E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{073F0D27-16B7-47BE-9793-1F63D52AEE4E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{081CB0D6-9F98-48BB-AD1E-05697ED2262A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{08407F67-7A2B-4100-B5D5-176BC2D2B904} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{08C26FFB-54D5-4EE4-AF9C-A30079837246} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{099395DC-006E-4278-8292-29561232A84C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0B689E58-3720-4EE4-A191-55AF4D70CE26} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0DEFAA49-778C-47F5-9AAA-CB6957C6FE3F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0E58E60B-C665-4B2B-8A9B-94AC76C5FF5F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0FEE1C87-B1EF-4E97-9195-B12F866A1580} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0FF9B4BD-1845-48FE-BC79-815F5E197C81} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{0AA4F299-5311-49D6-B7B6-1B83D9A550E9} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1090D1DD-1A68-4E4B-8D8F-647DD41BDE59} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{111B891B-35D6-4BC2-AFC7-0F9151B44E22} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1137ECDE-2F1B-4892-8BD8-92C280298000} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{130CF933-43DC-425F-A8C1-4AB27AF20F8D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{13A0BCD3-B2B7-4574-B26B-2D81C8D002E8} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{13ED4B3E-822B-49A5-A013-6D99BFAEDDFA} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{14DD271D-5B29-45C7-B3D5-E3B8BAA90A74} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{16279271-1C21-4930-B866-F98C83A9A9BD} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{16BDC0D5-B326-4E37-8355-F655333724D4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{17F728F6-7930-4C7C-90D4-C3AC7076EDB2} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{191CE0F5-DE35-4F2D-8F73-4CC9647E3330} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{19BED188-7B9A-4D99-906B-26B8DC4E7F44} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1A077C7A-57F6-44B7-80A5-5B648214819E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1A135101-EABF-4429-85D1-956B2955095A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1B241C1D-1466-4B3D-B0FB-DDA223CA407C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1D29C83D-2E35-4062-A929-D5157B539FA9} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1DCC3023-91D7-43A0-86C0-63C170092EFA} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1E195BFB-60A6-4BDF-B684-45AE8441B266} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1E56BDB9-FC6A-4406-AC5E-4C6AB496569C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{1F02654D-BDE6-4FB4-9D56-3F1AE018EE4B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{20087D76-10E6-48BC-AC51-81654A7AB3C0} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{22FEC44C-6185-42AF-9FBF-E91013EB89B5} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{24854F3B-6217-4C71-B7D8-B856042CA956} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2612A77B-9319-419F-A0E6-FB86A5DDC072} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2667A55C-D790-4C3D-AA0B-4ABB184B1F5B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{26C0C316-042E-41DE-A741-B2071CCE4440} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2764724C-9763-4585-A6A7-D8561B27511B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{27DBEC64-0249-49A5-93C6-2B65B1427FFF} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2A5F77CC-8D06-45D2-9BED-2A17A6B0D21B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2AC4DC0D-FC17-4A72-BBA8-3138D2B9A499} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2E61063D-B955-4474-B28E-44828490F874} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2E75F3D4-B59B-4865-9E6D-AA5C484CFDEB} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2F31B153-4E4A-4110-BEE8-61C599699A4F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2FFA00FD-5350-4A39-A9BF-9CF402D07960} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{2AA06100-DBA7-434A-AAAC-E8ECBAB8461B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{30722331-F080-4935-9825-FD1DBBC25FBE} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{30E170F5-198E-4FD4-B54D-EDF87BF2DACD} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{31B70DB8-C78C-41EA-82CE-0C22465A4DFF} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{32A052F0-20DB-4FC6-ADC1-8CD86F6DCEED} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3456E333-70AC-407C-A71E-6997244F28D7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{34C9E10F-82F4-4EB7-B0BF-2D8F66627BC3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{37C8ED4B-0651-442F-B121-B6FECB5E879B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{38F4BD13-E395-4968-AA83-B30717ED3061} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3907A71E-1C03-427F-9F80-CB6862DC32ED} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{39226931-BC4C-4B5B-90A6-D4D6C68F756E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{395B570B-E8CE-4E94-ADDB-45C24B9C788B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3A15C5CC-7DF3-4CA5-8A78-E5A86BE09E47} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3A21CC82-C79D-4E02-B10A-630080E8A427} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3B5000A5-DE75-46D9-A056-C23DFED7AC3F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3B650910-67DB-42D8-8A05-75ADAD160050} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3B6EDAB6-0C8E-4992-8FE5-C32F57C87903} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3DFDC176-2426-4C24-913A-54ED228B5C22} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{3FB1CA39-90F3-4ABE-8272-2F925ED1965A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4003A749-8A3B-4C69-8ADF-AE17A65698AF} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{403E5571-06E7-4A10-9D99-D7AF4FFF5096} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{408FFCBC-EDCC-4AEA-8D26-B4EE92BC165E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{40E62CBE-17D3-4A4C-AF61-6BB885A81706} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{41FA8D52-CD11-4E17-B916-987F95227AF4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{41FB17EB-B3EF-4562-BD83-1A84EA2CFA9F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4208D1D4-F982-471C-A40E-E9BF9E979160} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4210D639-2051-45BA-8756-58BD987E5D18} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{42539C6B-0787-462C-A95B-9A0E9D6734F1} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4440AD69-CB02-4747-A1CC-B47B182F14B8} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{462076CA-F4FF-4156-AC35-5A6F94C211FC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4776A06F-3DD5-4299-9CE5-28716EB04296} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{47A70894-2366-4C92-8A4A-4A6700F6AF03} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{496AB62D-177D-48E4-8CED-4E21E2E0DB70} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4A8A3B99-DA90-4C9E-9471-D779EF1A17EC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4CF15E1C-6698-4609-AD51-4D9EC556FB60} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4CF9DDF2-C320-48B2-A7C6-3A46DBE65A67} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4D289000-BFA2-4FE0-B249-09497C9BA9AA} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4DAD41C4-E9A4-42C1-A004-C6A2E49DC056} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4E15F791-2321-4CE0-9B69-EBEEE005F05C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4E82FF73-5DE0-4D40-ACE6-895EE996C129} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4EBAE578-9CE1-4C09-AA26-3834F552D015} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4EE62AD1-6422-4757-A1D2-63E627FBC939} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4EE8B557-4B6B-4168-B525-0F6D4B1FFF53} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4F2C172C-7618-487D-B7F2-968A8DF5115E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{4F79CA2C-91D6-4333-A87B-7B039B372636} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{509E1F18-8712-4ADB-A049-97F28B923A55} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{51D2B3DB-054E-48E4-8B6B-D3A0BFDB96A3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{52F040DD-27B9-45BC-924C-39D904D50FE2} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5354FA07-6429-4EDB-BE3E-AA627BD22B9A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5536834D-3CF0-4912-B74D-F09D3F4AACCD} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{558BBB88-BB43-4806-AA95-E198B123B407} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{560C24CB-5F87-404B-9632-5956E724E2AD} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5685C2E3-F0A1-44FB-96A7-0F8C7BB1BEB1} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5732C949-1794-4BF0-88D0-87196A266F58} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{58442B28-B0E2-48CD-9A80-8E8B4BF957A4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5876736D-C7CF-41DE-9AD7-713310A43328} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{58904820-B3E9-4E05-B192-CAAD746BDC61} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{595A6C0B-23B5-4AD0-B9BF-89414963E1A8} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5A22CF1F-C34F-4081-B655-9837FAD87CA7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5A6AA0EA-88B4-441D-AA21-8AC2DB18DB1D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5A81A196-2451-45CC-83DA-DFC860E00561} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5AD8BEBC-DAA5-4CF4-BC56-2DD5736933F4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5B1DFA2E-1B6C-432E-92D8-7E98964836A6} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5C486079-55D3-4DA5-A7B2-5401E80F36E3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5C90B513-6E1E-42D3-A351-F74188860DDB} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5D0069D3-8B45-4644-9A60-5B97A9B95CC2} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5E756729-B60C-4E8A-BF78-ECBC250C6C3F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{5AAF69C7-491C-4948-BBEA-D19A65DC5C4A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6082B309-7689-41C3-B30E-EDB1A6620635} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{608631E3-E5F8-487E-8F5A-E0806BB21CAC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{60E1D2F4-417D-4661-858D-B79042013DF7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{61491A28-C625-44F9-A897-549027607AE7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{62128B22-DFFD-4723-80E8-F8B13922669E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{624A7E8F-55A9-4548-81CF-A22755B2043B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{655BF6CC-A94A-4261-A156-AB0A5F3E9733} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{65C4E1C7-EFFD-47D2-ABEC-B7398FDED112} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{66129F9C-12D2-4178-A781-78B248578A7C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{661AA243-A417-4712-9959-582F61300B6C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{66B504D1-8436-44E6-87AD-73E863478CE6} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6732345F-5107-4F07-B6D7-8FF1B93DFB3D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{679E3DCB-2B67-48AA-8025-807D161B868B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{686F0732-94D9-41EB-8220-64DAC7B35582} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{68F54ADC-8B81-4E80-8BE4-73DEBF23A853} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6B7A439E-6E79-49D2-AB66-1062EEB9963C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6BFA614A-82DB-4B24-9373-FEBB3690CE83} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6C8C86D1-7456-442A-A47C-44F3858300CA} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6CBF9D30-1D8F-44DA-B516-5C4FDF2F124F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6CD8DF42-D85E-451C-A732-35813C88156D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6E0116F9-0DEB-4018-A7E0-F3FAAC21CDD9} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6E5171E1-925C-4D9F-AD49-EFE92D2EA63F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6F728F73-C1C4-408F-B3F9-E5429737FD54} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{6FBE61FE-767C-46EB-9AFE-E8B1F2D44038} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{71241DA0-C0BD-48D2-B282-664AD010ACFC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{75DC2900-0BA3-4B5D-A81A-950EF7DA8FE9} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{75E80A42-57AA-4DAA-A878-767D5B3FA956} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{76E31F0F-3243-4F23-A8A4-183F5207B4EC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{773EC171-D5BA-4A12-8A62-6FDC43BFE290} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{77C2D848-9441-447C-99C5-D5062D3DD37F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{78D34A78-1A2E-4BC4-AA06-B043D11D44F5} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7A420644-226A-4839-9F77-B13A70F8A079} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7A5DB546-D007-4F3C-9BF6-4D07B00AE0A5} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7B875E69-76CD-486B-8CFC-000FE299767B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7BDA2EDC-5F77-462E-8ED7-352DF68BCEB0} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7C439763-B18E-4DEF-BFD1-A7D677928583} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7CE65C08-8D46-43C9-939F-198014ED038F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7DAC6D12-7947-45A3-A93E-217A3436405C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7EA31C19-CDCF-4B15-9A07-DE7B917428F3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{7FAEAAC1-D460-4BF0-88ED-E928347B25AF} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{807BA362-BD25-499B-9C3C-19A4610981C3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{815230BA-7E24-44EB-8B64-6F6DCCE10C1E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{82ACB026-BCD5-45E3-B994-5187CF39CC3B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8500C2CB-18C7-44D3-ACA0-4837D2516F34} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{85C584EC-C2E7-49D5-8901-36067E15F40B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8662FF23-3D96-4F4A-8B9D-435140D1FD1E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{866CC55C-72DB-4A67-A2C2-3C48EA6952AC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{867D2714-4009-425E-86A1-4C91E5928E33} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8755445B-1787-4CA7-A17C-E29DF86E4DC8} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8791321C-9578-4118-A2D2-CA9A7F535AB4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{896FA546-2CD5-48D2-912B-29F2EEC391E2} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8979223A-471B-443D-9DC2-9351FEB62935} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8A3FEC13-ACE6-479D-A7B6-E7D9443E58E5} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8A7C279A-9A69-4BB9-B2DA-61BB1871CDA8} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8C093ACA-72F7-4898-AD33-166013619EF7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8C89CF68-E0AF-4E16-897A-525AEB8183BB} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8DA2BFC1-1F96-449E-A686-9B3F46375548} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8E23F2AC-ABF0-4E26-AAE0-1582394D4030} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8E2E6603-15A5-45D4-BB60-F82E8979E792} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8E6AB398-A7CA-48C1-9D8B-30F2D4F78A6C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8ED92A9F-D33C-427B-9BBE-F8CF84CB30C4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{8F568485-4DBD-4462-9A00-5DBD9FBF007A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{907AD658-1E6B-4F76-A37C-13131E1F493F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{91DF264A-D22F-452D-A431-9DAFDCE8327A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{91F26766-8FC1-455A-BA02-A458B273F3BE} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{930D3E40-0267-4B37-9C10-413186E4553A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9324686B-C645-4FC3-92CE-583FDDF507E9} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{93F8D128-7DA0-4F3F-811E-084CBDB3763E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{943A2F59-BE56-4656-BBD8-FC164BD3EC6A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9573009E-7DCC-42E2-8231-AE0C1309482E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9598DA1F-96FF-473D-B1BE-0FBD9CF34B5E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{96491F6C-A954-45B9-88A7-0D18D05DC6F9} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{96BA9ACA-069B-475C-A11F-637D44787D04} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{970109A1-895E-4CBD-8E66-893E63C11995} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{970C31B3-8DA6-4478-B0C2-E2A2C31DAEFC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{97126FBD-6027-4B4E-8901-008520720D8D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{97673E43-DD28-475D-A5B1-C7814586674F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{986DAFA7-D9DB-4875-A5EA-C64E944BA982} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9A2760DD-6689-4A8E-A587-739B1ADAF1A6} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9A4FA626-B348-4F06-AC96-7A02BC38C650} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9A700283-C1FD-489A-9CF2-787F4A6665CE} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9A727C33-E182-410E-9E70-3CC5D9A9478A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9B1FC09B-4EBB-4170-B0CB-9D699636AC69} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9B6EE683-B49A-4591-9B8D-AEB6FED56FB6} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9C2CB8FB-11D3-4F74-BDBF-61886E81F1EC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9CC491FF-2F6D-488F-9623-A92E5EB9C9D1} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9D610A2B-5827-4D71-9D23-537406FD0EBD} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9E9267DF-18DC-4CBB-8F8C-B7E3E402F8D1} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9F420C4B-E7A3-4D4D-AB7A-F583F3FF14E1} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9FF42B37-0881-4B57-A1DF-C072ABAE7DF3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{9AA31B1D-CE09-481A-BC22-7C56F9F0F6A3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A127AED5-3A65-4345-838A-E53AA46927DB} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A148EAB8-35F2-4953-B813-C922D63C01F1} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A2293877-79F3-4FD2-B030-C8BA56C473E0} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A2D96DE9-E2B8-4D68-85CC-45846C711DB7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A3763911-BBD7-46D8-B17E-C64959EDEECD} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A3E8ACC2-1139-40CF-AF46-8E107F6934D9} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A51A1BC0-F888-4705-8B67-2105B07D8DF2} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A52240A8-E755-4347-AB2B-3C28260AC179} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A5F098AB-1B4C-4EC3-B44E-BBD37009795B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A73ACEE1-246B-4AF1-B1F3-B5D3ADD5A27F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A765C0A1-76F5-4C6C-A462-CFAE96456104} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A8C7EDCC-4F2E-4B8B-9213-012800964C15} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A908E77B-1E6D-4B1F-89D1-49B4E6594C89} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{A95A2298-CF06-4D85-8CD6-38044E5815C8} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AB700E7A-37B2-4748-8066-93C75961D4C4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{ACAE2983-7637-4AD9-A393-0ACBC6F29412} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AE3F96DF-3CD8-4620-8E99-4F3057475C90} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AF84B881-191D-4335-9CBF-7D9CA139A29A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B081DD9D-A5FD-4947-A032-8AE32C257B87} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B0DF18B8-22A7-4600-8390-08ED3681E01C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B101CA8D-2A42-47A4-A973-38BFCED929C4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B21F620C-E16A-44C3-96C4-E46D18089227} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B52978AA-1DEC-45ED-9FD3-05D6E557D2BA} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B73BE9B3-B666-44C2-8F84-D7DE1E9C262E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B76673A2-EBCE-40CE-AF32-08E01B346B14} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B8152100-8F24-4658-8676-92D81E5DF693} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B81AF3E5-855B-4F2A-97C8-957E0CB18B38} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{B980D3BC-92DB-415F-8F6C-8763197170C0} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BA4D7E26-5294-4995-A8D5-043990656627} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BA751B3F-1029-44A9-BE8A-B47C12248E0C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BB5C51A6-851F-4A82-813A-6A3BB18F23DB} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BBD366B5-2E11-4421-BB90-80726B77FDEF} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BBFB1986-5377-410A-87AD-632175FB10CE} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BD1C8E87-70E2-402F-A04F-F31F4A3EF0FA} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BDD4E128-59BE-4509-B8C5-6DF5182DED60} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BFE7896C-97CE-4DC0-A915-99106C950436} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{BFFA4F92-9F8B-46CF-9CDA-C91D45544108} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C14D58CA-8468-4FA5-B61C-39BE6A500CC0} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C21C6949-7FE4-423E-8403-4706259A281F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C27EAFED-4EF2-48F1-8E4C-F69AB74C483B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C2CAF54A-6FD8-4BDB-A95F-C11466AA5A9D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C2EF71D9-71D4-4B52-AA2D-6A64009F4F80} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C374AE67-B308-4AA2-A5B3-A7EF8826E68F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C4862841-FF42-48CA-870D-14B33519B932} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C4A58A08-0A3D-4AFB-8865-42B91D615516} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C5418266-03E0-47D7-AA69-200407583ED4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C5543FF1-8D47-430F-BD70-C4AF76743385} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C5A05500-F577-4255-96A4-5EF4B5409C73} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C726584D-6633-4EC5-BECB-B89F2AC972B8} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C7D09B4A-2483-4B8D-A073-C5C7BD31E180} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C83E5705-B674-4461-96DF-979A266651A3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C92E0623-BD19-4879-849D-786B3EDC5756} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{C9A34610-219B-4EC4-8FCA-816A7DD8A814} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CA3555BF-9619-4109-AF7F-A599F751CDCC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CA733AA1-9F13-48EA-BF5C-9A1155F628F5} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CAB5C4C3-D2EB-4E99-8D23-A4F6A3D3B36D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CC14497B-F986-4F85-80E7-EADC0B595750} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CC4A09F5-222B-41E8-A2CA-BF438C10350D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CDC0E1D2-ECC8-40EA-950C-0B59A49FE457} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CEDEBDCE-3D92-4FAF-82F3-78F27C99F5DC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CF4F5293-C4E4-4D16-9CCA-31D3F331B4B5} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CF981F48-6D20-4EF9-A931-1669DB78ABE4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CFC0FDC0-BA04-4881-B94C-2AD29ED1DABA} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CFFB1C87-9E01-4770-A8A3-19B1E71CDA8A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{CAA130A3-372A-466C-8DCF-09284E70D40E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D2DCD2FF-9195-418C-BFA0-836A68D536AB} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D320F4A1-5BF1-4F38-88AD-3EF0B101B193} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D45CA94D-F06A-48C8-9376-2BC4DEA2E374} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D4C5F10A-AAE6-48A0-9E5A-0F39A23B5D49} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D52D5CF4-F444-47C8-A564-2984EA2EA0E9} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D6C40EE2-A107-4543-B58B-939E7880EEB0} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D8AB4C79-0383-4B16-A301-45512433EF46} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D8B48CF8-3B28-427D-9A83-35C99BD760BF} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D91BF3CC-5218-4E72-AF3C-2C82D40EAA1F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{D939B013-B128-438F-B6FC-6F88E5B21B72} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DA109444-F044-4F43-81C3-704EE6802E5E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DA620C82-5F56-4ED1-A632-ED060F946237} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DB1DE5AD-11AD-4DED-8F02-00117BFBD33E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DB52A583-4D05-4D9A-8FEA-C3869F0026CD} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DBF17007-8DB8-498F-9A1A-C06A31F2D94B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DDE749EC-3D7C-4E63-A5CE-A0E200D3FF34} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DE7B8ADD-2841-4A82-B5CE-1F77B05D2937} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DE9DFD42-8C87-4A9A-A307-B9A45776945C} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DEACD288-9853-4B0E-BF84-28B6988F692E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{DFC20BD6-0ACB-41FB-80B5-DD6C14C3DFA7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E195BE00-0BEE-437C-AE3C-6E94ADCD8BD0} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E2F7EA35-82F0-406B-8202-DAA22C6F1BF5} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E3AFACCA-9C34-4E20-9DB7-1CB303EABA0D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E404E7AB-0514-49D2-BA69-2131F30F3410} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E451BC95-41D6-435F-A8E7-A301F54CBA12} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E55AB43A-1742-4722-B86B-F3A3C89CB70E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E6E4F04B-40FD-4441-8376-1242022B67C3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E90171DD-844C-42BF-84F0-44F75C2C33B1} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{E9A9E595-E66C-454B-98FB-1C1E9241E1C3} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EA2224BA-0CC0-42EA-9CD3-C94817C7AC36} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EC625808-A82B-4872-9AA2-96F80CCF5824} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{ED94A634-06E3-4889-BD02-33715730F64A} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EDA3C584-BC0D-4047-9EB7-7F2AAE6777A2} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EE61872B-4C3F-4E75-9BDE-CB14C31D8419} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EF3DAAA4-29F5-46FC-A178-93AF7C8FD3BB} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{EF95D932-7672-4872-B0F0-58CD997F3EAE} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F0A30489-CE75-4ADE-BC9E-F444ED8282F0} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F0D76BB1-FD36-4BB5-A89F-385FF4CF395B} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F195CAA0-A6AB-4564-81BE-74162CEFBA73} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F1E324CD-5B79-4005-88EA-C897BAD4D827} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F1FFCE9D-4CC7-422F-BCCA-20E8DD104016} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F216B71F-4D10-4794-AF53-47786EF473D4} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F23F006D-C0AC-40AE-95BF-DCBD94E5750D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F286BA57-F3E2-4728-842E-66EEE7D53830} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F45E1D21-C28E-4B79-870D-854C7E824923} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F4711847-28A4-4A2D-911B-CF21E4E921A7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{F6A2D1C3-A6A5-4438-B3F6-FABBA8D7C38F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FAEF6443-734C-4630-8D4A-A42E658EEFBC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FB5FB160-692D-4D10-B2AE-C9A3B40C5E20} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FB9F279B-7A55-4795-BBB3-62A60FD9952F} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FBC6181D-7D4D-4B25-B870-DA600D3DBF4E} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FCE901CB-4452-4EF9-A271-587911ACA548} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FD8AE61D-4F2C-4BBD-8F62-B3371812507D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FDF4161E-1DE9-43A5-9A8E-64A9607D9C83} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FE96D84E-17DD-407F-8FB6-365725F43888} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FEF7CDA3-B4FC-4946-9BB0-914554B1C295} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FEFD6B7F-BD11-4951-954A-1728B34EA89D} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{FFB7B44D-DFC3-4087-AD71-FDE664F10385} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AA001D29-D8F8-41A7-860C-EF0C56B3E0CC} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AA7FEBAC-7D7B-433B-8EE5-154C10D7E644} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »{AAA6EF7F-DE9F-48CE-811B-F326BFCE67D7} - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »backup.db - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 19-02-18.SBU »ZIP »backup.db - error - password-protected file C:\Documents and Settings\Håvard Karlsnes\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\Håvard Karlsnes\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Temporary Internet Files\Content.IE5\XPH0ABLV\mosx1024[1] - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\Documents and Settings\Håvard Karlsnes\Programdata\setup_no[1].exe - probably a variant of Win32/Adware.RogueApp application C:\Documents and Settings\LocalService\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\LocalService\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\LocalService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\LocalService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\NetworkService\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\NetworkService\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\NetworkService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\NetworkService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\program files\fbb\freebbaccess\freebbaccess.exe - Win32/Dialer.Agent.AK application - deleted C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/106-va-stacie_orrico_-_o_come_all_ye_faithful-b2r.mp3 - incorrect CRC checksum, the file may be damaged C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/203-va-katarzyna_skrzynecka_-_oszaleli_anieli-b2r.mp3 - incorrect CRC checksum, the file may be damaged C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/306-va-mel_and_kim_-_rockin_around_the_christmas_tree-b2r.mp3 - incorrect CRC checksum, the file may be damaged C:\Programfiler\BitLord\Downloads\Classic.School.Girls.4.DANiSH.XXX.DVDRip.XviD-DKPORNA\dkp-csg4.rar »RAR »dkp-csg4.avi - next archive volume not found C:\Programfiler\BitLord\Downloads\Prison.Break.S02E18.HDTV.XviD-XOR\xor-prison.break.218.rar »RAR »prison.break.s02e18.hdtv.xvid-xor.avi - next archive volume not found C:\Programfiler\EA GAMES\Battlefield 2\pylib-2.3.4.zip »ZIP »test/testtar.tar »TAR - archive damaged C:\Programfiler\Fellesfiler\Error Safe\erscw.exe - Win32/Adware.SystemDoctor application - deleted C:\Programfiler\Fellesfiler\Error Safe\ESFF.exe - Win32/Adware.ErrorSafe application - deleted C:\Programfiler\Fellesfiler\Error Safe\ESPChck.dll - Win32/Adware.ErrorSafe application - deleted C:\QooBox\Quarantine\C\Programfiler\Screensavers.com\SSSInst\bin\SSSInst.dll.vir - Win32/Adware.Comet application - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\adfqpqka.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\anybsrtr.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\bysmiaxi.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\eqatritn.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\ewitpejo.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\fbakuitx.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\fpwbtigl.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\fvylxubw.dll.vir - Win32/BHO.NAV trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\gcryyxmh.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\gilmnolm.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\gnirnoln.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\gotacqyb.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\hbbrlfun.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\hfvilfiy.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\icefiapm.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\ifirbybi.dll.vir - Win32/BHO.NAV trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\jimulupb.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\jiygqrog.dll.vir - Win32/BHO.NAV trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\jmcwqjhm.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\ltyhphuk.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\mlkwvgjx.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\mucaapsh.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\nbimopne.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\niyvildk.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\npmiyyny.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\nsqaodtt.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\nvewgeyx.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\ofobggvs.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\ojkuroeu.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\onbivsvy.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\plminead.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\purfepoy.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\qaggbhwl.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\qejvnscf.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\qlmfjybd.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\quswmoja.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\rerjgdgn.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\rmyltmsb.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\slmqasrf.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\storxjsk.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\tlsgcyny.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\uikdvjsp.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\wbhcjpgl.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\wcsyavsh.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\whwashbi.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\wjyarwha.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\xjmexarb.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\xlktnfdx.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\yrasgtrk.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\yyoiiucd.dll.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c0022960.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c002324A.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c0023F21.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c0025266.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c0035220.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c0042E52.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c005A092.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00617C2.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c0062AF.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00659D1.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c006B7C4.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c008142E.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c0083DF9.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c0093A96.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00A7BBD.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00AB340.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00B72F6.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00B9EC9.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00BBDE3.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00CAE57.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00CDC9A.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00D8C69.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00DAAF9.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00DC910.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00E4516.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00E8490.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\QooBox\Quarantine\C\WINDOWS\system32\__c00EE5D8.dat.vir - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP229\A0109587.dll - a variant of Win32/Adware.Virtumonde application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109645.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109646.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109647.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109648.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109649.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109680.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109682.dll - a variant of Win32/Adware.Virtumonde application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109684.dll - a variant of Win32/Adware.Virtumonde application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP231\A0109685.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP232\A0110682.dll - probably a variant of Win32/Adware.Virtumonde.FP application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP232\A0110683.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP232\A0111705.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP233\A0111738.exe - probably a variant of Win32/Adware.180Solutions application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP234\A0111784.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP234\A0111785.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP234\A0111786.dll - a variant of Win32/Adware.Virtumonde application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP237\A0111854.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP237\A0111855.dll - probably a variant of Win32/Adware.Virtumonde.FP application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP237\A0111856.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP237\A0111857.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP238\A0112854.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP239\A0112881.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP241\A0112964.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP241\A0112965.dll - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP241\A0112986.dll - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP241\A0113981.exe - Win32/Adware.180Solutions application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP243\A0114973.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP243\A0114974.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP244\A0114992.dll - Win32/TrojanDownloader.FakeAlert.C trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP247\A0116077.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP248\A0117077.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118101.exe - Win32/Adware.SystemDoctor application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118102.exe - Win32/Adware.ErrorSafe application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118103.dll - Win32/Adware.ErrorSafe application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118104.dll - Win32/Adware.ErrorSafe application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118105.dll - Win32/Adware.ErrorSafe application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118107.dll - Win32/Adware.ErrorSafe application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP249\A0118110.sys - Win32/Rootkit.Agent.AF trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118120.exe - Win32/Adware.180Solutions application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118121.dll - probably a variant of Win32/Adware.Agent application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118138.exe - Win32/Adware.VirusProtectPro application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118149.dll - a variant of Win32/Adware.Virtumonde.FP application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118154.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118155.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118156.dll - a variant of Win32/BHO.G trojan C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118157.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118158.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118159.dll - a variant of Win32/BHO.G trojan C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118161.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118162.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118164.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118165.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118166.dll - Win32/Adware.Virtumonde application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118169.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118170.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118172.dll - probably a variant of Win32/Adware.HotBar application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118174.dll - Win32/Adware.HotBar application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118175.dll - Win32/Adware.HotBar application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118176.dll - probably a variant of Win32/Adware.HotBar application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118177.dll - Win32/Adware.Toolbar.ZangoBar application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118179.exe - Win32/Adware.HotBar application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118180.exe - probably a variant of Win32/Adware.HotBar application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118182.dll - probably a variant of Win32/Adware.HotBar application C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118184.exe - Win32/Adware.HotBar application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118185.dll - Win32/Adware.HotBar application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118198.exe - Win32/Adware.WinFixer application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118200.exe - Win32/TrojanDownloader.Zlob.BKT trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118204.exe - Win32/Adware.WinFixer application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118207.dll - a variant of Win32/BHO.G trojan C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118208.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118209.dll - a variant of Win32/BHO.G trojan C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118210.dll - Win32/BHO.G trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP250\A0118307.exe - a variant of Win32/TrojanDownloader.Dluca trojan C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119439.dll - Win32/Adware.Comet application - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119445.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119446.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119447.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119448.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119449.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119450.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119451.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119452.dll - Win32/BHO.NAV trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119453.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119454.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119455.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119456.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119457.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119458.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119459.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119460.dll - Win32/BHO.NAV trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119461.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119462.dll - Win32/BHO.NAV trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119463.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119464.dll - Win32/TrojanDownloader.Agent.NSM trojan - deleted C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119465.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119466.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119467.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119468.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119469.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119470.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119471.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119472.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119473.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119474.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119475.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119476.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119477.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119478.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119479.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119480.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119481.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119482.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119483.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119484.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119485.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119486.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119487.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119488.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119489.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119490.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119491.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119492.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119493.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119494.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119495.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119496.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119497.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119498.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119499.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119500.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119501.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119502.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119503.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119504.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119505.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119506.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119507.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119508.rbf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119509.rbf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119510.rbf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119511.rbf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119512.rbf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119513.rbf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119514.rbf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119515.rbf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119516.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119517.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119518.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119519.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119520.EXE - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119521.old - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119522.old - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119523.lnk - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119524.lnk - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119525.lnk - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119526.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119527.VBS - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119528.VBS - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119529.VBS - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119530.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119531.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119532.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119533.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119534.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119535.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119536.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119537.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119538.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119539.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119540.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119541.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119542.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119543.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119544.sys - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119545.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119546.reg - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119547.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119548.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119549.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119550.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119551.cf - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119552.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119553.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119554.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119555.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119556.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119557.reg - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119558.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119559.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119560.com - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119561.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119562.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119563.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119564.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119565.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119566.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119567.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119568.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119569.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119570.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119571.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119572.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119573.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119574.lnk - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119575.lnk - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119576.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119577.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119578.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119579.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119580.sys - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119581.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119582.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119583.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119584.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119585.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119586.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119587.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119588.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119589.sys - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119590.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119591.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119592.reg - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119593.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119594.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119595.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119596.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119597.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119598.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119599.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119600.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119601.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119602.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119603.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119604.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119605.com - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119606.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119607.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119608.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119609.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119610.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119611.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119612.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119613.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119614.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119615.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119616.vbs - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119617.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119618.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119619.bat - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119620.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119621.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119622.dll - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119623.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119624.EXE - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119625.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119626.exe - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119627.ini - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\A0119628.lnk - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\change.log - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\change.log.1 - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\change.log.2 - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\RestorePointSize - error opening [4] C:\System Volume Information\_restore{724444A4-FDCC-448B-8181-39F0C9F10A53}\RP255\rp.log - error opening [4] C:\WINDOWS\system32\fcosxxuf.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\fvplt.dll - a variant of Win32/TrojanDownloader.Dluca.CM trojan C:\WINDOWS\system32\lvrehndg.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\nrclqgvc.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\qockwxnu.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\retbjnyp.dll - Win32/BHO.NAV trojan Scanning interrupted by user! Number of scanned files: 185290 Number of threats found: 185 Number of files cleaned: 184 Number of active threats: 1 Time of completion: 13:01:19 Total scanning time: 3565 sec (00:59:25) Notes: [4] File cannot be opened. It may be in use by another application or operating system. Lenke til kommentar
norbat Skrevet 3. februar 2008 Del Skrevet 3. februar 2008 Ønsker at du følger veiledning og ikke begynner å gjøre så mye annet. Du gjør selvfølgelig hva du vil, men det er lett at det kan oppstå uklarheter. De fleste filene NOD fant er karantenefiler og filer i restore-mappa. Disse er ufarlig og vil bli fjernet på slutten av supporten Opprett en ny CFScript.txt fil med følgende innhold og gjennta prosedyren: File:: C:\WINDOWS\system32\drivers\wasfsd.sys C:\WINDOWS\system32\REN4C.tmp C:\WINDOWS\system32\REN4B.tmp C:\WINDOWS\system32\ikllm.tmp C:\WINDOWS\system32\tuxbc.tmp C:\WINDOWS\system32\rtstv.tmp Folder:: C:\Programfiler\Fellesfiler\Error Safe C:\Programfiler\Fellesfiler\Symantec Shared C:\Documents and Settings\All Users\Programdata\Symantec Post loggen på ny. Deretter: Fjern karantenefilene i SAS Fjern combofix ved å skrive combofix /u i kjør-feltet (Start->Kjør). Restart PC-en Kjør en full scan med ditt av-prog. (I denne sammenheng NOD). Post HJT-logg (før du kjører hjt, forandrer du programnavnet, hijackthis, til noe annet eks. mogie) og fortell om NOD fortsatt finner noe og evt. hvor disse filene blir funnet. Lenke til kommentar
m0g1e Skrevet 3. februar 2008 Forfatter Del Skrevet 3. februar 2008 HJT-logg: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:52:06, on 03.02.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\BCMSMMSG.exe C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe C:\Programfiler\Eset\nod32kui.exe C:\WINDOWS\system32\ctfmon.exe C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Programfiler\Eset\nod32krn.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe E:\clean_box\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.5.0_03\bin\ssv.dll (file missing) O4 - HKLM\..\Run: [bCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programfiler\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [nod32kui] "C:\Programfiler\Eset\nod32kui.exe" /WAITSERVICE O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Google Search - res://c:\programfiler\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\programfiler\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\programfiler\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programfiler\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\programfiler\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\programfiler\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe O15 - Trusted Zone: http://www.download.com O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programfiler\Eset\nod32krn.exe -- End of file - 4577 bytes Kjører en NOD32.scan nå.. Lenke til kommentar
m0g1e Skrevet 3. februar 2008 Forfatter Del Skrevet 3. februar 2008 (endret) NOD32-logg: Scan performed at: 03.02.2008 15:57:37 Scanning Log NOD32 version 2845 (20080202) NT Operating memory - is OK Date: 3.2.2008 Time: 15:57:44 Anti-Stealth technology is enabled. Scanned disks, folders and files: C: C:\pagefile.sys - error opening (File locked) [4] C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »backup.db - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 19-02-18.SBU »ZIP »backup.db - error - password-protected file C:\Documents and Settings\Håvard Karlsnes\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\Håvard Karlsnes\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\Håvard Karlsnes\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\Håvard Karlsnes\Mine dokumenter\downloads\sinstaller2.exe »NSIS »SSSInst.dll - Win32/Adware.Comet application C:\Documents and Settings\LocalService\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\LocalService\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\LocalService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\LocalService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\NetworkService\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\NetworkService\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\NetworkService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\NetworkService\Lokale innstillinger\Programdata\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\Nero7\nero7premium\Nero-7.7.5.1_eng_update.exe »RAR »Cab\E4060BF5.cab »CAB »rootFEAA0A71.img »GZ - archive damaged C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/106-va-stacie_orrico_-_o_come_all_ye_faithful-b2r.mp3 - incorrect CRC checksum, the file may be damaged C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/203-va-katarzyna_skrzynecka_-_oszaleli_anieli-b2r.mp3 - incorrect CRC checksum, the file may be damaged C:\Programfiler\BitLord\Downloads\The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO.zip »ZIP »The Best Christmas Album Ever.4 CD [2006.XMAS].LokoTorrents.com.By KELOLO/306-va-mel_and_kim_-_rockin_around_the_christmas_tree-b2r.mp3 - incorrect CRC checksum, the file may be damaged C:\Programfiler\BitLord\Downloads\Classic.School.Girls.4.DANiSH.XXX.DVDRip.XviD-DKPORNA\dkp-csg4.rar »RAR »dkp-csg4.avi - next archive volume not found C:\Programfiler\BitLord\Downloads\Prison.Break.S02E18.HDTV.XviD-XOR\xor-prison.break.218.rar »RAR »prison.break.s02e18.hdtv.xvid-xor.avi - next archive volume not found C:\Programfiler\EA GAMES\Battlefield 2\pylib-2.3.4.zip »ZIP »test/testtar.tar »TAR - archive damaged C:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] C:\WINDOWS\SoftwareDistribution\EventCache\{776FD12B-FF70-43AA-A26F-0670143EA38A}.bin - error opening (File locked) [4] C:\WINDOWS\system32\retbjnyp.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\ttdefvkw.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\ttochyoj.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\vevstteg.dll - a variant of Win32/Adware.Virtumonde application C:\WINDOWS\system32\xorspwqc.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\ymtbahhh.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\yptvgjtx.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\ywomxuxx.dll - Win32/BHO.NAV trojan - deleted C:\WINDOWS\system32\config\default - error opening (File locked) [4] C:\WINDOWS\system32\config\default.LOG - error opening (File locked) [4] C:\WINDOWS\system32\config\SAM - error opening (File locked) [4] C:\WINDOWS\system32\config\SAM.LOG - error opening (File locked) [4] C:\WINDOWS\system32\config\SECURITY - error opening (File locked) [4] C:\WINDOWS\system32\config\SECURITY.LOG - error opening (File locked) [4] C:\WINDOWS\system32\config\software - error opening (File locked) [4] C:\WINDOWS\system32\config\software.LOG - error opening (File locked) [4] C:\WINDOWS\system32\config\system - error opening (File locked) [4] C:\WINDOWS\system32\config\system.LOG - error opening (File locked) [4] Number of scanned files: 144066 Number of threats found: 9 Number of files cleaned: 8 Number of active threats: 1 Time of completion: 16:27:19 Total scanning time: 1775 sec (00:29:35) Notes: [4] File cannot be opened. It may be in use by another application or operating system. Skal ha slettet alle karantenefilene i SAS. I brukeren administrator også. Merkelig at de står oppført likevel... C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 18-11-22.SBU »ZIP »backup.db - error - password-protected file C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 02-02-2008 - 19-02-18.SBU »ZIP »backup.db - error - password-protected file Som du ser i NOD32-loggen ble det finnet en : C:\Documents and Settings\Håvard Karlsnes\Mine dokumenter\downloads\sinstaller2.exe »NSIS »SSSInst.dll - Win32/Adware.Comet application som ikke ble fjernet. Denne har kanskje kobling mot en .ddl fil? (SSSInst.dll) el lign. og at den kjører nå? Tusen hjertlig takk for hjelpen ennå Er nok "beste" tilfellet på lenge dette Endret 3. februar 2008 av mogie Lenke til kommentar
norbat Skrevet 3. februar 2008 Del Skrevet 3. februar 2008 (endret) sinstaller2.exe kan du fjerne manuelt fra Download-mappa di (mulig den må tas fra sikker modus). Kunne godt tenkt meg å sett en ny combofix-logg. Last ned på ny og kjør. Fortell også hvordan PC-en kjører. Endret 3. februar 2008 av norbat Lenke til kommentar
m0g1e Skrevet 3. februar 2008 Forfatter Del Skrevet 3. februar 2008 Fjernet sinstaller.exe i safe-modus. Fikk egentlig vite av laptopen var så og si ubrukelig siden den var så treg. Likevel har ikke jeg opplevd noe av dette. Så slik sett er den like rask som før... Det kan kanskje ha vært spesielle programmer som avgjør om PC-en jobbet sent, eller at malware ikke var aktiv ennå.. Uansett fungerer den flott nå Ny ComboFix logg: ComboFix 08-02.03.1 - Håvard Karlsnes 2008-02-03 17:25:36.6 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1044.18.697 [GMT 1:00] Running from: E:\clean_box\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 ))))))))))))))))))))))))))))))) . 2008-02-03 17:21 . 2007-05-14 18:46 177,152 --a------ C:\utorrent.exe 2008-02-03 13:02 . 2008-02-03 14:35 <DIR> d-------- C:\Programfiler\Opera 2008-02-03 11:55 . 2008-02-03 11:49 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys 2008-02-03 11:55 . 2008-02-03 11:49 298,104 --a------ C:\WINDOWS\system32\imon.dll 2008-02-03 11:55 . 2008-02-03 11:49 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys 2008-02-03 11:49 . 2008-02-03 16:00 <DIR> d-------- C:\Programfiler\ESET 2008-02-03 11:23 . 2008-02-03 11:23 <DIR> d-------- C:\Nero7 2008-02-03 11:13 . 2008-02-03 11:13 <DIR> d-------- C:\Documents and Settings\HÕvard Karlsnes\Lokale innstillinger 2008-02-02 18:58 . 2008-02-02 18:58 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\vlc 2008-02-02 17:18 . 2008-02-03 17:15 <DIR> dr-h----- C:\Documents and Settings\Administrator\Siste 2008-02-02 17:18 . 2008-02-02 17:18 <DIR> d-------- C:\Documents and Settings\Administrator\Programdata\SUPERAntiSpyware.com 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> dr------- C:\Documents and Settings\Administrator\Start-meny 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d--h----- C:\Documents and Settings\Administrator\Skrivere 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Skrivebord 2008-02-02 17:15 . 2008-02-02 18:58 <DIR> dr-h----- C:\Documents and Settings\Administrator\Programdata 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Mine dokumenter 2008-02-02 17:15 . 2006-06-23 16:23 <DIR> d--h----- C:\Documents and Settings\Administrator\Maler 2008-02-02 17:15 . 2008-02-03 15:33 <DIR> d--h----- C:\Documents and Settings\Administrator\Lokale innstillinger 2008-02-02 17:15 . 2006-06-23 18:10 <DIR> d-------- C:\Documents and Settings\Administrator\Favoritter 2008-02-02 17:15 . 2008-02-02 20:36 <DIR> d--h----- C:\Documents and Settings\Administrator\AndrMask 2008-02-02 17:11 . 2008-02-03 17:16 <DIR> d-------- C:\Programfiler\SUPERAntiSpyware 2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Programfiler\Fellesfiler\Wise Installation Wizard 2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\Håvard Karlsnes\Programdata\SUPERAntiSpyware.com 2008-02-02 17:11 . 2008-02-02 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Programdata\SUPERAntiSpyware.com 2008-02-02 17:10 . 2008-02-02 17:10 <DIR> d-------- C:\Programfiler\CCleaner 2008-01-29 00:05 . 2008-02-03 01:02 <DIR> d-------- C:\Programfiler\DivX . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-03 15:51 --------- d-----w C:\Documents and Settings\All Users\Programdata\Microsoft Help 2008-02-03 14:24 --------- d-----w C:\Programfiler\AnyDVD 2008-02-03 12:53 --------- d-----w C:\Programfiler\QuickTime 2008-02-03 10:02 --------- d-----w C:\Programfiler\Fellesfiler\Ahead 2008-02-02 23:58 --------- d-----w C:\Programfiler\LimeWire 2008-02-02 18:01 --------- d-----w C:\Programfiler\BitLord 2008-02-02 17:49 --------- d-----w C:\Programfiler\Yahoo! 2008-02-02 15:50 --------- d---a-w C:\Documents and Settings\All Users\Programdata\TEMP 2008-01-30 14:00 --------- d-----w C:\Documents and Settings\Håvard Karlsnes\Programdata\dvdcss 2007-11-07 09:30 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll 2006-09-01 18:38 5,361,664 ----a-w C:\Programfiler\NordicBetMPP_PW1.exe 2006-07-27 13:09 1,701,471 ----a-w C:\Programfiler\kart2.pdf 2006-07-14 16:17 12,766,208 ----a-w C:\Programfiler\MP10Setup.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programfiler\Fellesfiler\Ahead\lib\NMBgMonitor.exe" [ ] "SUPERAntiSpyware"="C:\Programfiler\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCMSMMSG"="BCMSMMSG.exe" [2003-02-24 17:34 122880 C:\WINDOWS\BCMSMMSG.exe] "nod32kui"="C:\Programfiler\Eset\nod32kui.exe" [2008-02-03 11:49 949376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 13:00 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Programfiler\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Programfiler\SUPERAntiSpyware\SASWINLO.dll R3 SIWIO;SIWIO;C:\WINDOWS\TEMP\SiwIo.sys [] S0 esff;esff;C:\WINDOWS\system32\drivers\esff.sys [] S0 wasfsd;wasfsd;C:\WINDOWS\system32\drivers\wasfsd.sys [] S3 AR5523;3Com OfficeConnect Wireless 108Mbps 11g USB Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5523.sys [] *Newly Created Service* - SIWIO . Contents of the 'Scheduled Tasks' folder "2007-11-22 18:16:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Programfiler\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-02-03 17:27:38 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-02-03 17:28:11 . 2008-02-03 00:25:08 --- E O F --- Lenke til kommentar
norbat Skrevet 3. februar 2008 Del Skrevet 3. februar 2008 Loggen ser fin ut. Du kan fjerne combofix igjen med kommandoen combofix /u fra kjør-vinduet. Du kan godt kjøre NOD igjen og se om det fortsatt sitter noen rester igjen i systemet. Gi gjerne tilbakemelding. En ny runde med CCleaner samt sjekk om PC-en trenger en diskdefragmentering (tilbehør->systemverktøy->diskdefragementering) kan være en grei avslutning. Lenke til kommentar
m0g1e Skrevet 3. februar 2008 Forfatter Del Skrevet 3. februar 2008 Loggen ser fin ut. Du kan fjerne combofix igjen med kommandoen combofix /u fra kjør-vinduet. Du kan godt kjøre NOD igjen og se om det fortsatt sitter noen rester igjen i systemet. Gi gjerne tilbakemelding. En ny runde med CCleaner samt sjekk om PC-en trenger en diskdefragmentering (tilbehør->systemverktøy->diskdefragementering) kan være en grei avslutning. Bra gjetta har akkurat gjort det. Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå