1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Brontok A

Discussion in 'Malware and Virus Removal Archive' started by Andy Cool, 2008/01/28.

  1. 2008/02/06
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I didn't get the logs. Resend them if you're unable to post them here.
     
  2. 2008/02/08
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Dave,

    Please find the HJT log. Please note that the log was produced before the Panda scan.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:00:15 AM, on 2/7/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    C:\WINDOWS\system32\ThpSrv.exe
    C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\TPSMain.exe
    C:\WINDOWS\system32\thpsrv.exe
    C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\Program Files\Protector Suite QL\psqltray.exe
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\WINDOWS\system32\dla\DLACTRLW.exe
    C:\toshiba\ivp\ism\pinger.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE
    C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\McAfee.com\VSO\oasclnt.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    c:\program files\mcafee.com\vso\mcmnhdlr.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\drivers\spoclsv.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\PROGRA~1\METAMA~1\METAMA~1\METAMA~2.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.toshibadirect.com/dpdstart
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} - C:\Program Files\Internet Explorer\IEXPLORE32.win
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: (no name) - {C5E87A05-F463-4841-B19E-DD3EC3862368} - C:\Program Files\Internet Explorer\IEXPLORE32.Sys
    O2 - BHO: (no name) - {EE12D60D-AD9A-4095-B839-3BE6862679FD} - C:\Program Files\Internet Explorer\IEXPLORE32.Dat
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
    O4 - HKLM\..\Run: [ThpSrv] thpsrv /logon
    O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [DockMsgFrom] C:\Program Files\Toshiba\Toshiba Applet\DockMsgFrom.exe
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
    O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [TMESRV.EXE] C:\Program Files\TOSHIBA\TME3\TMESRV31.EXE /Logon
    O4 - HKLM\..\Run: [TMERzCtl.EXE] C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE /Service
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe "
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
    O4 - HKCU\..\Run: [Tok-Cirrhatus-2025] "C:\Documents and Settings\mohamed\Local Settings\Application Data\br5073on.exe "
    O4 - HKUS\S-1-5-18\..\Run: [Tok-Cirrhatus] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Tok-Cirrhatus] (User 'Default user')
    O4 - Global Startup: Metamail Trust Manager.lnk = C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CB27FA68-A18C-45DE-AE89-F3CBBB9FE5CE}: NameServer = 192.168.1.1,192.168.1.5
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe
    O23 - Service: Tmesrv3 (Tmesrv) - TOSHIBA - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe

    --
    End of file - 10843 bytes
     

  3. to hide this advert.

  4. 2008/02/08
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Here is the DSS lof again prior to running Panda..I am currently running Panda and will post the log as soon as it's done.

    Deckard's System Scanner v20071014.68
    Run by mohamed on 2008-02-07 06:00:37
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    Total Physical Memory: 502 MiB (512 MiB recommended).


    -- HijackThis (run as mohamed.exe) ---------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:00:38 AM, on 2/7/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    C:\WINDOWS\system32\ThpSrv.exe
    C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\TPSMain.exe
    C:\WINDOWS\system32\thpsrv.exe
    C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\Program Files\Protector Suite QL\psqltray.exe
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\WINDOWS\system32\dla\DLACTRLW.exe
    C:\toshiba\ivp\ism\pinger.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE
    C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\McAfee.com\VSO\oasclnt.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    c:\program files\mcafee.com\vso\mcmnhdlr.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\drivers\spoclsv.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\PROGRA~1\METAMA~1\METAMA~1\METAMA~2.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\mohamed\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\mohamed.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.toshibadirect.com/dpdstart
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} - C:\Program Files\Internet Explorer\IEXPLORE32.win
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: (no name) - {C5E87A05-F463-4841-B19E-DD3EC3862368} - C:\Program Files\Internet Explorer\IEXPLORE32.Sys
    O2 - BHO: (no name) - {EE12D60D-AD9A-4095-B839-3BE6862679FD} - C:\Program Files\Internet Explorer\IEXPLORE32.Dat
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
    O4 - HKLM\..\Run: [ThpSrv] thpsrv /logon
    O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [DockMsgFrom] C:\Program Files\Toshiba\Toshiba Applet\DockMsgFrom.exe
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
    O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [TMESRV.EXE] C:\Program Files\TOSHIBA\TME3\TMESRV31.EXE /Logon
    O4 - HKLM\..\Run: [TMERzCtl.EXE] C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE /Service
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe "
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spoclsv.exe
    O4 - HKCU\..\Run: [Tok-Cirrhatus-2025] "C:\Documents and Settings\mohamed\Local Settings\Application Data\br5073on.exe "
    O4 - HKUS\S-1-5-18\..\Run: [Tok-Cirrhatus] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Tok-Cirrhatus] (User 'Default user')
    O4 - Global Startup: Metamail Trust Manager.lnk = C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CB27FA68-A18C-45DE-AE89-F3CBBB9FE5CE}: NameServer = 192.168.1.1,192.168.1.5
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe
    O23 - Service: Tmesrv3 (Tmesrv) - TOSHIBA - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe

    --
    End of file - 10881 bytes

    -- Files created between 2008-01-07 and 2008-02-07 -----------------------------

    2008-02-02 23:43:35 0 d-------- C:\Program Files\Trend Micro
    2008-02-02 23:32:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2008-02-02 23:32:51 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
    2008-01-29 06:09:58 0 d-------- C:\cc478d51da801b1fcbbb93910d
    2008-01-22 06:10:36 24576 -r------- C:\WINDOWS\system32\ipwcomm.dll <Not Verified; IPWireless; IPWireless 3G Adapter>
    2008-01-22 06:10:03 0 d-------- C:\Program Files\IPWireless Inc


    -- Find3M Report ---------------------------------------------------------------

    2008-02-07 00:29:23 8 -r-hs---- C:\Program Files\Desktop_.ini
    2008-01-24 04:16:17 0 d-------- C:\Program Files\Windows Live Toolbar
    2008-01-22 06:10:06 0 d-------- C:\Program Files\Common Files\InstallShield
    2008-01-22 06:10:03 0 d--h----- C:\Program Files\InstallShield Installation Information
    2007-11-19 06:41:49 40 --a------ C:\WINDOWS\system32\winitn.dll
    2007-11-19 06:41:43 2846720 --a------ C:\WINDOWS\system32\agsaamj.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress3 Module>
    2007-11-19 06:41:43 90112 --a------ C:\WINDOWS\system32\agsaami.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFormatSettings3 Module>
    2007-11-19 06:41:43 626688 --a------ C:\WINDOWS\system32\agsaamh.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCDGrabber2.dll Module>
    2007-11-19 06:41:43 753664 --a------ C:\WINDOWS\system32\agsaamg.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFile3 Module>
    2007-11-19 06:41:43 551424 --a------ C:\WINDOWS\system32\agsaame.dll <Not Verified; Online Media Technologies Ltd.; NCTDataDVDWriter2 Module>
    2007-11-19 06:41:43 544256 --a------ C:\WINDOWS\system32\agsaamd.dll <Not Verified; Online Media Technologies Ltd.; NCTDataCDWriter2 Module>
    2007-11-19 06:41:42 237568 --a------ C:\WINDOWS\system32\lame_enc.dll
    2007-11-19 06:41:42 40 --a------ C:\WINDOWS\system32\kakle.dll
    2007-11-19 06:41:42 372736 --a------ C:\WINDOWS\system32\agsaamc.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFileWMA3 Module>
    2007-11-19 06:41:42 538624 --a------ C:\WINDOWS\system32\agsaamb.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCDWriter2 Module>
    2007-11-19 06:41:42 331776 --a------ C:\WINDOWS\system32\agsaama.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioPlayer3 Module>
    2007-11-19 06:41:38 1245184 --a------ C:\WINDOWS\system32\bkll.dll <Not Verified; NCT Company Ltd.; NCTRMFile ActiveX DLL>
    2007-11-19 06:41:38 215552 --a------ C:\WINDOWS\system32\ALOWMVFile.dll <Not Verified; NCT Company Ltd.; NCTWMVFile ActiveX DLL>
    2007-11-19 06:41:38 403968 --a------ C:\WINDOWS\system32\ALOWMAFile2.dll <Not Verified; Online Media Technologies Ltd.; NCTWMAFile2 ActiveX DLL>
    2007-11-19 06:41:38 188416 --a------ C:\WINDOWS\system32\ALOVideoFile.dll <Not Verified; NCT Company Ltd.; NCTVideoFile ActiveX DLL>
    2007-11-19 06:41:38 495104 --a------ C:\WINDOWS\system32\ALOVideoCoreM.dll <Not Verified; NCT Company Ltd.; NCTVideoCoreM ActiveX DLL>
    2007-11-19 06:41:38 780288 --a------ C:\WINDOWS\system32\ALOVideoCompress.dll <Not Verified; NCT Company Ltd.; NCTVideoCompress ActiveX DLL>
    2007-11-19 06:41:38 249856 --a------ C:\WINDOWS\system32\ALOQuickTimeFile.dll <Not Verified; Online Media Technologies Company Ltd.; NCTQuickTimeFile Module>
    2007-11-19 06:41:38 382464 --a------ C:\WINDOWS\system32\ALOAVIFile.dll <Not Verified; NCT Company Ltd.; NCTAVIFile ActiveX DLL>
    2007-11-19 06:41:38 90112 --a------ C:\WINDOWS\system32\ALOAudioFormatSettings3.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFormatSettings3 Module>
    2007-11-19 06:41:38 877568 --a------ C:\WINDOWS\system32\ALOAudioFile2.dll <Not Verified; NCT Company Ltd.; NCTAudioFile2 ActiveX DLL>
    2007-11-19 06:41:37 2846720 --a------ C:\WINDOWS\system32\ALOAudioCompress3.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress3 Module>
    2007-11-19 06:41:37 778240 --a------ C:\WINDOWS\system32\ALOAudioCompress2.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress2 Module>


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}]
    02/06/2008 11:16 PM 29813 --ahs---- C:\Program Files\Internet Explorer\IEXPLORE32.win

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5E87A05-F463-4841-B19E-DD3EC3862368}]
    02/06/2008 11:16 PM 30346 --ahs---- C:\Program Files\Internet Explorer\IEXPLORE32.Sys

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE12D60D-AD9A-4095-B839-3BE6862679FD}]
    02/06/2008 11:16 PM 35992 --ahs---- C:\Program Files\Internet Explorer\IEXPLORE32.Dat

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MCUpdateExe "= "C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [01/11/2006 11:05 AM]
    "MCAgentExe "= "c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [09/22/2005 05:29 PM]
    "igfxtray "= "C:\WINDOWS\system32\igfxtray.exe" [11/27/2005 09:55 PM]
    "igfxhkcmd "= "C:\WINDOWS\system32\hkcmd.exe" [11/27/2005 09:52 PM]
    "igfxpers "= "C:\WINDOWS\system32\igfxpers.exe" [11/27/2005 09:55 PM]
    "TPSMain "= "TPSMain.exe" [05/31/2005 09:00 PM C:\WINDOWS\system32\TPSMain.exe]
    "PSQLLauncher "= "C:\Program Files\Protector Suite QL\launcher.exe" [05/05/2006 04:36 PM]
    "ThpSrv "= "thpsrv /logon" []
    "THotkey "= "C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [01/05/2006 02:02 PM]
    "SynTPLpr "= "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [12/16/2005 04:34 PM]
    "SynTPEnh "= "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [12/16/2005 04:32 PM]
    "LtMoh "= "C:\Program Files\ltmoh\Ltmoh.exe" [08/18/2004 03:37 AM]
    "AGRSMMSG "= "AGRSMMSG.exe" [10/15/2005 06:29 AM C:\WINDOWS\agrsmmsg.exe]
    "NDSTray.exe "= "NDSTray.exe" []
    "TFncKy "= "TFncKy.exe" []
    "DockMsgFrom "= "C:\Program Files\Toshiba\Toshiba Applet\DockMsgFrom.exe" []
    "PadTouch "= "C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" []
    "SmoothView "= "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [04/26/2005 04:13 PM]
    "dla "= "C:\WINDOWS\system32\dla\DLACTRLW.exe" [10/06/2005 05:20 AM]
    "Pinger "= "c:\toshiba\ivp\ism\pinger.exe" [03/17/2005 05:37 PM]
    "VSOCheckTask "= "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [07/08/2005 05:18 PM]
    "TMESRV.EXE "= "C:\Program Files\TOSHIBA\TME3\TMESRV31.exe" [01/18/2005 02:18 PM]
    "TMERzCtl.EXE "= "C:\Program Files\TOSHIBA\TME3\TMERzCtl.exe" [03/17/2005 09:08 PM]
    "RTHDCPL "= "RTHDCPL.EXE" [12/09/2005 03:49 PM C:\WINDOWS\RTHDCPL.exe]
    "Alcmtr "= "ALCMTR.EXE" [05/03/2005 06:43 PM C:\WINDOWS\Alcmtr.exe]
    "IntelZeroConfig "= "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [12/05/2005 11:37 AM]
    "IntelWireless "= "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [11/28/2005 10:41 AM]
    "VirusScan Online "= "C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [08/10/2005 12:49 PM]
    "RealTray "= "C:\Program Files\Real\RealPlayer\RealPlay.exe" [12/06/2005 02:24 PM]
    "OASClnt "= "C:\Program Files\McAfee.com\VSO\oasclnt.exe" [08/11/2005 09:02 PM]
    "CFSServ.exe "= "CFSServ.exe" []

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 04:00 AM]
    "TOSCDSPD "= "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [12/30/2004 12:32 AM]
    "msnmsgr "= "C:\Program Files\MSN Messenger\MsnMsgr.exe" [01/19/2007 11:54 AM]
    "swg "= "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [08/05/2007 12:20 PM]
    "svcshare "= "C:\WINDOWS\system32\drivers\spoclsv.exe" [01/13/2007 10:51 AM]
    "Tok-Cirrhatus-2025 "= "C:\Documents and Settings\mohamed\Local Settings\Application Data\br5073on.exe" []

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "Tok-Cirrhatus "=

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Metamail Trust Manager.lnk - C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe [6/12/2006 5:29:22 PM]
    RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [12/5/2005 7:10:57 PM]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
    "DisableCMD "=0 (0x0)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{91B1E846-2BEF-4345-8848-7699C7C9935F} "= C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll [ ]
    "{A93A4625-6216-499C-B360-BBD0A7C0D479} "= C:\Program Files\Common Files\Microsoft Shared\MSINFO\QQGS1.dll [10/03/2007 04:52 PM 240747]
    "{1AB09B3F-A6D0-4B55-B87D-264934EBEAED} "= C:\Program Files\Internet Explorer\PLUGINS\WinSys84.Sys [02/07/2008 05:58 AM 45171]
    "{D544C22D-1F70-4B1E-873D-D8DABEB26695} "= C:\Program Files\Common Files\Microsoft Shared\MSINFO\atmQQ2.dll [01/30/2008 11:17 AM 21650]
    "{C5E87A05-F463-4841-B19E-DD3EC3862368} "= C:\Program Files\Internet Explorer\IEXPLORE32.Sys [02/06/2008 11:16 PM 30346]
    "{EE12D60D-AD9A-4095-B839-3BE6862679FD} "= C:\Program Files\Internet Explorer\IEXPLORE32.Dat [02/06/2008 11:16 PM 35992]
    "{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E} "= C:\Program Files\Internet Explorer\IEXPLORE32.win [02/06/2008 11:16 PM 29813]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    psqlpwd.dll 05/05/2006 04:48 PM 40448 C:\WINDOWS\system32\psqlpwd.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Notification Packages "= scecli psqlpwd


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
    Auto\command- C:\setup.exe
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01409a22-35fd-11dc-91dd-00038a000015}]
    Auto\command- F:\setup.exe
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3009eac-46b0-11dc-92be-00038a000015}]
    Auto\command- F:\setup.exe
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac6b421a-4914-11dc-92e4-00038a000015}]
    Auto\command- F:\setup.exe
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ade1cffc-6c77-11dc-944a-00038a000015}]
    Auto\command- F:\setup.exe
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd6f8fb6-3123-11dc-91b3-00038a000015}]
    Auto\command- G:\setup.exe
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4124604-6c5d-11dc-9447-00038a000015}]
    Auto\command- F:\setup.exe
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe




    -- End of Deckard's System Scanner: finished at 2008-02-07 06:01:04 ------------
     
  5. 2008/02/08
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Dave,

    At last I have the Panda scan Log..:)

    ==========

    Incident Status Location

    Virus:W32/Radoppan.I Disinfected C:\Program Files\America Online 9.0\MyCalendar\help\cal_help.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\America Online 9.0\MyCalendar.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\America Online 9.0\pp.htm
    Virus:Trj/QQpass.AVS Disinfected C:\Program Files\Common Files\Microsoft Shared\MSInfo\atmQQ2.dll
    Virus:Trj/Lineage.GND Disinfected C:\Program Files\Internet Explorer\IEXPLORE32.ime
    Possible Virus. Not disinfected C:\Program Files\Internet Explorer\IEXPLORE32.jmp
    Virus:Trj/Lineage.GND Disinfected C:\Program Files\Internet Explorer\IEXPLORE32.New
    Virus:Generic Malware Disinfected C:\Program Files\Internet Explorer\PLUGINS\SysWin74.Jmp
    Virus:W32/Radoppan.I Disinfected C:\Program Files\InterVideo\WinDVD\Html\Default\InterVideo.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\InterVideo\WinDVD\Html\Default\WinDVD.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\InterVideo\WinDVD\Html\ENU\InterVideo.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\InterVideo\WinDVD\Html\ENU\WinDVD.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\IPWireless Inc\IPWireless PC Software\Documents\Version.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\IPWireless Inc\IPWireless PC Software\FindExe.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Learn English\Effects\Help\LearnE2A.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Learn English\Games\game.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Learn English\Internet\1article.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Metamail Inc\Metamail Tray\MetamailTrayAbout.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\CLRCHK.JSP
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\FONTLIST.JSP
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\OFREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\OLREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\ONREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\ONTOUR.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\ONTOURNF.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\ONTOURST.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\PBREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\PPREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\PVREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\WDREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\1033\XLREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Microsoft Office\OFFICE11\INTLBAND.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Ozone\Audio Converter\help\help.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\QuickTime\QuickTime Read Me.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Real\RealPlayer\playrlic.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Real\RealPlayer\Readme.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Bad_Read_Source.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\BufferUnderrun.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\copy_err.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Drives_In_Use.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Files.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\music_scan.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Recording.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Space_Disc.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Space_HDD.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Testing_Disc.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Unknown_Error.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Explain\Verify.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\readme.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\1.0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.1.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.3.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.5.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.1.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.3.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.5.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\4.0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\4.1.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\4.2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\5.0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\5.1.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\5.1a.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\5.2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\6.0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\6.1.htm
     
  6. 2008/02/08
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Panda Log (2nd part)


    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\6.2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\7.0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.1.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.3.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.4.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.5.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\glossary.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\index.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Sonic\RecordNow!\upgrade.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\cfloghis.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\cflogtmp.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\cf1_0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\cf1_1.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\cf1_2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\cf1_3.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\header.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\menu.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\top.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\top2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_1.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_3.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_4.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_5.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_6.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_7.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_0.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_1.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_10.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_11.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_13.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_17.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_2.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_3.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_4.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_5.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_6.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_7.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_8.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_9.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\ConfigFree\FUG\index.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\MyConnect Special Offer\specialoffer.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\kihon_bottom.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\kihon_header.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\kihon_index.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\kihon_left.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\kihon_main.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\kihon_right.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\shindan_bottom.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\shindan_header.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\shindan_index.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\shindan_left.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\shindan_main.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\PCDiag\shindan_right.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\TOSHIBA\Windows Utilities\SVPWTool\README.HTM
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-au\noext.htm
     
  7. 2008/02/08
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Panda Scan Log (3rd part)


    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-au\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-ca\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-ca\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-gb\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-gb\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-id\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-id\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-ie\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-ie\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-in\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-in\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-my\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-my\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-nz\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-nz\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-ph\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-ph\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-sg\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-sg\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-us\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-us\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-ww\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-ww\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-za\noext.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Windows Live Toolbar\en-za\offline.htm
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_atb.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_catb.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_cnf.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_cotb.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_ctb.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_fantip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_fantipg.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_fintip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_fintipg.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_grptip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_grptipg.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_logtip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_mailatip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_mailtip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_map.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_mlbtip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_mlbtipg.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_msgratip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_msgrtip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_nbatip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_nbatipg.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_newstip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_newstipg.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_nfltip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_nfltipg.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_opt.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_pub.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_srchtip.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_upg.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Companion\Data\dlg_wp.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\cd.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\default.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\devices.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\home.html
    Virus:W32/Radoppan.I Disinfected C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\networkmusic.html
    Virus:W32/Radoppan.U.drp Renamed C:\setup.exe
    Virus:Generic Malware Disinfected C:\WINDOWS\pz.exe
    Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.msn
    Virus:W32/Radoppan.U.drp Renamed C:\WINDOWS\system32\drivers\spoclsv_exe.vir
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\WKSHARED\OEM\WS06WARR.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\STANDARD\HELP.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\STANDARD\PAGES.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\STANDARD\START.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\STANDARD\TASKS.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\STANDARD\WKSGSG.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\SUITE\HELP.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\SUITE\PAGES.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\SUITE\START.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\SUITE\TASKS.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\SUITE\WKSGSG.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\MSWORKS\PFILES\OFFICE\PPV\PVREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\1033\OFREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\1033\OLREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\1033\PBREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\1033\PPREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\1033\PVREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\1033\WDREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\1033\XLREADME.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\README.HTM
    Virus:W32/Radoppan.I Disinfected C:\WORKSSETUP\OFFICE\SETUP.HTM
    Virus:Trj/QQPass.AEG Disinfected C:\xteq2
     
  8. 2008/02/08
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Delete the following files, if present.

    C:\setup.exe
    C:\xteq2
    C:\WINDOWS\pz.exe
    C:\WINDOWS\system32\drivers\etc\hosts.msn
    C:\WINDOWS\system32\drivers\spoclsv_exe.vir
    C:\Program Files\Common Files\Microsoft Shared\MSInfo\atmQQ2.dll
    C:\Program Files\Internet Explorer\IEXPLORE32.ime
    C:\Program Files\Internet Explorer\IEXPLORE32.jmp
    C:\Program Files\Internet Explorer\IEXPLORE32.New
    C:\Program Files\Internet Explorer\PLUGINS\SysWin74.Jmp


    You have a flash drive infection. Please download Flash_Disinfector by sUBs and save it to your desktop:

    NOTE: In the event you already have Flash_Disinfector, this is a new version that I need you to download.

    • Plug in your USB flash drive.
    • Double-click Flash_Disinfector.exe to run it.
    • Follow any prompts that may appear.
    • Your desktop will vanish for a while, and then reappear. This is normal.
    • Wait until the program has finished scanning, then please exit the program. If you use more than 1 flash drive, run the tool with each plugged in.

    Download ComboFix by sUBs from here, saving the file to your desktop.

    It's best disable realtime protection applications as they sometime interfere with the tool. Check this link for your applicable programs.

    • Close all open programs and windows
    • Double click combofix.exe and follow the prompts.
    • It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log and a new HijackThis log in your next reply.
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall
     
  9. 2008/02/09
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Dave,

    Please find below the log of Combofix.

    ComboFix 08-02.05.3 - mohamed 2008-02-09 21:53:35.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.167 [GMT -8:00]
    Running from: C:\Documents and Settings\mohamed\Desktop\ComboFix.exe
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\6dac0fb86b4deb069a9600633777\Desktop_.ini
    C:\6dac0fb86b4deb069a9600633777\update\Desktop_.ini
    C:\980bebc1b839fe1333\Desktop_.ini
    C:\980bebc1b839fe1333\update\Desktop_.ini
    C:\Autorun.inf
    C:\cc478d51da801b1fcbbb93910d\Desktop_.ini
    C:\cc478d51da801b1fcbbb93910d\update\Desktop_.ini
    C:\Config.Msi\Desktop_.ini
    C:\d95c693f166a31e2581f\Desktop_.ini
    C:\DOCS\Desktop_.ini
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    C:\Documents and Settings\mohamed\Desktop\gada\Desktop_.ini
    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\Desktop_.ini
    C:\MSOCache\All Users\Desktop_.ini
    C:\MSOCache\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\ActiveX\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Esl\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Help\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Help\ENU\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\Images\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Javascripts\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\en_US\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\ENU\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Optional\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\PMP\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\ENU\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\en_US\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\MPP\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\images\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\ENU\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Templates\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\ENU\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins3d\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\SPPlugins\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Reader\WebSearch\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Resource\CMap\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Resource\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\PFM\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\LanguageNames\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Proximity\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Setup Files\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\Desktop_.ini
    C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\ENU\Desktop_.ini
    C:\Program Files\Adobe\Desktop_.ini
    C:\Program Files\America Online 9.0\backup\Desktop_.ini
    C:\Program Files\America Online 9.0\backup\restore\Desktop_.ini
    C:\Program Files\America Online 9.0\components\Desktop_.ini
    C:\Program Files\America Online 9.0\cool\Desktop_.ini
    C:\Program Files\America Online 9.0\Desktop_.ini
    C:\Program Files\America Online 9.0\download\Desktop_.ini
    C:\Program Files\America Online 9.0\Jiti\Desktop_.ini
    C:\Program Files\America Online 9.0\media\Desktop_.ini
    C:\Program Files\America Online 9.0\media\nmpx\Desktop_.ini
    C:\Program Files\America Online 9.0\media\nmpx\plugins\Desktop_.ini
    C:\Program Files\America Online 9.0\media\nmpxchat\Desktop_.ini
    C:\Program Files\America Online 9.0\media\nmpxchat\plugins\Desktop_.ini
    C:\Program Files\America Online 9.0\MyCalendar\Desktop_.ini
    C:\Program Files\America Online 9.0\MyCalendar\help\Desktop_.ini
    C:\Program Files\America Online 9.0\sounds\Desktop_.ini
    C:\Program Files\America Online 9.0\sounds\us\Desktop_.ini
    C:\Program Files\America Online 9.0\tool\Desktop_.ini
    C:\Program Files\Audio MP3 Converter\Desktop_.ini
    C:\Program Files\Audio MP3 Converter\skins\Desktop_.ini
    C:\Program Files\Audio MP3 Converter\temp\Desktop_.ini
    C:\Program Files\Desktop_.ini
    C:\Program Files\DVD-RAM\Desktop_.ini
    C:\Program Files\DVD-RAM\WinXP\Desktop_.ini
    C:\Program Files\DVD-RAM\WinXP\DVD-RAM Driver\Desktop_.ini
    C:\Program Files\easetech\AudioConverter\Desktop_.ini
    C:\Program Files\easetech\AudioConverter\help\Desktop_.ini
    C:\Program Files\easetech\AudioConverter\skins\Desktop_.ini
    C:\Program Files\easetech\Desktop_.ini
    C:\Program Files\Google\Common\Desktop_.ini
    C:\Program Files\Google\Common\Google Updater\Desktop_.ini
    C:\Program Files\Google\Desktop_.ini
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\Desktop_.ini
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\swg-2.0.301.7164\Desktop_.ini
    C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\Desktop_.ini
    C:\Program Files\Google\GoogleToolbarNotifier\Desktop_.ini
    C:\Program Files\illiminable\Desktop_.ini
    C:\Program Files\illiminable\oggcodecs\Desktop_.ini
    C:\Program Files\Intel\Desktop_.ini
    C:\Program Files\Intel\INFInst\Desktop_.ini
    C:\Program Files\Intel\Wireless\AutoImport\Desktop_.ini
    C:\Program Files\Intel\Wireless\Bin\Desktop_.ini
    C:\Program Files\Intel\Wireless\Bin\EvTrace\DB\Desktop_.ini
    C:\Program Files\Intel\Wireless\Bin\EvTrace\Desktop_.ini
    C:\Program Files\Intel\Wireless\Bin\FrameworkPlugins\Desktop_.ini
    C:\Program Files\Intel\Wireless\Desktop_.ini
    C:\Program Files\Intel\Wireless\Help\Desktop_.ini
    C:\Program Files\Intel\Wireless\ProfileImporters\Desktop_.ini
    C:\Program Files\Internet Explorer\IEXPLORE32.Dat
    C:\Program Files\Internet Explorer\IEXPLORE32.Sys
    C:\Program Files\Internet Explorer\IEXPLORE32.win
    C:\Program Files\InterVideo\Common\Bin\Desktop_.ini
    C:\Program Files\InterVideo\Common\Desktop_.ini
    C:\Program Files\InterVideo\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Html\Default\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Html\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Html\ENU\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Html\Images\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Audio Effect Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Audio Mode Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Audio Spatializer Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Audio SRS Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Bookmak Window\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Color Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Display Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Language Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Navigation Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\SoundVu DMO Subpanel\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\Video Window\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\VR Window\Desktop_.ini
    C:\Program Files\InterVideo\WinDVD\Skins\WinDVD 5\WinDVD Player\Desktop_.ini
    C:\Program Files\IPWireless Inc\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Config\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Config\Tcp\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Config\Tcp\Win2k\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Config\Tcp\Win9x\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Documents\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Modem\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\PCMCIA\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\PCMCIA\Win2K\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\PCMCIA\Win98\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\PCMCIA\WinME\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\PCMCIA\WinXP\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\Utils\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\Win2k\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\Win2k\inf\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\Win98\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\Win98\inf\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\Win98\system\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\WinME\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\WinME\inf\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\WinME\system\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\WinXP\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Drivers\Usb\WinXP\inf\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Operator\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Operator\P1_3G4\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Operator\P1B\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Operator\P1C\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Operator\P1D\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Operator\PCMCIA\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Dun\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Dun\Win95\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Dun\Win98SE\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Ndis\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Ndis\Win98SE\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Tcp\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Tcp\Win2k\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Tcp\Win95\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Patches\Tcp\Win98\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\PPPoE\Desktop_.ini
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Upgrade\Desktop_.ini
     
  10. 2008/02/09
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    C:\Program Files\Java\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\bin\client\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\bin\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\applet\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\audio\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\cmm\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\ext\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\fonts\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\i386\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\im\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\images\cursors\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\images\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\javaws\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\management\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\security\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Africa\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\America\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\America\Indiana\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\America\Kentucky\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\America\North_Dakota\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Antarctica\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Asia\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Atlantic\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Australia\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Etc\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Europe\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Indian\Desktop_.ini
    C:\Program Files\Java\jre1.5.0_04\lib\zi\Pacific\Desktop_.ini
    C:\Program Files\Learn English\Desktop_.ini
    C:\Program Files\Learn English\Effects\AniHelp\AniBmp\Desktop_.ini
    C:\Program Files\Learn English\Effects\AniHelp\AniBmp\Res1\Desktop_.ini
    C:\Program Files\Learn English\Effects\AniHelp\AniBmp\Res2\Desktop_.ini
    C:\Program Files\Learn English\Effects\AniHelp\AniBmp\Res3\Desktop_.ini
    C:\Program Files\Learn English\Effects\AniHelp\AniWav\Desktop_.ini
    C:\Program Files\Learn English\Effects\AniHelp\Desktop_.ini
    C:\Program Files\Learn English\Effects\Desktop_.ini
    C:\Program Files\Learn English\Effects\Help\Desktop_.ini
    C:\Program Files\Learn English\Effects\Help\LearnE2A_files\Desktop_.ini
    C:\Program Files\Learn English\Effects\Help\LearnE2E_files\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\About\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\About\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\About\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Achieve\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Achieve\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Achieve\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Conversation\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Conversation\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Conversation\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Exercises\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Exercises\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Exercises\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Games\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Games\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Games\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Goals\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Goals\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Goals\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Grammar\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Grammar\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Grammar\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Internet\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Internet\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Internet\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lesson\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lesson\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lesson\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\A\Book1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\A\Book2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\A\Book3\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\A\Book4\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\A\Book5\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\E\Book1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\E\Book2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\E\Book3\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\E\Book4\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\E\Book5\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Lessons\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Levels\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Levels\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Levels\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Main\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Main\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Main\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\MatchExercise\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\MatchExercise\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\MatchExercise\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLesson1\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLesson1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLesson1\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLesson2\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLesson2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLesson2\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLevel\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLevel\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\PreLevel\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Progress\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Progress\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Progress\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Reading\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Reading\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Reading\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Sign\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Sign\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Sign\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Test\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Test\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Test\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Vocabulary\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Vocabulary\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res1\Vocabulary\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\About\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\About\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\About\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Achieve\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Achieve\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Achieve\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Conversation\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Conversation\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Conversation\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Exercises\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Exercises\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Exercises\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Games\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Games\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Games\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Goals\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Goals\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Goals\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Grammar\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Grammar\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Grammar\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Internet\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Internet\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Internet\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lesson\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lesson\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lesson\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\A\Book1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\A\Book2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\A\Book3\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\A\Book4\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\A\Book5\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\E\Book1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\E\Book2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\E\Book3\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\E\Book4\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\E\Book5\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Lessons\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Levels\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Levels\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Levels\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Main\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Main\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Main\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\MatchExercise\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\MatchExercise\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\MatchExercise\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLesson1\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLesson1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLesson1\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLesson2\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLesson2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLesson2\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLevel\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLevel\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\PreLevel\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Progress\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Progress\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Progress\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Reading\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Reading\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Reading\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Sign\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Sign\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Sign\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Test\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Test\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Test\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Vocabulary\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Vocabulary\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res2\Vocabulary\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\About\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\About\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\About\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Achieve\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Achieve\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Achieve\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Conversation\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Conversation\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Conversation\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Exercises\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Exercises\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Exercises\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Games\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Games\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Games\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Goals\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Goals\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Goals\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Grammar\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Grammar\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Grammar\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Internet\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Internet\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Internet\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lesson\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lesson\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lesson\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\A\Book1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\A\Book2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\A\Book3\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\A\Book4\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\A\Book5\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\E\Book1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\E\Book2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\E\Book3\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\E\Book4\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\E\Book5\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Lessons\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Levels\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Levels\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Levels\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Main\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Main\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Main\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\MatchExercise\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\MatchExercise\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\MatchExercise\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLesson1\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLesson1\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLesson1\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLesson2\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLesson2\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLesson2\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLevel\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLevel\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\PreLevel\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Progress\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Progress\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Progress\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Reading\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Reading\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Reading\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Sign\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Sign\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Sign\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Test\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Test\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Test\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Vocabulary\A\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Vocabulary\Desktop_.ini
    C:\Program Files\Learn English\Effects\Res3\Vocabulary\E\Desktop_.ini
    C:\Program Files\Learn English\Effects\Sounds\Desktop_.ini
    C:\Program Files\Learn English\Games\Desktop_.ini
    C:\Program Files\Learn English\Games\game1_files\Desktop_.ini
    C:\Program Files\Learn English\Games\Motys98\Desktop_.ini
    C:\Program Files\Learn English\Games\Wav\Desktop_.ini
    C:\Program Files\Learn English\Internet\Desktop_.ini
    C:\Program Files\Learn English\Internet\speikr\Desktop_.ini
    C:\Program Files\Learn English\Internet\Wav\Desktop_.ini
    C:\Program Files\Learn English\Users\Desktop_.ini
    C:\Program Files\ltmoh\Desktop_.ini
    C:\Program Files\McAfee.com\Agent\app\Desktop_.ini
    C:\Program Files\McAfee.com\Agent\Custom_Uninstall\Desktop_.ini
    C:\Program Files\McAfee.com\Agent\Desktop_.ini
    C:\Program Files\McAfee.com\Agent\submgr\6,0,0,15\Desktop_.ini
    C:\Program Files\McAfee.com\Agent\submgr\6,0,0,16\Desktop_.ini
    C:\Program Files\McAfee.com\Agent\submgr\6,0,0,3\Desktop_.ini
    C:\Program Files\McAfee.com\Agent\submgr\Desktop_.ini
    C:\Program Files\McAfee.com\Agent\Uninst\Desktop_.ini
    C:\Program Files\McAfee.com\Desktop_.ini
    C:\Program Files\McAfee.com\Shared\Desktop_.ini
    C:\Program Files\McAfee.com\Shared\mcuicfg\6,0,0,4\Desktop_.ini
    C:\Program Files\McAfee.com\Shared\mcuicfg\Desktop_.ini
    C:\Program Files\McAfee.com\VSO\Dat\4858\Desktop_.ini
    C:\Program Files\McAfee.com\VSO\Dat\Desktop_.ini
    C:\Program Files\McAfee.com\VSO\Desktop_.ini
    C:\Program Files\McAfee.com\VSO\Res00\Desktop_.ini
    C:\Program Files\Metamail Inc\Desktop_.ini
    C:\Program Files\Metamail Inc\Metamail Reader\Archive\14 e6 34 0c 00 00 00 00 00 0f\CampaignID_9C3FF896-EE66-4F9B-9D71-E5039763FD07\Desktop_.ini
    C:\Program Files\Metamail Inc\Metamail Reader\Archive\14 e6 34 0c 00 00 00 00 00 0f\Desktop_.ini
    C:\Program Files\Metamail Inc\Metamail Reader\Archive\Desktop_.ini
    C:\Program Files\Metamail Inc\Metamail Reader\Desktop_.ini
    C:\Program Files\Metamail Inc\Metamail Tray\Desktop_.ini
    C:\Program Files\Metamail Inc\Updates\Desktop_.ini
    C:\Program Files\Metamail Inc\Updates\First\Desktop_.ini
    C:\Program Files\Metamail Inc\Updates\Second\Desktop_.ini
    C:\Program Files\Metamail Inc\Updates\Temp\Desktop_.ini
    C:\Program Files\Microsoft ActiveSync\Desktop_.ini
    C:\Program Files\Microsoft Office\CLIPART\Desktop_.ini
    C:\Program Files\Microsoft Office\CLIPART\PUB60COR\Desktop_.ini
    C:\Program Files\Microsoft Office\CLIPART\Publisher\Backgrounds\Desktop_.ini
    C:\Program Files\Microsoft Office\CLIPART\Publisher\Desktop_.ini
    C:\Program Files\Microsoft Office\Desktop_.ini
    C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\1033\Desktop_.ini
    C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\Desktop_.ini
    C:\Program Files\Microsoft Office\MEDIA\Desktop_.ini
    C:\Program Files\Microsoft Office\MEDIA\OFFICE11\1033\Desktop_.ini
    C:\Program Files\Microsoft Office\MEDIA\OFFICE11\AUTOSHAP\Desktop_.ini
    C:\Program Files\Microsoft Office\MEDIA\OFFICE11\BULLETS\Desktop_.ini
    C:\Program Files\Microsoft Office\MEDIA\OFFICE11\Desktop_.ini
    C:\Program Files\Microsoft Office\MEDIA\OFFICE11\LINES\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\1033\1A1\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\1033\1CA\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\1033\BOTSTYLE\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\1033\DataServices\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\1033\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\1033\PUBBRD\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\1033\PUBFTSCM\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\1033\PUBWIZ\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\ADDINS\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\CONVERT\1033\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\CONVERT\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\FORMS\1033\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\FORMS\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\HTML\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\Library\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\Migration\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\QUERIES\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\SAMPLES\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\STARTUP\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\XLATORS\Desktop_.ini
    C:\Program Files\Microsoft Office\OFFICE11\XLSTART\Desktop_.ini
    C:\Program Files\Microsoft Office\PowerPoint Viewer\Desktop_.ini
    C:\Program Files\Microsoft Office\Templates\1033\Desktop_.ini
    C:\Program Files\Microsoft Office\Templates\1033\FAX\Desktop_.ini
    C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\Desktop_.ini
    C:\Program Files\Microsoft Office\Templates\1033\ONENOTE\Stationery\Desktop_.ini
    C:\Program Files\Microsoft Office\Templates\Desktop_.ini
    C:\Program Files\Microsoft Office\Templates\Presentation Designs\Desktop_.ini
    C:\Program Files\Microsoft Works\1033\Desktop_.ini
    C:\Program Files\Microsoft Works\1033\Tasks\Desktop_.ini
    C:\Program Files\Microsoft Works\1033\Wizards\Desktop_.ini
    C:\Program Files\Microsoft Works\Desktop_.ini
    C:\Program Files\Microsoft Works\Images\Desktop_.ini
    C:\Program Files\Microsoft.NET\Desktop_.ini
    C:\Program Files\Microsoft.NET\Primary Interop Assemblies\Desktop_.ini
    C:\Program Files\MP3 CD Converter\bitmaps\Desktop_.ini
    C:\Program Files\MP3 CD Converter\Desktop_.ini
    C:\Program Files\MP3 CD Converter\Help\Desktop_.ini
    C:\Program Files\MP3 CD Converter\images\Desktop_.ini
    C:\Program Files\MP3 CD Converter\Language\Desktop_.ini
    C:\Program Files\MP3 CD Converter\Temp\Desktop_.ini
    C:\Program Files\MSN Gaming Zone\Desktop_.ini
    C:\Program Files\MSN Messenger\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\10\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\1028\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\1046\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\11\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\12\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\16\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\17\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\18\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\19\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\20\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\22\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\25\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\29\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\31\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\4\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\6\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\7\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\8\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\9\Desktop_.ini
    C:\Program Files\MSN Messenger\Device Manager\Loc\Desktop_.ini
    C:\Program Files\MSXML 4.0\Desktop_.ini
    C:\Program Files\Online Services\Desktop_.ini
    C:\Program Files\Ozone\Audio Converter\Desktop_.ini
    C:\Program Files\Ozone\Audio Converter\help\Desktop_.ini
    C:\Program Files\Ozone\Desktop_.ini
    C:\Program Files\Protector Suite QL\browser\Desktop_.ini
    C:\Program Files\Protector Suite QL\Desktop_.ini
    C:\Program Files\Protector Suite QL\Drivers\Desktop_.ini
    C:\Program Files\Protector Suite QL\Drivers\WinXP\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0404\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0407\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0408\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0409\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\040c\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0410\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0411\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0412\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0413\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0419\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0804\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0816\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\0c0a\Desktop_.ini
    C:\Program Files\Protector Suite QL\mui\Desktop_.ini
    C:\Program Files\Protector Suite QL\rsc\Desktop_.ini
    C:\Program Files\Pure Networks\Desktop_.ini
    C:\Program Files\Pure Networks\Port Magic\Desktop_.ini
    C:\Program Files\Pure Networks\Port Magic\RG\Desktop_.ini
    C:\Program Files\QuickTime\Desktop_.ini
    C:\Program Files\QuickTime\Plugins\Desktop_.ini
    C:\Program Files\Real\Desktop_.ini
    C:\Program Files\Real\RealPlayer\Desktop_.ini
    C:\Program Files\Real\RealPlayer\Msg\0_1155166162\Desktop_.ini
    C:\Program Files\Real\RealPlayer\Msg\0_1161123042\Desktop_.ini
    C:\Program Files\Real\RealPlayer\Msg\0_1166484035\Desktop_.ini
    C:\Program Files\Real\RealPlayer\Msg\0_1175545881\Desktop_.ini
    C:\Program Files\Real\RealPlayer\Msg\10_1187985326\Desktop_.ini
    C:\Program Files\Real\RealPlayer\Msg\Desktop_.ini
    C:\Program Files\Real\RealPlayer\Setup\Desktop_.ini
    C:\Program Files\Real\RhapsodyPlayerEngine\Desktop_.ini
    C:\Program Files\Realtek\Desktop_.ini
    C:\Program Files\Realtek\InstallShield\Desktop_.ini
    C:\Program Files\Sonic\Desktop_.ini
    C:\Program Files\Sonic\DLA\Desktop_.ini
    C:\Program Files\Sonic\DLA\install\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\Explain\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\Explain\Images\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\images\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\skins\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\Tutorial\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\images\Desktop_.ini
    C:\Program Files\Sonic\RecordNow!\Tutorial\Movies\Desktop_.ini
     
  11. 2008/02/09
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    C:\Program Files\Synaptics\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\BP\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\DK\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\FI\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\FR\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\GR\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\IT\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\JP\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\KR\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\LS\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\NL\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\NO\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\SC\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\SE\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\TC\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\TH\Desktop_.ini
    C:\Program Files\Synaptics\SynTP\Media\US\Desktop_.ini
    C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\blue horizon\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\cyberspace\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\digital seed\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\green hill\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\metal work\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\nature\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\normal\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\psychedelic\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\solid jaguar\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFSkin\toy\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFView\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFWANImage\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\CFXICON\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\img\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\img\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\img2\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\img\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\img2\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\FUG\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\ICON\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\Image\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\Launcher\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\Launcher\Image\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\Launcher\Image\Large\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\Launcher\Image\Normal\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\SampleJpeg\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\SMSGIMG\Desktop_.ini
    C:\Program Files\TOSHIBA\ConfigFree\TOKEN\Desktop_.ini
    C:\Program Files\TOSHIBA\DeleteHddRecovery\Desktop_.ini
    C:\Program Files\TOSHIBA\Desktop_.ini
    C:\Program Files\TOSHIBA\Hard Disk Recovery Utilities\Desktop_.ini
    C:\Program Files\TOSHIBA\HDD Protection\Desktop_.ini
    C:\Program Files\TOSHIBA\MyConnect Special Offer\Desktop_.ini
    C:\Program Files\TOSHIBA\MyConnect Special Offer\images\Desktop_.ini
    C:\Program Files\TOSHIBA\PCDiag\Desktop_.ini
    C:\Program Files\TOSHIBA\PCDiag\set_pic\Desktop_.ini
    C:\Program Files\TOSHIBA\Power Saver\Desktop_.ini
    C:\Program Files\TOSHIBA\SD Format\Desktop_.ini
    C:\Program Files\TOSHIBA\TME3\Desktop_.ini
    C:\Program Files\TOSHIBA\TOSCDSPD\Desktop_.ini
    C:\Program Files\TOSHIBA\TOSHIBA Applet\Desktop_.ini
    C:\Program Files\TOSHIBA\TOSHIBA Assist\Desktop_.ini
    C:\Program Files\TOSHIBA\TOSHIBA Controls\Desktop_.ini
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\Desktop_.ini
    C:\Program Files\TOSHIBA\Windows Utilities\Desktop_.ini
    C:\Program Files\TOSHIBA\Windows Utilities\SVPWTool\Desktop_.ini
    C:\Program Files\Trend Micro\Desktop_.ini
    C:\Program Files\Trend Micro\HijackThis\Desktop_.ini
    C:\Program Files\Uninstall Information\Desktop_.ini
    C:\Program Files\Viewpoint\Desktop_.ini
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\Components\Desktop_.ini
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\Desktop_.ini
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\DownloadedComponents\Desktop_.ini
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\Custom Buttons\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-au\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-ca\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-gb\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-id\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-ie\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-in\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-my\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-nz\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-ph\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-sg\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-us\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-ww\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\en-za\Desktop_.ini
    C:\Program Files\Windows Live Toolbar\Extensions\Desktop_.ini
    C:\Program Files\xerox\Desktop_.ini
    C:\Program Files\xerox\nwwia\Desktop_.ini
    C:\Program Files\Yahoo!\Common\Desktop_.ini
    C:\Program Files\Yahoo!\Common\Icons\Desktop_.ini
    C:\Program Files\Yahoo!\Companion\Data\Desktop_.ini
    C:\Program Files\Yahoo!\Companion\Desktop_.ini
    C:\Program Files\Yahoo!\Companion\Installs\cpn\Desktop_.ini
    C:\Program Files\Yahoo!\Companion\Installs\Desktop_.ini
    C:\Program Files\Yahoo!\Desktop_.ini
    C:\Program Files\Yahoo!\Installs\Desktop_.ini
    C:\Program Files\Yahoo!\Shared\Desktop_.ini
    C:\Program Files\Yahoo!\Shared\Graphics\Desktop_.ini
    C:\Program Files\Yahoo!\Shared\Graphics\Indigo\Desktop_.ini
    C:\Program Files\Yahoo!\Shared\Graphics\Maverick\Desktop_.ini
    C:\Program Files\Yahoo!\Shared\Graphics\yme\Desktop_.ini
    C:\Program Files\Yahoo!\Yahoo! Music Engine\Desktop_.ini
    C:\Program Files\Yahoo!\Yahoo! Music Engine\minis\Desktop_.ini
    C:\Program Files\Yahoo!\Yahoo! Music Engine\minis\Kamino\Desktop_.ini
    C:\Program Files\Yahoo!\Yahoo! Music Engine\minis\YME Mini\Desktop_.ini
    C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\Desktop_.ini
    C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\resources\Desktop_.ini
    C:\Program Files\Yahoo!\Yahoo! Music Engine\Plugins\Desktop_.ini
    C:\Program Files\Yahoo!\Yahoo! Music Engine\Support\Desktop_.ini
    C:\RECYCLER\Desktop_.ini
    C:\RECYCLER\S-1-5-21-1460681789-3494792902-3943353954-500\Desktop_.ini
    C:\RECYCLER\S-1-5-21-3454122850-2608146190-3624656239-1006\Desktop_.ini
    C:\setup.exe
    C:\TOSAPINS\AUTOIT\Desktop_.ini
    C:\TOSAPINS\BASE\Desktop_.ini
    C:\TOSAPINS\BIN\Desktop_.ini
    C:\TOSAPINS\COMPS1\Adobe Acrobat Reader0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Adobe Acrobat Reader0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Adobe Acrobat Reader0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Atheros Client Utility (802.11 abg, bg)0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Atheros Client Utility (802.11 abg, bg)0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Atheros Client Utility (802.11 abg, bg)0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Bluetooth Monitor0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Bluetooth Monitor0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Bluetooth Monitor0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Bluetooth Stack for Windows0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Bluetooth Stack for Windows0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Bluetooth Stack for Windows0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\CDDVD Drive Acoustic Silencer0\Desktop_.ini
    C:\TOSAPINS\COMPS1\CDDVD Drive Acoustic Silencer0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\CDDVD Drive Acoustic Silencer0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Config Free Demo Screen Saver0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Config Free Demo Screen Saver0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Config Free Demo Screen Saver0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Config Free0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Config Free0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Config Free0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Desktop_.ini
    C:\TOSAPINS\COMPS1\DLA Packet Writing Software0\Desktop_.ini
    C:\TOSAPINS\COMPS1\DLA Packet Writing Software0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\DLA Packet Writing Software0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\DVD RAM Driver Software0\Desktop_.ini
    C:\TOSAPINS\COMPS1\DVD RAM Driver Software0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\DVD RAM Driver Software0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Infineon TPM Software Professional Package0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Infineon TPM Software Professional Package0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Infineon TPM Software Professional Package0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Infineon Trusted Platform Module Installation Guide0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Infineon Trusted Platform Module Installation Guide0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Infineon Trusted Platform Module Installation Guide0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Intel Chipset Software Installation Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Intel Chipset Software Installation Utility0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Intel Chipset Software Installation Utility0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Intel PROSET Utility (802.11 abg, bg)0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Intel PROSET Utility (802.11 abg, bg)0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Intel PROSET Utility (802.11 abg, bg)0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\InterVideo WinDVD0\Desktop_.ini
    C:\TOSAPINS\COMPS1\InterVideo WinDVD0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\InterVideo WinDVD0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\McAfee Active Shield Antivirus0\Desktop_.ini
    C:\TOSAPINS\COMPS1\McAfee Active Shield Antivirus0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\McAfee Active Shield Antivirus0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Microsoft Office OneNote 2003 SP10\Desktop_.ini
    C:\TOSAPINS\COMPS1\Microsoft Office OneNote 2003 SP10\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Microsoft Office OneNote 2003 SP10\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for A Windows XP SP2 Computer with Multiple Processors(V3)0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for A Windows XP SP2 Computer with Multiple Processors(V3)0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for A Windows XP SP2 Computer with Multiple Processors(V3)0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for ASP.Net May Lead to Authentication Bypass0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for ASP.Net May Lead to Authentication Bypass0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for ASP.Net May Lead to Authentication Bypass0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Availability of Win XP COM+ Hotfix Rollup Package 90\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Availability of Win XP COM+ Hotfix Rollup Package 90\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Availability of Win XP COM+ Hotfix Rollup Package 90\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Cannot Add Windows Components in Win XP0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Cannot Add Windows Components in Win XP0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Cannot Add Windows Components in Win XP0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Client Service for NetWare Could Remote Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Client Service for NetWare Could Remote Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Client Service for NetWare Could Remote Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Cumulative Security Update for Internet Explorer0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Cumulative Security Update for Internet Explorer0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Cumulative Security Update for Internet Explorer0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for DBCS File Names Are Not Displayed0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for DBCS File Names Are Not Displayed0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for DBCS File Names Are Not Displayed0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR DHTML EDITING COMPONENT ACTIVEX CONTROL COULD ALLOW COD0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR DHTML EDITING COMPONENT ACTIVEX CONTROL COULD ALLOW COD0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR DHTML EDITING COMPONENT ACTIVEX CONTROL COULD ALLOW COD0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for DirectShow Could Allow Remote Code Execution(V2)0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for DirectShow Could Allow Remote Code Execution(V2)0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for DirectShow Could Allow Remote Code Execution(V2)0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Display Hibernate Button at Start - TurnOffComputer M0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Display Hibernate Button at Start - TurnOffComputer M0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Display Hibernate Button at Start - TurnOffComputer M0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Fixing Fir Issue0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Fixing Fir Issue0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Fixing Fir Issue0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Fixing Hardware Data Execution Prevention of Win XP SP20\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Fixing Hardware Data Execution Prevention of Win XP SP20\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Fixing Hardware Data Execution Prevention of Win XP SP20\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Graphics Rendering Engine Could Allow Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Graphics Rendering Engine Could Allow Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Graphics Rendering Engine Could Allow Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR HYPERLINK OBJECT LIBRARY COULD ALLOW REMOTE CODE EXECUT0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR HYPERLINK OBJECT LIBRARY COULD ALLOW REMOTE CODE EXECUT0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR HYPERLINK OBJECT LIBRARY COULD ALLOW REMOTE CODE EXECUT0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for HyperTerminal Could Allow Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for HyperTerminal Could Allow Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for HyperTerminal Could Allow Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR IE ACTIVEX SUPPLEMENT0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR IE ACTIVEX SUPPLEMENT0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR IE ACTIVEX SUPPLEMENT0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue in HTML Help Could Allow Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue in HTML Help Could Allow Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue in HTML Help Could Allow Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue in HTML Help Could Allow Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue in HTML Help Could Allow Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue in HTML Help Could Allow Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue MS Color Management Module Could Allow Remote Cod0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue MS Color Management Module Could Allow Remote Cod0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issue MS Color Management Module Could Allow Remote Cod0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issues in TCPIP Could Allow Remote Code Execution and0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issues in TCPIP Could Allow Remote Code Execution and0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issues in TCPIP Could Allow Remote Code Execution and0\MANUAL\IP Could Allow Remote Code Execution and Denial of Service ver. (V2)\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Issues in TCPIP Could Allow Remote Code Execution and0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for LibPNG May Lead to Elevation of Privilege0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for LibPNG May Lead to Elevation of Privilege0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for LibPNG May Lead to Elevation of Privilege0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Agent Could Allow Spoofing0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Agent Could Allow Spoofing0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Agent Could Allow Spoofing0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Collaboration Data Objects Could Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Collaboration Data Objects Could Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Collaboration Data Objects Could Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Windows Installer 3.1 (V2)0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Windows Installer 3.1 (V2)0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for MS Windows Installer 3.1 (V2)0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Network Connection Manager Could Denial of Service0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Network Connection Manager Could Denial of Service0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Network Connection Manager Could Denial of Service0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for OLE and COM Could Allow Remote Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for OLE and COM Could Allow Remote Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for OLE and COM Could Allow Remote Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Plug and Play Remote and Local Elevation of Privilege0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Plug and Play Remote and Local Elevation of Privilege0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Plug and Play Remote and Local Elevation of Privilege0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Server Message Block Could Allow Remote Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Server Message Block Could Allow Remote Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Server Message Block Could Allow Remote Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Server Message Block Could Allow Remote Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Server Message Block Could Allow Remote Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Server Message Block Could Allow Remote Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Step by Step Interactive Training0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Step by Step Interactive Training0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Step by Step Interactive Training0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for the Welcome Music and Video Do Not Play during the OOBE0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for the Welcome Music and Video Do Not Play during the OOBE0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for the Welcome Music and Video Do Not Play during the OOBE0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerabilities in Kerberos0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerabilities in Kerberos0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerabilities in Kerberos0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Print Spooler Service0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Print Spooler Service0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Print Spooler Service0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Remote Desktop Protocol0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Remote Desktop Protocol0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Remote Desktop Protocol0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Telnet Client0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Telnet Client0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerability in Telnet Client0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerabillities in Windows Kernel0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerabillities in Windows Kernel0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Vulnerabillities in Windows Kernel0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Wi-Fi Protected Access 2 (WPA2)0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Wi-Fi Protected Access 2 (WPA2)0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Wi-Fi Protected Access 2 (WPA2)0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR WINDOWS COULD ALLOW INFORMATION DISCLOSURE0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR WINDOWS COULD ALLOW INFORMATION DISCLOSURE0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE FOR WINDOWS COULD ALLOW INFORMATION DISCLOSURE0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Firewall My Network (Subnet) Only0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Firewall My Network (Subnet) Only0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Firewall My Network (Subnet) Only0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Kernel and LSASS Could Allow Elevation of Privi0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Kernel and LSASS Could Allow Elevation of Privi0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Kernel and LSASS Could Allow Elevation of Privi0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Shell Could Allow for Remote Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Shell Could Allow for Remote Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Shell Could Allow for Remote Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Telephony Service Could Allow Remote Code Execu0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Telephony Service Could Allow Remote Code Execu0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for Windows Telephony Service Could Allow Remote Code Execu0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for WordPad Could Allow Code Execution0\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for WordPad Could Allow Code Execution0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\QFE for WordPad Could Allow Code Execution0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Realtek Audio Driver with UAA Bus Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Realtek Audio Driver with UAA Bus Driver0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\Realtek Audio Driver with UAA Bus Driver0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\RecordNow! Basic0\Desktop_.ini
    C:\TOSAPINS\COMPS1\RecordNow! Basic0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\RecordNow! Basic0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\SD Secure Module0\Desktop_.ini
    C:\TOSAPINS\COMPS1\SD Secure Module0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\SD Secure Module0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\SMBIOS ActiveX Control v1.30\Desktop_.ini
    C:\TOSAPINS\COMPS1\SMBIOS ActiveX Control v1.30\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS1\SMBIOS ActiveX Control v1.30\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\SMSC Fir Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS1\SMSC Fir Driver0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Sun Java 2 Runtime Environment0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Sun Java 2 Runtime Environment0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Synaptics TouchPad Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Synaptics TouchPad Driver0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TBIOS Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TBIOS Driver0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Texas Instruments PCIxx21 FlashMedia Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Texas Instruments PCIxx21 FlashMedia Driver0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Assist0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Assist0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Common Modules0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Common Modules0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Controls0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Controls0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Fast Ether LAN Adapter0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Fast Ether LAN Adapter0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Gigabit Ether LAN Adapter0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Gigabit Ether LAN Adapter0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Google Toolbar Installer0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Google Toolbar Installer0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba HDD Protection0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba HDD Protection0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Hotkey Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Hotkey Utility0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Management Console0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Management Console0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Mobile Extension 30\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Mobile Extension 30\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba MyConnect Special Offer Version 1.10\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba MyConnect Special Offer Version 1.10\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA PC Diagnostic Tool0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA PC Diagnostic Tool0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA PC HEALTH CUSTOMIZATION (WINDOWS XP)0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA PC HEALTH CUSTOMIZATION (WINDOWS XP)0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Power Saver0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Power Saver0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA SD Memory Card Format Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA SD Memory Card Format Utility0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Skins for Media Player0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Skins for Media Player0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Software Modem0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Software Modem0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Software Upgrades0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Software Upgrades0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Utilities0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Toshiba Utilities0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Zooming Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS1\TOSHIBA Zooming Utility0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Touch Pad EnableDisable Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Touch Pad EnableDisable Utility0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\User's Guide - Unattended Installation00\Desktop_.ini
    C:\TOSAPINS\COMPS1\User's Guide - Unattended Installation00\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Video display drivers0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Video display drivers0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Windows Media Player 100\Desktop_.ini
    C:\TOSAPINS\COMPS1\Windows Media Player 100\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS1\Wireless Lan Drivers0\Desktop_.ini
    C:\TOSAPINS\COMPS1\Wireless Lan Drivers0\TEXT\Desktop_.ini
    C:\TOSAPINS\COMPS2\Desktop_.ini
    C:\TOSAPINS\COMPS2\SMSC Fir Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS2\SMSC Fir Driver0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Sun Java 2 Runtime Environment0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Sun Java 2 Runtime Environment0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Synaptics TouchPad Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Synaptics TouchPad Driver0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TBIOS Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TBIOS Driver0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Texas Instruments PCIxx21 FlashMedia Driver0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Texas Instruments PCIxx21 FlashMedia Driver0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Assist0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Assist0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Common Modules0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Common Modules0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Controls0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Controls0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Fast Ether LAN Adapter0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Fast Ether LAN Adapter0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Fingerprint Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Fingerprint Utility0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Gigabit Ether LAN Adapter0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Gigabit Ether LAN Adapter0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Google Toolbar Installer0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Google Toolbar Installer0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba HDD Protection0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba HDD Protection0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Hotkey Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Hotkey Utility0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Management Console0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Management Console0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Mobile Extension 30\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Mobile Extension 30\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba MyConnect Special Offer Version 1.10\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba MyConnect Special Offer Version 1.10\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA PC Diagnostic Tool0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA PC Diagnostic Tool0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA PC HEALTH CUSTOMIZATION (WINDOWS XP)0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA PC HEALTH CUSTOMIZATION (WINDOWS XP)0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Power Saver0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Power Saver0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Registration - Metamail0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Registration - Metamail0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA SD Memory Card Format Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA SD Memory Card Format Utility0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Skins for Media Player0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Skins for Media Player0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Software Modem0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Software Modem0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Software Upgrades0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Software Upgrades0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Utilities0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Toshiba Utilities0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Zooming Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS2\TOSHIBA Zooming Utility0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Touch Pad EnableDisable Utility0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Touch Pad EnableDisable Utility0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\User's Guide - Unattended Installation00\Desktop_.ini
    C:\TOSAPINS\COMPS2\User's Guide - Unattended Installation00\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Video display drivers0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Video display drivers0\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Windows Media Player 100\Desktop_.ini
    C:\TOSAPINS\COMPS2\Windows Media Player 100\MANUAL\Desktop_.ini
    C:\TOSAPINS\COMPS2\Wireless Lan Drivers0\Desktop_.ini
    C:\TOSAPINS\COMPS2\Wireless Lan Drivers0\MANUAL\Desktop_.ini
    C:\TOSAPINS\Desktop_.ini
    C:\TOSAPINS\i386\Desktop_.ini
     
  12. 2008/02/09
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    C:\TOSHIBA\BTMonitor\Desktop_.ini
    C:\TOSHIBA\Desktop_.ini
    C:\TOSHIBA\IVP\Desktop_.ini
    C:\TOSHIBA\IVP\ISM\Desktop_.ini
    C:\TOSHIBA\IVP\NetInt\Desktop_.ini
    C:\TOSHIBA\IVP\swupdate\Desktop_.ini
    C:\WINDOWS\system32\drivers\spoclsv.exe
    C:\WINDOWS\system32\kakle.dll
    C:\WINDOWS\system32\winitn.dll
    C:\WORKSSETUP\ASSIST\Desktop_.ini
    C:\WORKSSETUP\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\COMMAPP\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\DAO\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\EQUATION\1033\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\EQUATION\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\GRPHFLT\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\INFORET\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\PROOF\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\TEXTCONV\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\WKSHARED\1033\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\WKSHARED\1033\OEM\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\WKSHARED\1033\SUITE\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\WKSHARED\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\WKSHARED\OEM\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\COMMON\MSSHARED\WKSHARED\SOUND\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\DATA\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\DATA\SV7\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\FONTS\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\OEM\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\STANDARD\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\SUITE\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\TASKS\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\TASKS\LANG1\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\TASKS\LANG2\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\TASKS\LANG3\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\TASKS\LANG4\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\TASKS\LANG5\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\WIZARDS\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\WIZARDS\LANG1\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\1033\WIZARDS\LANG2\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\ANSI\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\BINLANG1\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\BINLANG2\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\IMAGES\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\IMAGES\IMAGESTD\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\IMAGES\IMAGESTE\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\STANDARD\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\MSWORKS\SUITE\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\OFFICE\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PFILES\OFFICE\PPV\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\PSS\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\REDIST\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\REDIST\IE6\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\SXS\Desktop_.ini
    C:\WORKSSETUP\MSWORKS\SYSTEM\Desktop_.ini
    C:\WORKSSETUP\OFFICE\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\OWC10\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\OWC11\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\PFILES\COMMON\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\PFILES\COMMON\MSSHARED\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\PFILES\COMMON\MSSHARED\DW\1033\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\PFILES\COMMON\MSSHARED\DW\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\PFILES\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\1033\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\PFILES\MSOFFICE\OFFICE11\Desktop_.ini
    C:\WORKSSETUP\OFFICE\FILES\SETUP\Desktop_.ini
    E:\autorun.inf
    E:\setup.exe

    ----- BITS: Possible infected sites -----

    hxxp://www.download.windowsupdate.com

    .
    ((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
    .

    2008-02-09 06:56 . 2008-02-09 06:56 1,386,496 --a------ C:\WINDOWS\system32\7A7.tmp
    2008-02-09 06:44 . 2008-02-09 06:44 53,248 --a------ C:\WINDOWS\system32\46C.tmp
    2008-02-09 06:24 . 2007-06-08 09:44 8,576 --a------ C:\WINDOWS\system32\drivers\wpmjwaiopdiu.sys
    2008-02-07 07:28 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
    2008-02-07 07:07 . 2004-08-04 04:00 811,064 --a------ C:\WINDOWS\system32\imjp81k.dll
    2008-02-07 06:51 . 2008-02-09 07:07 30,590 --a------ C:\WINDOWS\system32\pavas.ico
    2008-02-07 06:51 . 2008-02-09 07:07 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
    2008-02-07 06:51 . 2008-02-09 07:07 1,406 --a------ C:\WINDOWS\system32\Help.ico
    2008-02-07 06:50 . 2008-02-09 07:48 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
    2008-02-07 06:48 . 2008-02-07 06:59 <DIR> d-------- C:\Documents and Settings\mohamed\Application Data\Yahoo!
    2008-02-07 06:48 . 2008-02-07 06:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2008-02-07 06:45 . 2008-02-07 06:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
    2008-02-02 23:43 . 2008-02-09 21:55 <DIR> d-------- C:\Program Files\Trend Micro
    2008-02-02 23:32 . 2008-02-02 23:32 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
    2008-02-02 23:32 . 2008-02-02 23:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2008-01-29 06:28 . 2008-02-09 21:54 <DIR> d-------- C:\Deckard
    2008-01-29 06:09 . 2008-02-09 21:54 <DIR> d-------- C:\cc478d51da801b1fcbbb93910d
    2008-01-23 08:30 . 2007-07-09 05:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
    2008-01-22 06:10 . 2008-02-09 21:54 <DIR> d-------- C:\Program Files\IPWireless Inc
    2008-01-22 06:10 . 2004-03-11 21:28 118,784 --a------ C:\WINDOWS\system32\IpwUsb32.dll
    2008-01-22 06:10 . 2003-02-12 18:21 77,232 --a------ C:\WINDOWS\system32\drivers\ipw_mdm.sys
    2008-01-22 06:10 . 2003-12-18 07:51 24,576 -r------- C:\WINDOWS\system32\ipwcomm.dll
    2008-01-22 06:10 . 2003-02-12 18:21 6,080 --a------ C:\WINDOWS\system32\drivers\ipw_cm.sys
    2008-01-22 06:10 . 2003-02-12 18:21 6,032 --a------ C:\WINDOWS\system32\drivers\ipw_mdfl.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-02-10 05:55 --------- d-----w C:\Program Files\Yahoo!
    2008-02-10 05:55 --------- d-----w C:\Program Files\Windows Live Toolbar
    2008-02-10 05:55 --------- d-----w C:\Program Files\Viewpoint
    2008-02-10 05:55 --------- d-----w C:\Program Files\TOSHIBA
    2008-02-10 05:55 --------- d-----w C:\Program Files\Synaptics
    2008-02-10 05:55 --------- d-----w C:\Program Files\Sonic
    2008-02-10 05:55 --------- d-----w C:\Program Files\Realtek
    2008-02-10 05:55 --------- d-----w C:\Program Files\Real
    2008-02-10 05:55 --------- d-----w C:\Program Files\QuickTime
    2008-02-10 05:55 --------- d-----w C:\Program Files\Pure Networks
    2008-02-10 05:55 --------- d-----w C:\Program Files\Protector Suite QL
    2008-02-10 05:55 --------- d-----w C:\Program Files\Ozone
    2008-02-10 05:55 --------- d-----w C:\Program Files\MSXML 4.0
    2008-02-10 05:55 --------- d-----w C:\Program Files\MSN Messenger
    2008-02-10 05:55 --------- d-----w C:\Program Files\MP3 CD Converter
    2008-02-10 05:55 --------- d-----w C:\Program Files\Microsoft.NET
    2008-02-10 05:55 --------- d-----w C:\Program Files\Microsoft Works
    2008-02-10 05:55 --------- d-----w C:\Program Files\Microsoft ActiveSync
    2008-02-10 05:55 --------- d-----w C:\Program Files\Metamail Inc
    2008-02-10 05:55 --------- d-----w C:\Program Files\McAfee.com
    2008-02-10 05:55 --------- d-----w C:\Program Files\ltmoh
    2008-02-10 05:55 --------- d-----w C:\Program Files\Learn English
    2008-02-10 05:55 --------- d-----w C:\Program Files\Java
    2008-02-10 05:54 --------- d-----w C:\Program Files\InterVideo
    2008-02-10 05:54 --------- d-----w C:\Program Files\Intel
    2008-02-10 05:54 --------- d-----w C:\Program Files\illiminable
    2008-02-10 05:54 --------- d-----w C:\Program Files\Google
    2008-02-10 05:54 --------- d-----w C:\Program Files\easetech
    2008-02-10 05:54 --------- d-----w C:\Program Files\DVD-RAM
    2008-02-10 05:54 --------- d-----w C:\Program Files\Audio MP3 Converter
    2008-02-10 05:54 --------- d-----w C:\Program Files\America Online 9.0
    2008-01-22 14:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-22 14:10 --------- d-----w C:\Program Files\Common Files\InstallShield
    2007-11-19 14:41 90,112 ----a-w C:\WINDOWS\system32\ALOAudioFormatSettings3.dll
    2007-11-19 14:41 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
    2007-11-19 14:41 877,568 ----a-w C:\WINDOWS\system32\ALOAudioFile2.dll
    2007-11-19 14:41 780,288 ----a-w C:\WINDOWS\system32\ALOVideoCompress.dll
    2007-11-19 14:41 778,240 ----a-w C:\WINDOWS\system32\ALOAudioCompress2.dll
    2007-11-19 14:41 753,664 ----a-w C:\WINDOWS\system32\agsaamg.dll
    2007-11-19 14:41 626,688 ----a-w C:\WINDOWS\system32\agsaamh.dll
    2007-11-19 14:41 551,424 ----a-w C:\WINDOWS\system32\agsaame.dll
    2007-11-19 14:41 544,256 ----a-w C:\WINDOWS\system32\agsaamd.dll
    2007-11-19 14:41 538,624 ----a-w C:\WINDOWS\system32\agsaamb.dll
    2007-11-19 14:41 495,104 ----a-w C:\WINDOWS\system32\ALOVideoCoreM.dll
    2007-11-19 14:41 403,968 ----a-w C:\WINDOWS\system32\ALOWMAFile2.dll
    2007-11-19 14:41 382,464 ----a-w C:\WINDOWS\system32\ALOAVIFile.dll
    2007-11-19 14:41 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
    2007-11-19 14:41 331,776 ----a-w C:\WINDOWS\system32\agsaama.dll
    2007-11-19 14:41 249,856 ----a-w C:\WINDOWS\system32\ALOQuickTimeFile.dll
    2007-11-19 14:41 237,568 ----a-w C:\WINDOWS\system32\lame_enc.dll
    2007-11-19 14:41 215,552 ----a-w C:\WINDOWS\system32\ALOWMVFile.dll
    2007-11-19 14:41 2,846,720 ----a-w C:\WINDOWS\system32\ALOAudioCompress3.dll
    2007-11-19 14:41 2,846,720 ----a-w C:\WINDOWS\system32\agsaamj.dll
    2007-11-19 14:41 188,416 ----a-w C:\WINDOWS\system32\ALOVideoFile.dll
    2007-11-19 14:41 1,245,184 ----a-w C:\WINDOWS\system32\bkll.dll
    2004-02-23 08:00 1,386,496 --sh--r C:\WINDOWS\system32\msvbvm60.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
    "TOSCDSPD "= "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 00:32 65536]
    "msnmsgr "= "C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
    "swg "= "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-05 12:20 68856]
    "Tok-Cirrhatus-2025 "= "C:\Documents and Settings\mohamed\Local Settings\Application Data\br5073on.exe" [ ]
    "Yahoo! Pager "= "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MCUpdateExe "= "C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 11:05 212992]
    "MCAgentExe "= "c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 17:29 303104]
    "igfxtray "= "C:\WINDOWS\system32\igfxtray.exe" [2005-11-27 21:55 98304]
    "igfxhkcmd "= "C:\WINDOWS\system32\hkcmd.exe" [2005-11-27 21:52 77824]
    "igfxpers "= "C:\WINDOWS\system32\igfxpers.exe" [2005-11-27 21:55 118784]
    "TPSMain "= "TPSMain.exe" [2005-05-31 21:00 282624 C:\WINDOWS\system32\TPSMain.exe]
    "PSQLLauncher "= "C:\Program Files\Protector Suite QL\launcher.exe" [2006-05-05 16:36 30208]
    "ThpSrv "= "thpsrv /logon" []
    "THotkey "= "C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 14:02 352256]
    "SynTPLpr "= "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 16:34 82009]
    "SynTPEnh "= "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 16:32 761945]
    "LtMoh "= "C:\Program Files\ltmoh\Ltmoh.exe" [2004-08-18 03:37 184320]
    "AGRSMMSG "= "AGRSMMSG.exe" [2005-10-15 06:29 88203 C:\WINDOWS\agrsmmsg.exe]
    "NDSTray.exe "= "NDSTray.exe" []
    "TFncKy "= "TFncKy.exe" []
    "DockMsgFrom "= "C:\Program Files\Toshiba\Toshiba Applet\DockMsgFrom.exe" [ ]
    "PadTouch "= "C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [ ]
    "SmoothView "= "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 16:13 122880]
    "dla "= "C:\WINDOWS\system32\dla\DLACTRLW.exe" [2005-10-06 05:20 122940]
    "Pinger "= "c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 17:37 151552]
    "VSOCheckTask "= "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 17:18 151552]
    "TMESRV.EXE "= "C:\Program Files\TOSHIBA\TME3\TMESRV31.exe" [2005-01-18 14:18 126976]
    "TMERzCtl.EXE "= "C:\Program Files\TOSHIBA\TME3\TMERzCtl.exe" [2005-03-17 21:08 81920]
    "RTHDCPL "= "RTHDCPL.EXE" [2005-12-09 15:49 15691264 C:\WINDOWS\RTHDCPL.exe]
    "IntelZeroConfig "= "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 11:37 667718]
    "IntelWireless "= "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 10:41 602182]
    "VirusScan Online "= "C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49 163840]
    "RealTray "= "C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-12-06 14:24 26112]
    "OASClnt "= "C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 21:02 53248]
    "CFSServ.exe "= "CFSServ.exe" []

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Tok-Cirrhatus "=" " []

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Metamail Trust Manager.lnk - C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe [2006-06-12 17:29:22 329472]
    RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-12-05 19:10:57 155648]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
    "DisableCMD "= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{A93A4625-6216-499C-B360-BBD0A7C0D479} "= C:\Program Files\Common Files\Microsoft Shared\MSINFO\QQGS1.dll [2007-10-03 16:52 240747]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    psqlpwd.dll 2006-05-05 16:48 40448 C:\WINDOWS\system32\psqlpwd.dll

    R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\WINDOWS\system32\DRIVERS\thpdrv.sys [2004-12-27 22:31]
    R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\WINDOWS\system32\DRIVERS\Thpevm.SYS [2004-11-13 11:24]
    R0 TVALG;Toshiba Value Added Logical and General Purpose Device Driver;C:\WINDOWS\system32\DRIVERS\TVALG.SYS [2005-12-26 13:49]
    R1 TMEI3E;TMEI3E;C:\WINDOWS\system32\Drivers\TMEI3E.SYS [2004-06-16 11:08]
    R2 FdRedir;FdRedir;C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [2006-05-05 17:00]
    R2 FileDisk2;FileDisk Protector Kernel Driver;C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys [2006-05-05 16:59]
    R2 smihlp;SMI helper driver;C:\Program Files\Protector Suite QL\smihlp.sys [2006-05-05 16:33]
    R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-06-09 21:26]
    R3 ipw_mdfl;Wireless Broadband Modem Filter;C:\WINDOWS\system32\DRIVERS\ipw_mdfl.sys [2003-02-12 18:21]
    R3 ipw_mdm;Wireless Broadband Modem (WDM);C:\WINDOWS\system32\DRIVERS\ipw_mdm.sys [2003-02-12 18:21]
    R3 TcUsb;TC USB Kernel Driver;C:\WINDOWS\system32\Drivers\tcusb.sys [2006-05-05 16:43]
    S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-09-09 14:47]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
    \Shell\Auto\command - C:\setup.exe
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01409a22-35fd-11dc-91dd-00038a000015}]
    \Shell\Auto\command - F:\setup.exe
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3009eac-46b0-11dc-92be-00038a000015}]
    \Shell\Auto\command - F:\setup.exe
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac6b421a-4914-11dc-92e4-00038a000015}]
    \Shell\Auto\command - F:\setup.exe
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ade1cffc-6c77-11dc-944a-00038a000015}]
    \Shell\Auto\command - F:\setup.exe
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd6f8fb6-3123-11dc-91b3-00038a000015}]
    \Shell\Auto\command - G:\setup.exe
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4124604-6c5d-11dc-9447-00038a000015}]
    \Shell\Auto\command - F:\setup.exe
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

    .
    Contents of the 'Scheduled Tasks' folder
    "2008-02-09 17:29:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job "
    - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-02-09 21:59:21
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    C:\WINDOWS\system32\ThpSrv.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\system32\thpsrv.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\Protector Suite QL\psqltray.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\PROGRA~1\METAMA~1\METAMA~1\METAMA~2.EXE
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
    .
    **************************************************************************
    .
    Completion time: 2008-02-09 22:00:36 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-02-10 06:00:32
    .
    2008-02-09 18:27:46 --- E O F ---
     
  13. 2008/02/09
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Again..:)

    This is the HJT log file after running the Combo fix...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:05:19 PM, on 2/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\system32\DVDRAMSV.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    C:\WINDOWS\system32\ThpSrv.exe
    C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\TPSMain.exe
    C:\WINDOWS\system32\thpsrv.exe
    C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\Protector Suite QL\psqltray.exe
    C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
    C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\WINDOWS\system32\dla\DLACTRLW.exe
    C:\WINDOWS\system32\TPSBattM.exe
    C:\toshiba\ivp\ism\pinger.exe
    C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe
    C:\WINDOWS\system32\RAMASST.exe
    C:\PROGRA~1\METAMA~1\METAMA~1\METAMA~2.EXE
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\IPWireless Inc\IPWireless PC Software\UEStatus.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.toshibadirect.com/dpdstart
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
    O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
    O4 - HKLM\..\Run: [ThpSrv] thpsrv /logon
    O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
    O4 - HKLM\..\Run: [DockMsgFrom] C:\Program Files\Toshiba\Toshiba Applet\DockMsgFrom.exe
    O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
    O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [TMESRV.EXE] C:\Program Files\TOSHIBA\TME3\TMESRV31.EXE /Logon
    O4 - HKLM\..\Run: [TMERzCtl.EXE] C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE /Service
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe "
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Tok-Cirrhatus-2025] "C:\Documents and Settings\mohamed\Local Settings\Application Data\br5073on.exe "
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - HKUS\S-1-5-18\..\Run: [Tok-Cirrhatus] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Tok-Cirrhatus] (User 'Default user')
    O4 - Global Startup: Metamail Trust Manager.lnk = C:\Program Files\Metamail Inc\Metamail Tray\Metamail Trust Manager.exe
    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0C4C7CA9-5CB1-41D2-9E5A-35362D4CEFB4}: NameServer = 85.112.85.85 85.112.85.86
    O17 - HKLM\System\CCS\Services\Tcpip\..\{CB27FA68-A18C-45DE-AE89-F3CBBB9FE5CE}: NameServer = 192.168.1.1,192.168.1.5
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
    O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
    O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe
    O23 - Service: Tmesrv3 (Tmesrv) - TOSHIBA - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe

    --
    End of file - 11862 bytes
     
  14. 2008/02/09
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Dave,

    I have McAfee installed on the PC but my license is expired..so I thought of downloading AVG...
    Whenever the download starts (1%) the PC automatically shuts down and restart...is this related to some more virus I have on the laptop or what?

    If you want we tackle this issue later on..let's focus on the clean up for now??:) just wanted to mention it in case it helps in anything..:)
     
  15. 2008/02/09
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Brontok Again!!!

    Dave,

    I just noticed that everytime i open IE, there is a file (HTML Document) under the name about.Brontok.A that is placed in C:\Documents and Settings\mohamed\My Documents\My Pictures :mad: :mad:

    Maybe this explains why the PC is restarting when I am downloading the antivirus??
     
  16. 2008/02/10
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Dave,

    Since I suspect Brontok is still on the PC I have run a Kaspersky online scan (just in case it helps :) Attached is the log file.

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Sunday, February 10, 2008 11:52:45 PM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 10/02/2008
    Kaspersky Anti-Virus database records: 555943
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    C:\
    D:\

    Scan Statistics:
    Total number of scanned objects: 107406
    Number of viruses found: 14
    Number of infected objects: 4823
    Number of suspicious objects: 0
    Duration of the scan process: 00:52:54

    Infected Object Name / Virus Name / Last Action
    C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
    C:\Deckard\System Scanner\20080204063001\backup\DOCUME~1\mohamed\LOCALS~1\Temp\RN1A.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd001.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\mohamed\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\br5073on.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\csrss.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\inetinfo.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\lsass.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\services.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\smss.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\svchost.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Local Settings\Application Data\winlogon.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\History\History.IE5\MSHist012008021020080211\index.dat Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Temp\~DF8C12.tmp Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Temp\~DF963F.tmp Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Temp\~DFA168.tmp Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Temp\~DFE198.tmp Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
    C:\Documents and Settings\mohamed\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\mohamed\My Documents\My Received Files\My Received Files.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe\My Safe.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_133\My Safe.backup_133`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_21\My Safe.backup_21`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_262\My Safe.backup_262`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_27\My Safe.backup_27`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_285\My Safe.backup_285`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_286\My Safe.backup_286`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_290\My Safe.backup_290`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_329\My Safe.backup_329`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_336\My Safe.backup_336`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_353\My Safe.backup_353`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_36\My Safe.backup_36`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_364\My Safe.backup_364`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_399\My Safe.backup_399`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_409\My Safe.backup_409`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_431\My Safe.backup_431`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_432\My Safe.backup_432`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_458\My Safe.backup_458`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_459\My Safe.backup_459`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_460\My Safe.backup_460`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_461\My Safe.backup_461`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_462\My Safe.backup_462`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_464\My Safe.backup_464`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_465\My Safe.backup_465`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_466\My Safe.backup_466`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_468\My Safe.backup_468`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_469\My Safe.backup_469`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_470\My Safe.backup_470`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_471\My Safe.backup_471`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_472\My Safe.backup_472`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_473\My Safe.backup_473`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_476\My Safe.backup_476`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_477\My Safe.backup_477`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_479\My Safe.backup_479`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_480\My Safe.backup_480`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_481\My Safe.backup_481`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_483\My Safe.backup_483`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_484\My Safe.backup_484`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_485\My Safe.backup_485`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_486\My Safe.backup_486`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_487\My Safe.backup_487`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_490\My Safe.backup_490`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_493\My Safe.backup_493`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_497\My Safe.backup_497`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_498\My Safe.backup_498`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_508\My Safe.backup_508`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_511\My Safe.backup_511`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_512\My Safe.backup_512`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_513\My Safe.backup_513`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_517\My Safe.backup_517`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_517\My Safe.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_518\My Safe.backup_518`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_518\My Safe.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_519\My Safe.backup_519`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_519\My Safe.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_520\My Safe.backup_520`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_520\My Safe.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_521\My Safe.backup_521`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_521\My Safe.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_522\My Safe.backup_522`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_522\My Safe.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_91\My Safe.backup_91`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_92\My Safe.backup_92`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\My Documents\My Safe.backup_98\My Safe.backup_98`.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\mohamed\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\mohamed\Start Menu\Programs\Startup\Empty.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\mohamed\Templates\8328-NendangBro.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\America Online 9.0\MyCalendar\help\cal_help.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\America Online 9.0\MyCalendar.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\America Online 9.0\pp.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Common Files\Microsoft Shared\MSInfo\QQGS1.dll Infected: Trojan-PSW.Win32.QQPass.zu skipped
    C:\Program Files\InterVideo\WinDVD\Html\Default\InterVideo.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\InterVideo\WinDVD\Html\Default\WinDVD.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\InterVideo\WinDVD\Html\ENU\InterVideo.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\InterVideo\WinDVD\Html\ENU\WinDVD.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\IPWireless Inc\IPWireless PC Software\Documents\Version.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\IPWireless Inc\IPWireless PC Software\FindExe.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Learn English\Effects\Help\LearnE2A.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Learn English\Games\game.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Learn English\Internet\1article.html Infected: Worm.Win32.Fujack.al skipped
     
  17. 2008/02/10
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    C:\Program Files\Metamail Inc\Metamail Tray\MetamailTrayAbout.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\CLRCHK.JSP Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\FONTLIST.JSP Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\OFREADME.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\OLREADME.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\ONREADME.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\ONTOUR.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\ONTOURNF.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\ONTOURST.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\PBREADME.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\PPREADME.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\PVREADME.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\WDREADME.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\1033\XLREADME.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Microsoft Office\OFFICE11\INTLBAND.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Ozone\Audio Converter\help\help.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\QuickTime\QuickTime Read Me.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Real\RealPlayer\playrlic.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Real\RealPlayer\Readme.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Bad_Read_Source.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\BufferUnderrun.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\copy_err.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Drives_In_Use.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Files.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\music_scan.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Recording.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Space_Disc.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Space_HDD.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Testing_Disc.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Unknown_Error.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Explain\Verify.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\readme.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\1.0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.3.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\2.5.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.3.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\3.5.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\4.0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\4.1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\4.2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\5.0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\5.1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\5.1a.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\5.2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\6.0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\6.1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\6.2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\7.0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.3.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.4.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\Adv.5.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\glossary.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\Tutorial\ENU\index.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Sonic\RecordNow!\upgrade.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\cfloghis.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\cflogtmp.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\cf1_0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\cf1_1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\cf1_2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\cf1_3.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\header.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\menu.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\top.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF1\top2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_3.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_4.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_5.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_6.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF2\cf2_7.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_0.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_1.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_10.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_11.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_13.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_17.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_2.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_3.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_4.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_5.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_6.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_7.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_8.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\CF3\cf3_9.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\ConfigFree\FUG\index.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\MyConnect Special Offer\specialoffer.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\kihon_bottom.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\kihon_header.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\kihon_index.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\kihon_left.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\kihon_main.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\kihon_right.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\shindan_bottom.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\shindan_header.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\shindan_index.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\shindan_left.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\shindan_main.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\PCDiag\shindan_right.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\TOSHIBA\Windows Utilities\SVPWTool\README.HTM Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-au\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-au\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-ca\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-ca\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-gb\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-gb\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-id\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-id\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-ie\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-ie\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-in\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-in\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-my\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-my\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-nz\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-nz\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-ph\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-ph\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-sg\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-sg\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-us\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-us\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-ww\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-ww\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-za\noext.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Windows Live Toolbar\en-za\offline.htm Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_atb.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_catb.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_cnf.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_cotb.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_ctb.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_fantip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_fantipg.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_fintip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_fintipg.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_grptip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_grptipg.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_logtip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_mailatip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_mailtip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_map.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_mlbtip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_mlbtipg.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_msgratip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_msgrtip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_nbatip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_nbatipg.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_newstip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_newstipg.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_nfltip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_nfltipg.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_opt.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_pub.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_srchtip.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_upg.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Companion\Data\dlg_wp.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\cd.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\default.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\devices.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\home.html Infected: Worm.Win32.Fujack.al skipped
    C:\Program Files\Yahoo!\Yahoo! Music Engine\offline\networkmusic.html Infected: Worm.Win32.Fujack.al skipped
    C:\QooBox\Quarantine\C\Program Files\Internet Explorer\IEXPLORE32.Sys.vir Infected: Trojan-Spy.Win32.Delf.azt skipped
    C:\QooBox\Quarantine\C\setup.exe.vir Infected: Worm.Win32.Fujack.l skipped
    C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\spoclsv.exe.vir Infected: Worm.Win32.Fujack.l skipped
    C:\QooBox\Quarantine\E\setup.exe.vir Infected: Worm.Win32.Fujack.l skipped
    C:\setup_exe.vir Infected: Worm.Win32.Fujack.l skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152568.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152569.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152570.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152571.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152572.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152573.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152574.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152575.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152576.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152577.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152578.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152579.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152580.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152588.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152589.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152590.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152591.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152592.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152593.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152594.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152595.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152596.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152597.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152598.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152599.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152600.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152601.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152614.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152615.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152616.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152617.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152618.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152619.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152620.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152621.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152622.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152623.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152624.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152625.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152626.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP160\A0152629.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0152984.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0152986.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0152987.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0152989.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0152990.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0152992.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0152994.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0152995.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153734.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153735.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153736.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153737.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153738.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153739.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153740.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153741.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153742.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153746.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153749.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153751.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153754.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153786.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153787.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153788.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153789.exe Infected: Email-Worm.Win32.Brontok.q skipped
     
  18. 2008/02/10
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153790.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153791.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153792.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153793.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153794.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153795.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153796.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153797.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP161\A0153798.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154891.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154892.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154893.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154894.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154895.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154896.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154897.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154898.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154899.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154900.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154919.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154920.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154925.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0154927.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0155997.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0155999.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156000.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156001.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156002.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156003.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156004.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156005.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156006.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156007.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156008.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156009.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156010.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156011.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0156014.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157087.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157088.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157089.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157090.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157091.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157092.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157093.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157094.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157095.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157096.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157097.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157098.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157099.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157101.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157102.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157141.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157142.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157143.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157144.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157145.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157146.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157147.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157148.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157149.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157150.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157151.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157152.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157153.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157154.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0157155.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158194.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158195.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158196.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158197.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158198.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158199.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158200.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158201.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158202.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158203.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158204.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158205.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158206.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158207.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158208.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158216.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158217.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158218.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158219.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158220.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158221.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158222.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158223.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158224.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158225.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158226.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158227.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158228.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158229.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0158230.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159325.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159326.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159327.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159328.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159329.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159330.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159331.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159332.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159333.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159334.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159335.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159336.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159337.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159339.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0159340.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160416.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160417.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160418.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160419.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160420.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160421.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160422.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160423.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160424.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160425.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160426.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160428.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160430.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0160435.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161101.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161102.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161103.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161104.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161105.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161106.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161107.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161108.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161109.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161110.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161111.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161112.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161113.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161114.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161117.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161127.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161128.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161129.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161130.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161131.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161132.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161133.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161134.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161135.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161136.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161137.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161138.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161139.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161140.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161141.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161149.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161150.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161151.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161152.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161153.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161154.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161155.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161156.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161157.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161158.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161159.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161160.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161161.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161162.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161163.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161580.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161581.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161582.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161583.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161584.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161585.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161586.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161587.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161588.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161589.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161590.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161591.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161592.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161593.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161594.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161602.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161603.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161604.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161605.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161606.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161607.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161608.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161609.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161610.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161611.exe Infected: Email-Worm.Win32.Brontok.q skipped
     
  19. 2008/02/10
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161612.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161613.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161614.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161615.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161616.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161624.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161625.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161626.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161627.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161628.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161629.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161630.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161631.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161632.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161633.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161634.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161635.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161636.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161637.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161638.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161645.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161647.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161648.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161649.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161650.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161651.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161652.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161653.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161654.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161655.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161656.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161657.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161658.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161659.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161660.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161668.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161669.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161670.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161671.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161672.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161673.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161674.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161675.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161676.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161677.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161678.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161679.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161680.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161681.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161682.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161690.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161691.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161692.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161693.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161694.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161695.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161696.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161697.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161698.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161699.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161700.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161701.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161702.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161703.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161704.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161712.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161713.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161714.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161715.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161716.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161717.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161718.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161719.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161720.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161721.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161722.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161723.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161724.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161725.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161726.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161734.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161735.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161736.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161737.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161738.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161739.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161740.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161741.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161742.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161743.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161744.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161745.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161746.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161747.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161748.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161756.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161757.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161758.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161759.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161760.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161761.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161762.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161763.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161764.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161765.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161766.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161767.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161768.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161769.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161770.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161778.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161779.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161780.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161781.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161782.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161783.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161784.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161785.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161786.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161787.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161788.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161789.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161790.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161791.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161792.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161800.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161801.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161802.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161803.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161804.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161805.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161806.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161807.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161808.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161809.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161810.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161811.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161812.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161813.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161814.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161822.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161823.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161824.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161825.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161826.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161827.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161828.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161829.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161830.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161831.exe Infected: Email-Worm.Win32.Brontok.q skipped
     
  20. 2008/02/10
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161832.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161833.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161834.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161835.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161836.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161844.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161845.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161846.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161847.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161848.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161849.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161850.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161851.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161852.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161853.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161854.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161855.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161856.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161857.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0161858.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162027.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162029.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162030.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162031.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162032.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162033.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162034.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162035.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162036.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162037.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162038.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162039.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162040.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162041.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162042.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162049.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162051.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162052.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162053.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162054.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162055.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162056.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162057.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162058.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162059.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162060.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162061.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162062.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162063.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162064.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162071.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162073.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162074.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162075.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162076.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162077.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162078.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162079.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162080.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162081.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162082.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162083.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162084.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162085.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162086.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162093.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162095.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162096.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162097.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162098.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162099.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162100.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162101.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162102.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162103.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162104.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162105.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162106.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162107.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162108.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162115.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162117.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162118.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162119.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162120.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162121.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162122.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162123.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162124.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162125.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162126.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162127.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162128.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162129.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162130.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162137.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162139.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162140.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162141.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162142.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162143.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162144.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162145.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162146.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162147.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162148.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162149.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162150.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162151.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162152.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162159.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162161.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162162.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162163.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162164.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162165.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162166.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162167.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162168.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162169.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162170.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162171.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162172.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162173.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162174.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162181.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162182.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162184.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162185.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162186.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162187.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162188.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162189.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162190.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162191.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162192.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162193.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162194.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162195.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162196.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162203.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162205.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162206.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162207.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162208.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162209.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162210.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162211.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162212.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162213.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162214.exe Infected: Email-Worm.Win32.Brontok.q skipped
     
  21. 2008/02/10
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162215.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162216.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162217.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162218.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162225.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162227.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162228.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162229.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162230.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162231.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162232.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162233.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162234.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162235.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162236.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162237.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162238.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162239.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162240.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162247.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162248.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162250.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162251.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162252.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162253.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162254.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162255.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162256.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162257.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162258.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162259.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162260.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162261.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162262.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162269.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162271.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162272.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162273.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162274.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162275.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162276.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162277.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162278.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162279.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162280.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162281.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162282.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162283.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162284.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162291.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162293.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162294.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162295.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162296.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162297.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162298.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162299.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162300.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162301.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162302.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162303.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162304.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162305.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162306.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162312.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162314.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162315.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162316.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162317.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162318.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162319.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162320.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162321.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162322.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162323.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162324.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162325.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162326.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162327.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162334.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162336.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162337.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162338.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162339.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162340.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162341.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162342.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162343.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162344.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162345.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162346.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162347.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162348.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162349.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162356.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162358.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162359.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162360.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162361.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162362.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162363.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162364.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162365.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162366.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162367.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162368.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162369.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162370.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162371.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162378.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162380.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162381.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162382.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162383.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162384.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162385.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162386.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162387.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162388.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162389.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162390.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162391.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162392.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162393.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162400.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162402.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162403.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162404.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162405.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162406.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162407.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162408.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162409.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162410.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162411.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162412.pif Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162413.com Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162414.scr Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162415.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162422.Sys Infected: Trojan-PSW.Win32.QQPass.afp skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162423.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162425.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162426.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162427.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162428.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162429.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162430.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162431.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162432.exe Infected: Email-Worm.Win32.Brontok.q skipped
    C:\System Volume Information\_restore{3A3C753E-374F-4D63-88D5-9555F76A7918}\RP162\A0162433.exe Infected: Email-Worm.Win32.Brontok.q skipped
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.