1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Bit Defender Trojan Detected Hijack Log

Discussion in 'Windows - Virus and spyware problems' started by gotrice8, Mar 11, 2008.

  1. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:27:04 PM, on 22/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Opera\Opera.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
    C:\Program Files\Steam\Steam.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - S-1-5-18 Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe (User 'Default user')
    O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/wuweb_site.cab?1205258109281
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1205257778265
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

    --
    End of file - 6715 bytes



    Incident Status Location

    Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies-1.txt[counter.hitslink.com/]
    Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies-1.txt[.doubleclick.net/]
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies-1.txt[.statcounter.com/]
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies-1.txt[.xiti.com/]
    Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies-1.txt[.toplist.cz/]
    Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies-1.txt[.clickbank.net/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Tuan Nguyen\Cookies\tuan nguyen@atdmt[1].txt

     
  2. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Currently I am not having any visible trouble with my PC. From the previous post of the Bit Defender Scan there seems to be a lot of viruses and trojans located in the folder named "How To.." located C:\Documents and Settings\Tuan Nguyen\My Documents\shit\How To.. That is the full name of the folder and sorry if i was not clear. I would like to get rid of the folder and viruses inside with your help.

    Thank you
     
    Last edited: Mar 22, 2008
  3. Ltangel

    Ltangel Regular member

    Joined:
    Feb 17, 2008
    Messages:
    200
    Likes Received:
    0
    Trophy Points:
    26
    Hey gotrice8,

    Your HijackThis log looks fine now. :) Good work! Don't worry about that folder, we'll delete it now.

    Delete Unwanted Folder with Unlocker 1.8.6

    * Please download Unlocker 1.8.6 to your desktop.
    * Double click on the setup file and follow the prompts.
    * When done, click "Finish" to close setup.
    * Now, go to C:\Documents and Settings\Tuan Nguyen\My Documents\ and locate the folder shit.
    * Right click on that folder and select "Unlocker".
    * A window will open, click on "Kill all processes".
    * Then right click on the folder and select Delete. The folder should now be moved to Recycle bin.

    ---------------------------------------------------------------------

    Scan with Dr WebCureIt


    * Download Dr.Web CureIt to the desktop:
    ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe


    * Doubleclick the drweb-cureit.exe file and Allow to run the express scan
    * This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
    * Once the short scan has finished, mark the drives that you want to scan.
    * Select all drives. A red dot shows which drives have been chosen.
    * Click the green arrow at the right, and the scan will start.
    * Click 'Yes to all' if it asks if you want to cure/move the file.
    * When the scan has finished, look if you can click next icon next to the files found:
    * If so, click it and then click the next icon right below and select Move incurable.

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
    * After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
    * Save the report to your desktop. The report will be called DrWeb.csv
    * Close Dr.Web Cureit.
    * Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.

    ---------------------------------------------------------------------

    In your next reply (please include):

    Fresh HijackThis log
    WebCureIt log


    ~Ltangel~







     
  4. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:51:43 PM, on 23/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Opera\Opera.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - S-1-5-18 Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe (User 'Default user')
    O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/wuweb_site.cab?1205258109281
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1205257778265
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

    --
    End of file - 6728 bytes


    livesrv.exe;c:\program files\common files\bitdefender\bitdefender update service;Probably DLOADER.Trojan;Incurable.Deleted.;
    inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.1;Probably BACKDOOR.Trojan;Incurable.Moved.;
    aolsetup.exe;C:\Program Files\AIM6\services\softwareUpdate\ver2_13_13_7;Probably BACKDOOR.Trojan;Incurable.Moved.;
    A0158089.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP673;Probably BATCH.Virus;Incurable.Moved.;
    A0158094.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP673;Probably SCRIPT.Virus;Incurable.Moved.;
    A0158795.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP677;Probably BATCH.Virus;Incurable.Moved.;
    A0158801.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP677;Probably SCRIPT.Virus;Incurable.Moved.;
    A0158849.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP678;Probably BATCH.Virus;Incurable.Moved.;
    A0158855.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP678;Probably SCRIPT.Virus;Incurable.Moved.;
    A0158927.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP678;Probably BATCH.Virus;Incurable.Moved.;
    A0158933.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP678;Probably SCRIPT.Virus;Incurable.Moved.;
    A0158968.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP679;Probably BATCH.Virus;Incurable.Moved.;
    A0158973.bat;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP679;Probably SCRIPT.Virus;Incurable.Moved.;
    A0159608.exe;C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP680;Probably DLOADER.Trojan;Incurable.Moved.;
     
  5. Ltangel

    Ltangel Regular member

    Joined:
    Feb 17, 2008
    Messages:
    200
    Likes Received:
    0
    Trophy Points:
    26
    Hey gotrice8,

    Good work! Just a few more issues and we can close this. :)

    Update your Java

    Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. Please follow these steps to remove older version Java components and update:

    * Download and install the latest version of Java here.
    * Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java (they begin with "J2SE Runtime Environment...").
    * It may prompt you to reboot once you have removed previous versions, please click "Yes" if the prompt comes up.

    ---------------------------------------------------------------------

    Reset System Restore

    Now, we shall clean and reset the Restore Points so as to clean up previously infected Restore Points.

    Please right click on My Computer, select "Properties". Then in "System Properties" window, select the "System Restore" tab.

    Clean existing Restore Points
    * Put a check next to "Turn off System Restore on all drives". Click Apply. (Please wait for a moment to complete the cleaning process)

    Set new Restore Points
    * Uncheck "Turn off System Restore on all drives". Click Apply. (Please wait for a moment to complete the reset process)

    ----------------------------------------------------------------------

    Now that your log is fine, I have some recommended downloads for you. Please have a look at them and decide for yourself what you would like to use as protection for your system. After you have chosen the protection softwares you want to download, please don't forget to set them to automatic updating to get the latest protection.

    [*]Spybot Search & Destroy- An excellent and free anti-spyware software with Immunize functionability that will help prevent future infections. PGPhantom has written a very comprehensive instruction set for Spybot, available here.

    [*]SpywareBlaster - A wonderful prevention tool to protect yourself from installation of malicious codes. SpywareBlaster tutorial (by Grinler) is available here.

    [*]IE-SpyAd - It puts over 5000 sites in your restricted zone and protect your Internet browser from being redirected to a malicious site. Lawrence Abrams has written an excellent tutorial about IE-SpyAd here.

    Special Note: It is vital to know that you should only have ONE anti-spyware resident protection and ONE anti-virus resident protection running. Running more than one resident protection can slow down your system and cause conflicts between the protection softwares. Exceptions are Spywareblaster and IE-SpyAd which can be used with any other protection softwares.

    To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.

    Happy safe surfing!

    ~Ltangel~
     
  6. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Thank you, Ltangel you have been a godsend! :)
    Would you recommend I uninstall BitDefender? Or is SpyAd compatible with it? I think Spyblaster is not compatible with BitDefender. Also I am using Opera for my current internet browser is there any improvements I can make? Thanks again!
     
    Last edited: Mar 25, 2008
  7. Ltangel

    Ltangel Regular member

    Joined:
    Feb 17, 2008
    Messages:
    200
    Likes Received:
    0
    Trophy Points:
    26
    Hey gotrice8,

    Your utmost welcome, glad that I could help you. :)

    I doubt that SpywareBlaster and IE-SpyAd has compatibility issues with Bitdefender, at least I have never heard that from anywhere.

    I'm not exactly familiar with Opera, but I would highly recommend the use of Firefox. It is a constantly upgraded web browser with various features that allow you to browse the site safer. You can visit mozilla.org if you are interested.

    Good luck. :)

    ~Ltangel~
     
  8. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Hello, I wasn't sure if I should of made a new topic but posting here you guys would see my history. Several trojans and spyware has infected my PC from a file I downloaded off a usenet group and I shall need further assistance from you guys again. I am constantly having anti virus removal pop ups now and after a full scan I have several trojans that cannot be deleted. I will post the Hijack log I have and my Bit Defender log as well. If you need more just reply thanks!


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:07:11 PM, on 03/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\iftuyszv.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\444.471
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system\CmSNXeye.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\TEMP\CC05.tmp
    C:\WINDOWS\explorer.exe
    C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\TEMP\CC05.tmp

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = file://c:/windows/homepage.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\iftuyszv.exe,
    O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
    O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
    O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
    O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
    O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
    O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
    O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
    O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
    O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
    O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
    O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
    O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
    O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
    O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
    O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
    O2 - BHO: gooochi browser optimizer - {d5399b78-f945-362e-98ed-c86207ab488a} - C:\WINDOWS\system32\{53dcb5b9-cfe0-8dff-b034-92cb8d2ecc0d}.dll (file missing)
    O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
    O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
    O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
    O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
    O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
    O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\jqwnw64m.exe
    O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/wuweb_site.cab?1205258109281
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1205257778265
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
    O20 - Winlogon Notify: urqQiGwX - urqQiGwX.dll (file missing)
    O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\444.471.exe (file missing)
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

    --
    End of file - 11344 bytes
     
  9. cdavfrew

    cdavfrew Regular member

    Joined:
    May 19, 2008
    Messages:
    1,183
    Likes Received:
    0
    Trophy Points:
    46
    Hey gotrice8. As for your question concerning Opera as your current browser, I wouldn't quite recommend it, as althought it is indeed fast and considered by some to be secure, it is more susceptible to security holes and such. See this article: http://news.softpedia.com/news/Is-Internet-Explorer-Safer-than-Firefox-Opera-and-Safari-80051.shtml

    As for your current malware problem, please open your Task Manager, and end the processes C:\WINDOWS\system32\iftuyszv.exe and C:\WINDOWS\444.471. See if you can quarantine these files using Bitdefender.

    I have found a whole lot of malicious entries in your hijackthis log, so you can put a checkmark by all of these and then click on fix.

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\iftuyszv.exe,
    O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
    O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
    O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
    O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
    O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
    O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
    O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
    O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
    O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
    O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)
    O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
    O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)
    O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
    O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
    O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
    O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
    O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
    O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
    O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
    O2 - BHO: gooochi browser optimizer - {d5399b78-f945-362e-98ed-c86207ab488a} - C:\WINDOWS\system32\{53dcb5b9-cfe0-8dff-b034-92cb8d2ecc0d}.dll (file missing)
    O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
    O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
    O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
    O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
    O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
    O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
    O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\jqwnw64m.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
    O20 - Winlogon Notify: urqQiGwX - urqQiGwX.dll (file missing)
    O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
    O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\444.471.exe (file missing)

    Please boot into safe mode and then do a scan with Bitdefender. Quarantine all found files.

    Best Regards :D
     
  10. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    I had switch to Firefox before this problem but thank you for the article. I was able to delete more viruses in safe mode but there were 8 that could not be deleted or quarantined.

    BitDefender Log File !!!!!
    Product : BitDefender Total Security 2008
    Version : BitDefender UIScanner v.11
    Log date : 08:51:38 04/06/2008
    Log path : C:\Documents and Settings\Administrator\Application Data\BitDefender\Desktop\Profiles\Logs\manual_scan\1212583898_1_02.xml

    Scan Paths:path0000: C:\


    Scan Options:Scan for viruses : Yes
    Scan for adware : Yes
    Scan for spyware : Yes
    Scan for applications : Yes
    Scan for dialers : Yes
    Scan for rootkits : No


    Target selection options:Scan registry keys : No
    Scan cookies : No
    Scan boot sectors : No
    Scan memory processes : No
    Scan archives : No
    Scan runtime packers : No
    Scan emails : No
    Scan all files : No
    Heuristic Scan : No
    Scanned extensions :
    Excluded extensions :


    Target ProcessingDefault action for infected objects : None
    Default action for suspicious objects : None
    Default action for hidden objects : None


    Scan engines summaryNumber of virus signatures : 1256003
    Archive plugins : 42
    Email plugins : 6
    Scan plugins : 12
    Archive plugins : 42
    System plugins : 4
    Unpack plugins : 7


    Overall scan summaryScanned items : 227887
    Infected items : 13
    Suspicious items : 0
    Resolved items : 5
    Individual viruses found : 8
    Scanned directories : 8910
    Scanned boot sectors : 0
    Scanned archives : 3272
    Input-output errors : 22
    Scan time : 00:01:43:32
    Files per second : 36


    Scanned processes summaryScanned : 0
    Infected : 0


    Scanned registry keys summaryScanned : 0
    Infected : 0


    Scanned cookies summaryScanned : 0
    Infected : 0


    Remaining issues:Object Name Threat Name Final Status
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temporary Internet Files\Content.IE5\KLAN8L23\gside[1].exe=](NSIS 2g)=]bzip2_solid_nsis0002 Adware.BHO.WRG Delete Failed (file was in an archive)
    C:\WINDOWS\system32\gside.exe=](NSIS o)=]bzip2_solid_nsis0002 Adware.BHO.WRG Delete Failed (file was in an archive)
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temp\Temporary Internet Files\Content.IE5\054DMP6X\g96[1].exe=](NSIS 2g)=]lzma_solid_nsis0002 MemScan:Adware.Rotator.B Delete Failed (file was in an archive)
    C:\WINDOWS\system32\g96.exe=](NSIS o)=]lzma_solid_nsis0002 MemScan:Adware.Rotator.B Delete Failed (file was in an archive)
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temp\mmonHJ.exe=](NSIS o)=]zlib_nsis0004 Trojan.Downloader.VB.VPG Delete Failed (file was in an archive)
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temporary Internet Files\Content.IE5\KLAN8L23\mmonHJ[1].exe=](NSIS o)=]zlib_nsis0004 Trojan.Downloader.VB.VPG Delete Failed (file was in an archive)
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temp\mmonHJ.exe=](NSIS o)=]zlib_nsis0005 Trojan.Generic.277397 Delete Failed (file was in an archive)
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temporary Internet Files\Content.IE5\KLAN8L23\mmonHJ[1].exe=](NSIS o)=]zlib_nsis0005 Trojan.Generic.277397 Delete Failed (file was in an archive)


    Resolved issues:Object Name Threat Name Final Status
    C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP779\A0200162.exe Adware.BHO.WRH Deleted
    C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP779\A0200163.dll Trojan.BHO.OAQ Deleted
    C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP779\A0200169.exe Trojan.Downloader.VB.Gen.1 Deleted
    C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP779\A0200187.exe Trojan.Downloader.VB.Gen.1 Deleted
    C:\System Volume Information\_restore{BC7BD415-6941-456E-B61A-AE4165AA5675}\RP779\A0200170.exe Trojan.Retapu.D Deleted


    Objects that were not scanned:Object Name Reason Final Status
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip=]related.htm Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService2.zip=]cmdinst.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService3.zip=]atmtd.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService4.zip=]atmtd.dll._ Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService6.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommandService6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch10.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch10.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch11.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch11.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch12.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch12.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch13.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch13.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch14.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch14.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch15.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch15.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch16.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch16.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch17.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch17.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch18.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch18.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch19.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch19.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch20.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch20.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch21.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch21.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch22.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch22.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch23.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch23.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch24.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch24.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch25.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch25.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch26.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch26.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch27.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch27.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch28.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch28.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch29.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch29.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch30.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch30.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch31.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch31.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch32.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch32.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch33.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch33.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch34.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch34.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch35.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch35.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch36.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch36.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch37.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch37.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch38.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch38.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch39.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch39.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch6.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch7.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch8.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch9.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll.zip=]iedll.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll1.zip=]loader.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll10.zip=]iedll.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll10.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll11.zip=]loader.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll11.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll2.zip=]iedll.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll3.zip=]loader.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll4.zip=]iedll.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll5.zip=]loader.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll6.zip=]iedll.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll7.zip=]loader.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll8.zip=]iedll.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll9.zip=]loader.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow10.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow10.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow11.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow11.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow12.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow12.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow13.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow13.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow14.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow14.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow15.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow15.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow16.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow16.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow17.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow17.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow18.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow18.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow19.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow19.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow6.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow7.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow8.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow9.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf.zip=]msupdate.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf1.zip=]msupdate.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf2.zip=]msupdate.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf3.zip=]msupdate.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf4.zip=]msupdate.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf5.zip=]msupdate.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace6.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace7.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace8.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace9.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch10.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch10.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch11.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch11.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch12.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch12.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch13.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch13.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch14.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch14.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch15.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch15.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch16.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch16.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch17.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch17.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch18.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch18.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch19.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch19.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch20.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch20.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch21.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch21.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch22.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch22.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch23.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch23.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch24.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch24.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch25.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch25.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch26.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch26.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch27.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch27.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch6.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch7.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch8.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch9.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk10.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk10.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk11.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk11.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk12.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk12.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk13.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk13.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk14.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk14.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk15.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk15.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk6.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk7.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk8.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk9.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers10.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers10.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers11.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers11.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers12.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers12.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers13.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers13.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers14.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers14.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers15.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers15.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers16.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers16.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers17.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers17.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers18.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers18.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers19.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers19.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers20.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers20.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers21.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers21.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers22.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers22.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers23.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers23.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers6.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers7.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers8.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers9.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch.zip=]notepad32.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch1.zip=]notepad32.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch1.zip=]sbRecovery.ini Password-Protected No action was possible
     
  11. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch2.zip=]notepad32.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch3.zip=]notepad32.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch4.zip=]notepad32.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch5.zip=]notepad32.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit.zip=]mssys.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit1.zip=]mssys.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit2.zip=]mssys.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit3.zip=]mssys.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit4.zip=]mssys.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit5.zip=]mssys.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotKeysHook.zip=]TEMP#01.EXE Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotKeysHook.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotKeysHook1.zip=]TEMP#01.EXE Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotKeysHook1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager5.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor2.zip=]uninstall_nmon.vbs Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor5.zip=]domains.txt Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor5.zip=]log.txt Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip=]users32.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip=]accesss.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip=]olehelp.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip=]win64.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip=]astctl32.ocx Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip=]cpan.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC17.zip=]mtwirl32.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC17.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip=]winajbm.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip=]users32.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip=]winmgnt.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip=]winmgnt.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC21.zip=]avpcc.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC21.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip=]window.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC23.zip=]systemcritical.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC23.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC24.zip=]clrssn.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC24.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC25.zip=]xxxvideo.hta Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC25.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC26.zip=]waol.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC26.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC27.zip=]y.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC27.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC28.zip=]accesss.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC28.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC29.zip=]olehelp.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC29.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip=]avpcc.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC30.zip=]win64.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC30.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC31.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC31.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC32.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC32.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC33.zip=]astctl32.ocx Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC33.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC34.zip=]cpan.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC34.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC35.zip=]mtwirl32.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC35.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC36.zip=]winajbm.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC36.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip=]window.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip=]systemcritical.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip=]clrssn.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip=]xxxvideo.hta Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip=]waol.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip=]y.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip=]systeem.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip=]iexplorer.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip=]systeem.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric3.zip=]iexplorer.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip=]x.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp1.zip=]x.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC2.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC3.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip=]removalfile.bat Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip=]yaywvWqn.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip=]yaywvWqn.dll_old Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]Programs/license.txt Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]Programs/readme.txt Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]Programs/sporder.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]Programs/webhdll.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]Programs/whagent.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]Programs/whagent.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]Programs/whiehlpr.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]Programs/whinstaller.exe Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer1.zip=]Programs/webhdll.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer1.zip=]Programs/whiehlpr.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer10.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer10.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer11.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer11.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer12.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer12.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer13.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer13.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer14.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer14.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer15.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer15.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer16.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer16.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer17.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer17.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer18.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer18.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer19.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer19.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer2.zip=]Programs/webhdll.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer2.zip=]Programs/whiehlpr.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer2.zip=]sbRecovery.ini Password-Protected No action was possible
     
  12. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer20.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer20.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer21.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer21.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer3.zip=]Programs/webhdll.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer3.zip=]Programs/whiehlpr.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer3.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer4.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer4.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer5.zip=]Programs/webhdll.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer5.zip=]Programs/whiehlpr.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer5.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer6.zip=]webhdll.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer6.zip=]whiehlpr.dll Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer6.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer7.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer7.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer8.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer8.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer9.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\webHancer9.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBancoszm.zip=]sn.txt Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBancoszm.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBancoszm1.zip=]sn.txt Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBancoszm1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSharkaf.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSharkaf.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSharkaf1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSharkaf1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl1.zip=]sbRecovery.reg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinVBtr.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinVBtr1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinVBtr2.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZenoSearch.zip=]zxdnt3d.cfg Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZenoSearch.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZenoSearch1.zip=]msnav32.ax Password-Protected No action was possible
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZenoSearch1.zip=]sbRecovery.ini Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br=]GGclient.exe.br.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/button_addfriend_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/button_addfriend_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/button_mode_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/button_mode_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/exit_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/exit_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/forum_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/forum_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/ggladder_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/ggladder_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/GGMainHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/GGMainNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/ggtv_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/ggtv_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/gg_menu_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/gg_menu_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/gg_msg_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/gg_msg_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/LobbyHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/LobbyNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/RoomHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/RoomNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/settings_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/settings_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/support_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/support_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.br.ggz=]br/Thumbs.db Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn=]GGclient.exe.cn.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/button_addfriend_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/button_addfriend_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/button_mode_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/button_mode_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/exit_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/exit_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/forum_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/forum_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/ggladder_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/ggladder_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/GGMainHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/GGMainNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/ggtv_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/ggtv_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/gg_menu_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/gg_menu_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/gg_msg_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/gg_msg_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/LobbyHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/LobbyNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/reg.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/reg_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/RoomHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/RoomNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/settings_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/settings_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/support_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/support_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.cn.ggz=]cn/Thumbs.db Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru=]GGclient.exe.ru.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/button_addfriend_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/button_addfriend_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/button_mode_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/button_mode_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/exit_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/exit_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/forum_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/forum_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/ggladder_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/ggladder_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/GGMainHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/GGMainNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/ggtv_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/ggtv_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/gg_menu_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/gg_menu_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/gg_msg_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/gg_msg_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/LobbyHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/LobbyNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/RoomHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/RoomNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/settings_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/settings_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/support_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.ru.ggz=]ru/support_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp=]GGclient.exe.sp.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/button_addfriend_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/button_addfriend_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/button_mode_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/button_mode_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/exit_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/exit_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/forum_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/forum_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/ggladder_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/ggladder_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/GGMainHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/GGMainNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/ggtv_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/ggtv_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/gg_menu_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/gg_menu_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/gg_msg_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/gg_msg_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/LobbyHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/LobbyNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/RoomHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/RoomNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/settings_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/settings_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/support_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/support_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.sp.ggz=]sp/Thumbs.db Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th=]GGclient.exe.th.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/button_addfriend_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/button_addfriend_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/button_mode_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/button_mode_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/exit_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/exit_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/forum_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/forum_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/ggladder_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/ggladder_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/GGMainHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/GGMainNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/ggtv_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/ggtv_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/gg_menu_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/gg_menu_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/gg_msg_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/gg_msg_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/LobbyHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/LobbyNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/RoomHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/RoomNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/settings_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/settings_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/support_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/support_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.th.ggz=]th/Thumbs.db Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw=]GGclient.exe.tw.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/button_addfriend_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/button_addfriend_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/button_mode_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/button_mode_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/exit_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/exit_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/forum_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/forum_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/ggladder_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/ggladder_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/GGMainHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/GGMainNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/ggtv_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/ggtv_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/gg_menu_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/gg_menu_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/gg_msg_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/gg_msg_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/LobbyHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/LobbyNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/reg.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/reg_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/RoomHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/RoomNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/settings_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/settings_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/support_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.tw.ggz=]tw/support_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn=]GGclient.exe.vn.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/button_addfriend_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/button_addfriend_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/button_mode_hover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/button_mode_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/exit_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/exit_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/forum_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/forum_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/ggladder_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/ggladder_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/GGMainHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/GGMainNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/ggtv_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/ggtv_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/gg_menu_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/gg_menu_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/gg_msg_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/gg_msg_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/LobbyHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/LobbyNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/RoomHover.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/RoomNormal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/settings_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/settings_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/support_normal.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\GGclient.exe.vn.ggz=]vn/support_on.bmp Password-Protected No action was possible
    C:\Program Files\Garena\Languages\update.exe.cn=]update.exe.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\update.exe.en=]update.exe.xml Password-Protected No action was possible
    C:\Program Files\Garena\Languages\update.exe.tw=]update.exe.xml Password-Protected No action was possible
    C:\Program Files\Garena\mdata.ggz=]mh.xml Password-Protected No action was possible
     
  13. cdavfrew

    cdavfrew Regular member

    Joined:
    May 19, 2008
    Messages:
    1,183
    Likes Received:
    0
    Trophy Points:
    46
    Hey gotrice.

    Bitdefender isn't exactly the best tool for removing spyware. Please download both superantispyware and a-squared (both free versions) and run a scan in safe mode. With superantispyware, please quarantine everything it detects. With a-squared, please post the scan log here without removing anything.

    Best Regards :D
     
  14. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Sorry about the long reply. Here's a-squared log:

    a-squared Anti-Malware - Version 3.5
    Last update: 15/06/2008 5:16:01 PM

    Scan settings:

    Objects: Memory, Traces, Cookies, C:\, F:\
    Scan archives: On
    Heuristics: On
    ADS Scan: On

    Scan start: 15/06/2008 8:41:54 PM

    c:\program files\accessdiver detected: Trace.Directory.AccessDiver
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{799a370d-5993-4887-9df7-0a4756a77d00} detected: Trace.Registry.CWS.GonnaSearch
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a55581dc-2cdb-4089-8878-71a080b22342} detected: Trace.Registry.CWS.GonnaSearch
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} detected: Trace.Registry.CWS.GoogleMS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{e2ddf680-9905-4dee-8c64-0a5de7fe133c} detected: Trace.Registry.CWS.MSSearch
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{150fa160-130d-451f-b863-b655061432ba} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2d38a51a-23c9-48a1-a33c-48675aa2b494} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2e9caff6-30c7-4208-8807-e79d4ec6f806} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{79369d5c-2903-4b7a-ade2-d5e0dee14d24} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{b847676d-72ac-4393-bfff-43a1eb979352} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{e7afff2a-1b57-49c7-bf6b-e5123394c970} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} detected: Trace.Registry.CWS
    Key: HKEY_CURRENT_USER\software\kazaa detected: Trace.Registry.KaZaA
    c:\program files\gamespy arcade detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\addins detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\cstrike detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\cstrike\frontline detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\action detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\cstrike detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\firearms detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\frontline detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\gearbox detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\tfc detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\aq2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\battle detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\chaosdm detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\duel detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\freeze detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\gloom detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\gxmod detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\holywars detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\jail detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\kots detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\lfiredm detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\lithium2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\lmctf detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\pball detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\q2comp detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\qpong detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\ra2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\requiem detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\sconfig detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\tourney detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\wf detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\wod detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\alliance detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\beryllium detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\excessive detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\instagib detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\jailbreak detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\matchmod detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\osp detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\q3comp detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\q3f detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\q3ut2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\requiem detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\rocketarena3 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\wfa detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\arena detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\ch detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\ctf detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\ctfb detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\ctfplus detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\dd detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\dm detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\duel detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\fr detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\mt detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\open cal detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\rpg detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\tac detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\ut detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\ut\excessive detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\ut\rocketarena detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\ut\swat detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\images detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\images\icons detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\images\portraits detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\profiles detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\profiles\(default) detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_common detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_demospy detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_fplanet detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_gnews detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_gspyder detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_news detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_support detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\skins detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\skins\(default3) detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\sounds detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\sounds\(default) detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\sounds\classic detected: Trace.Directory.GameSpy Arcade
    c:\documents and settings\tuan nguyen\start menu\programs\gamespy arcade detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\4dca9208.dat detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\aphex.exe detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\arcres.dll detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\banner.html detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\dat.bmp detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_banner.gif detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_banner.html detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_bannerbg.jpg detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_loading.gif detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_logo.jpg detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_news.html detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\fpupdate.exe detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy arcade - debug.lnk detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy arcade help.url detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy arcade website.url detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy arcade.lnk detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy.com gaming's homepage.url detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gsapak.exe detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gslan.dll detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gsws.dll detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\install.log detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\pw32.dll detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\readme.html detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\register gamespy arcade.url detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\rptcrash.exe detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_news\rsrc.dir detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_news\service_tab.psd detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_news\service_tab+.tga detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_support\rsrc.dir detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_support\service_tab.psd detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\ws_default.html detected: Trace.File.GameSpy Arcade
    Value: HKEY_CURRENT_USER\Software\GameSpy\GameSpy Arcade --> InstDir detected: Trace.Registry.GameSpy Arcade
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\GameSpy\GameSpy Arcade --> InstDir detected: Trace.Registry.GameSpy Arcade
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GameSpy Arcade --> DisplayName detected: Trace.Registry.GameSpy Arcade
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GameSpy Arcade --> UninstallString detected: Trace.Registry.GameSpy Arcade
    Value: HKEY_CURRENT_USER\Software\Viewpoint\Content Debugger --> SearchBar detected: Trace.Registry.Viewpoint Media Toolbar
    Value: HKEY_CURRENT_USER\Software\Viewpoint\Content Debugger --> Viewbar Installer detected: Trace.Registry.Viewpoint Media Toolbar
    Value: HKEY_CURRENT_USER\Software\Viewpoint\Content Debugger --> Viewpoint Manager detected: Trace.Registry.Viewpoint Media Toolbar
    Value: HKEY_CURRENT_USER\Software\Viewpoint\Content Debugger --> Viewpoint Manager Installer detected: Trace.Registry.Viewpoint Media Toolbar
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:295 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:296 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:297 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:298 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:299 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:338 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:339 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:340 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:341 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:342 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:343 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:344 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:345 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:346 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:347 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:381 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:384 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:442 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:443 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:444 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:547 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:549 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:550 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:551 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:552 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:553 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:554 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:563 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:564 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:565 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:754 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Desktop\Everything\RatioMaster-1.7.5\RatioMaster.exe detected: Trojan-PSW.Win32.LdPinch.fsq
    C:\Documents and Settings\Tuan Nguyen\Desktop\Everything\Warcraft 3\Warcraft3ReignOfChaosv1.21ANDWarcraft3TheFrozenThrone1.21BNetLoaderNoCDLoaderAll.zip/Frozen Throne.exe detected: Trojan.Win32.AddUser.o
    C:\Documents and Settings\Tuan Nguyen\Desktop\Everything\Warcraft 3\Warcraft3ReignOfChaosv1.21ANDWarcraft3TheFrozenThrone1.21BNetLoaderNoCDLoaderAll.zip/Warcraft III.exe detected: Trojan.Win32.AddUser.o
    C:\Documents and Settings\Tuan Nguyen\Desktop\Everything\Warcraft 3\Warcraft3ReignOfChaosv1.21ANDWarcraft3TheFrozenThrone1.21BNetLoaderNoCDLoaderAll.zip/World Editor.exe detected: Trojan.Win32.AddUser.o
    C:\Documents and Settings\Tuan Nguyen\Desktop\SkillMonitor.rar/SkillMonitor.exe detected: IM-Worm.Win32.Sohanad.hw
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temp\4FEE.tmp detected: Backdoor.Win32.KeyStart.c
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temp\Temporary Internet Files\Content.IE5\054DMP6X\kb456456[1] detected: Trojan.Win32.Monder.gen
    C:\Program Files\mIRC\mirc.exe detected: Riskware.Client-IRC.Win32.mIRC.631
    C:\Program Files\URLHelper\WinPcap_3_1.exe detected: Trojan-PSW.Win32.WOW.ats
    C:\Program Files\Warkeys\AutoWarkey\AutoWarkey.exe detected: Trojan-Spy.Win32.Agent.bgr
    C:\Program Files\Warkeys\WarKeys.exe detected: Trojan-Spy.Win32.Agent.bga
    C:\WINDOWS\444.471 detected: Trojan.Win32.DNSChanger.dxy
    C:\WINDOWS\system32\crypts.dll detected: Trojan-Downloader.Win32.Agent.rhg
    C:\WINDOWS\Temp\2A3D.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\3120.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\4C20.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\CC05.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\FBDF.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CTZGGIKX\r4n1[1].exe detected: Trojan-Downloader.Win32.Agent.stf

    Scanned

    Files: 180401
    Traces: 184852
    Cookies: 965
    Processes: 11

    Found

    Files: 19
    Traces: 141
    Cookies: 31
    Processes: 0
    Registry keys: 0

    Scan end: 15/06/2008 10:06:41 PM
    Scan time: 1:24:47
     
  15. cdavfrew

    cdavfrew Regular member

    Joined:
    May 19, 2008
    Messages:
    1,183
    Likes Received:
    0
    Trophy Points:
    46
    Hey gotrice.

    You most definitely are infected. It seems that you like downloading games, including cracked ones, I suppose? I must remind you that cracking shareware is illegal, and it may be enough cause for me to discontinue helping in this thread.

    I have looked over your a-squared log. Please note that I said the free version of a-squared, not the trial version of the shareware. Also, where I have said "remove", actually, you should quarantine the files.

    Do you use AccessDiver? If so, ignore this entry.
    c:\program files\accessdiver detected: Trace.Directory.AccessDiver

    Remove all these entries. Also, download and run CWShredder as the presence of these keys suggest CoolWebSearch.
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{799a370d-5993-4887-9df7-0a4756a77d00} detected: Trace.Registry.CWS.GonnaSearch
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a55581dc-2cdb-4089-8878-71a080b22342} detected: Trace.Registry.CWS.GonnaSearch
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} detected: Trace.Registry.CWS.GoogleMS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{e2ddf680-9905-4dee-8c64-0a5de7fe133c} detected: Trace.Registry.CWS.MSSearch
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{150fa160-130d-451f-b863-b655061432ba} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2d38a51a-23c9-48a1-a33c-48675aa2b494} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2e9caff6-30c7-4208-8807-e79d4ec6f806} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{79369d5c-2903-4b7a-ade2-d5e0dee14d24} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{b847676d-72ac-4393-bfff-43a1eb979352} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{e7afff2a-1b57-49c7-bf6b-e5123394c970} detected: Trace.Registry.CWS
    Key: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} detected: Trace.Registry.CWS

    Do you use Kazaa? If so, ignore this key. However, I must remind you that Kazaa is both illegal in some countries, and definitely a malware spreading application.
    Key: HKEY_CURRENT_USER\software\kazaa detected: Trace.Registry.KaZaA

    As for all these entries, you can ignore them, as A-squared has detected your gamespy arcade as malware.
    c:\program files\gamespy arcade detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\addins detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\cstrike detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\cstrike\frontline detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\action detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\cstrike detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\firearms detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\frontline detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\gearbox detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\halflife\tfc detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\aq2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\battle detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\chaosdm detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\duel detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\freeze detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\gloom detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\gxmod detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\holywars detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\jail detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\kots detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\lfiredm detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\lithium2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\lmctf detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\pball detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\q2comp detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\qpong detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\ra2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\requiem detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\sconfig detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\tourney detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\wf detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake2\wod detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\alliance detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\beryllium detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\excessive detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\instagib detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\jailbreak detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\matchmod detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\osp detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\q3comp detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\q3f detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\q3ut2 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\requiem detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\rocketarena3 detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\quake3\wfa detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\arena detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\ch detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\ctf detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\ctfb detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\ctfplus detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\dd detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\dm detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\duel detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\fr detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\mt detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\open cal detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\rpg detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\tribes\tac detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\ut detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\ut\excessive detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\ut\rocketarena detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\custom\ut\swat detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\images detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\images\icons detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\images\portraits detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\profiles detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\profiles\(default) detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_common detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_demospy detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_fplanet detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_gnews detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_gspyder detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_news detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\services\_support detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\skins detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\skins\(default3) detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\sounds detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\sounds\(default) detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\sounds\classic detected: Trace.Directory.GameSpy Arcade
    c:\documents and settings\tuan nguyen\start menu\programs\gamespy arcade detected: Trace.Directory.GameSpy Arcade
    c:\program files\gamespy arcade\4dca9208.dat detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\aphex.exe detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\arcres.dll detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\banner.html detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\dat.bmp detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_banner.gif detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_banner.html detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_bannerbg.jpg detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_loading.gif detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_logo.jpg detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\def_news.html detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\fpupdate.exe detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy arcade - debug.lnk detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy arcade help.url detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy arcade website.url detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy arcade.lnk detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gamespy.com gaming's homepage.url detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gsapak.exe detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gslan.dll detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\gsws.dll detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\install.log detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\pw32.dll detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\readme.html detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\register gamespy arcade.url detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\rptcrash.exe detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_news\rsrc.dir detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_news\service_tab.psd detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_news\service_tab+.tga detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_support\rsrc.dir detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\services\_support\service_tab.psd detected: Trace.File.GameSpy Arcade
    c:\program files\gamespy arcade\ws_default.html detected: Trace.File.GameSpy Arcade
    Value: HKEY_CURRENT_USER\Software\GameSpy\GameSpy Arcade --> InstDir detected: Trace.Registry.GameSpy Arcade
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\GameSpy\GameSpy Arcade --> InstDir detected: Trace.Registry.GameSpy Arcade
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GameSpy Arcade --> DisplayName detected: Trace.Registry.GameSpy Arcade
    Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GameSpy Arcade --> UninstallString detected: Trace.Registry.GameSpy Arcade

    Remove all these entries.
    Value: HKEY_CURRENT_USER\Software\Viewpoint\Content Debugger --> SearchBar detected: Trace.Registry.Viewpoint Media Toolbar
    Value: HKEY_CURRENT_USER\Software\Viewpoint\Content Debugger --> Viewbar Installer detected: Trace.Registry.Viewpoint Media Toolbar
    Value: HKEY_CURRENT_USER\Software\Viewpoint\Content Debugger --> Viewpoint Manager detected: Trace.Registry.Viewpoint Media Toolbar
    Value: HKEY_CURRENT_USER\Software\Viewpoint\Content Debugger --> Viewpoint Manager Installer detected: Trace.Registry.Viewpoint Media Toolbar
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:295 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:296 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:297 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:298 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:299 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:338 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:339 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:340 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:341 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:342 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:343 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:344 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:345 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:346 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:347 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:381 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:384 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:442 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:443 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:444 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:547 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:549 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:550 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:551 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:552 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:553 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:554 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:563 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:564 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:565 detected: Trace.TrackingCookie
    C:\Documents and Settings\Tuan Nguyen\Application Data\Mozilla\Firefox\Profiles\q1wzkbia.default\cookies.txt:754 detected: Trace.TrackingCookie

    Apparently, a-squared detected ratiomaster.exe. I will recommend removing it, but it is your choice.
    C:\Documents and Settings\Tuan Nguyen\Desktop\Everything\RatioMaster-1.7.5\RatioMaster.exe detected: Trojan-PSW.Win32.LdPinch.fsq

    It seems that you have obtained an infected version of Warcraft, as A-squared does not detect my legitimate version of Warcraft. Remove these entries if you wish, but I will recommend it.
    C:\Documents and Settings\Tuan Nguyen\Desktop\Everything\Warcraft 3\Warcraft3ReignOfChaosv1.21ANDWarcraft3TheFrozenThrone1.21BNetLoaderNoCDLoaderAll.zip/Frozen Throne.exe detected: Trojan.Win32.AddUser.o
    C:\Documents and Settings\Tuan Nguyen\Desktop\Everything\Warcraft 3\Warcraft3ReignOfChaosv1.21ANDWarcraft3TheFrozenThrone1.21BNetLoaderNoCDLoaderAll.zip/Warcraft III.exe detected: Trojan.Win32.AddUser.o
    C:\Documents and Settings\Tuan Nguyen\Desktop\Everything\Warcraft 3\Warcraft3ReignOfChaosv1.21ANDWarcraft3TheFrozenThrone1.21BNetLoaderNoCDLoaderAll.zip/World Editor.exe detected: Trojan.Win32.AddUser.o

    I find no information on Skillmonitor.exe on the internet. Therefore, I have reason enough to believe that this is malware, and if you think otherwise, ignore it.
    C:\Documents and Settings\Tuan Nguyen\Desktop\SkillMonitor.rar/SkillMonitor.exe detected: IM-Worm.Win32.Sohanad.hw

    Remove all these entries.
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temp\4FEE.tmp detected: Backdoor.Win32.KeyStart.c
    C:\Documents and Settings\Tuan Nguyen\Local Settings\Temp\Temporary Internet Files\Content.IE5\054DMP6X\kb456456[1] detected: Trojan.Win32.Monder.gen

    Do you use mIRC? If so, ignore this. However, I will say the same thing that I said for Kazaa.
    C:\Program Files\mIRC\mirc.exe detected: Riskware.Client-IRC.Win32.mIRC.631

    You can remove this, unless you think otherwise. There is a newer version of WinPCap, and even so, it should not be detected as malware.
    C:\Program Files\URLHelper\WinPcap_3_1.exe detected: Trojan-PSW.Win32.WOW.ats

    I am not too sure about these. It is up to you to remove it or not.
    C:\Program Files\Warkeys\AutoWarkey\AutoWarkey.exe detected: Trojan-Spy.Win32.Agent.bgr
    C:\Program Files\Warkeys\WarKeys.exe detected: Trojan-Spy.Win32.Agent.bga

    Remove all these entries. These are definitely malware, and may be the ones causing your problem.
    C:\WINDOWS\444.471 detected: Trojan.Win32.DNSChanger.dxy
    C:\WINDOWS\system32\crypts.dll detected: Trojan-Downloader.Win32.Agent.rhg
    C:\WINDOWS\Temp\2A3D.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\3120.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\4C20.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\CC05.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\FBDF.tmp detected: Backdoor.Win32.KeyStart.c
    C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CTZGGIKX\r4n1[1].exe detected: Trojan-Downloader.Win32.Agent.stf

    Best Regards :D
     
  16. gotrice8

    gotrice8 Member

    Joined:
    Mar 11, 2008
    Messages:
    23
    Likes Received:
    0
    Trophy Points:
    11
    Thanks for all the help!

    Cheers! :]
     

Share This Page