Aller au contenu

crissou

Membres
  • Compteur de contenus

    43
  • Inscription

  • Dernière visite

Tout ce qui a été posté par crissou

  1. crissou

    PC bloqué - message STOP

    yououhh... mon problème n'interesse personne ?
  2. Voilà tout est fait, merci et bonne continuation.
  3. Bonjour, voilà donc le rapport de kaspersky : Scan ---- Scanned: 442836 Detected: 131 Untreated: 0 Start time: 03/01/2009 18:22:45 Duration: 15:52:32 Finish time: 04/01/2009 10:15:17 Detected -------- Status Object ------ ------ deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\winupgro.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Bagle.afl File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\_srosa_.sys.zip/srosa.sys deleted: virus Email-Worm.Win32.Bagle.majc File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\386875.exe.vir deleted: virus Email-Worm.Win32.Bagle.majc File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\903578.exe.vir deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\data.oct.vir deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\(Serial).Symantec.Livestate.Recovery.6.0.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\32bit Email Broadcaster 08.11.17.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\A123 AVI MPEG WMV ASF MOV FLV to Zune Converter 4.0.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ace DVD Backup 1.3.32.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AdvaSaR Ed 5.04.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Aimersoft DVD to 3GP Converter 1.1.62.zip.vir/key_gen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ali Landry 33 Screensaver 1.0.zip.vir/serial.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ASP.NET Image Gallery 1.1.zip.vir/key_gen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ATnotes 9.5.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AudioManage 2.10.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AutoQ2 1.0.9.9r3.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AVAST.4.6.PRO+KEY+TESTED.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Azureus Turbo Accelerator 2.7.0.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Babysitter Services Finder 1.0.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Be Mine Screensaver 2.0.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Beach Cams PT 0.2.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Biometric HP Manager Enterprise 6.12.44.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Bitdefender Free Antivir Software.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Blade Runner Font 1.0.zip.vir/serial.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CadLib 3.5.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CCNA FlashCards 1.0.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Citrix 1Y0-991 Practice Exam Test Questions.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Claymore Time Sheets 2005 1.0.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CodeWorker 4.5.1.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Convert Image 1.96.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CryptaFlix 1.11.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DDObjects 0.9.95.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DeepForm 1.1.1.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Desktop Fay 2.8.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DiskSurvey 1.0.5.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Domeru DVD to iPod Converter 3.6.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Don's Alarm Clock 1.1.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Drag to MP3 1.0.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Dragonfly Attack Screensaver.zip.vir/serial.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Duplicate DLL File Finder Software 7.0.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\e!Sankey 1.3.0.324.zip.vir/key_gen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Easy Peasy Passwords 2.3.1.17.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Elecard Codec .NET SDK G4 1.1.80717.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\entOnly.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EVE Online Images Widget 1.1.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Event Engineer 1.0.zip.vir/key_gen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Execute This! 1.3.0.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EZ Contract Proposal 2.3.0.zip.vir/key_gen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FeedStation 2.0 beta2.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Filo 2.0.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FireCode 2004 1.00.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\First Radio 89.1FM Israel 3.0.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Flawless Makeup Tips 3.0.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\foo vis flame 0.93.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Geforce Tweak Utility 3.2.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GEODisk 3.3.4.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GoodOK MP4 Converter 5.3.zip.vir/key_gen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Guitar Ensemble 1.0.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GZ Calendar 1.0.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Hilary Duff Screensaver1.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HMView 4.04.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HoursClocked-Basic 001-004-002.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML to Flash Password 1.0.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML-Handler for Eudora 3.1.zip.vir/serial.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTPT Console 2.06.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Icesun Audio Converter 2.00.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Image++ 2.1.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Indian HoroScope 1.0.0.0.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iRep 2.5.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iTunes Alarm Clock 2.0.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAMDAT.Mobile.Tetris.Marathon.v1.8.16.S60.J2ME.Retail-daddyfatsax.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAME 6.0.1.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Jvw filter email 1.0.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ka Log Analyzer 1.65.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\KingConvert For SamSung E768 4.0.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\LDAPsearcher 1.1.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Lomsel Shutdown 1.04.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\M3U Creator 1.0.1.4.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Mini Log Book 1.0.zip.vir/serial.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\mnoGoSearch for Windows Pro Oracle Edition Pro 3.2.40.1.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MoonSked 1.4.7.zip.vir/serial.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\My Auction Search Browser for eBay 2.2.0.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MyPhone Book Dialer 8.1.0.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\News Talk ZB 1.0.0.0.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Nod32_v2+manual+plugin+(crack_de_por_vida)(español-spanish)por_borracho.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Norton AntiVirus and Internet Security LiveSubscribe Crack (Extends Subscription to 8-20-2116).zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Offline Explorer Pro 5.2.2878 Service Release 1.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Omega Constellation Screen Saver.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PaintFX 1.01.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Pamela for Skype Professional Version 1.36.zip.vir/serial.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PauseProcess 1.0.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PDF Password Remover 3.0.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Picture Spyglass Rev 4.0.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PlotLab .NET 3.1.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PopupAlert 2.02.0086.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PrintController 2.0.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Profile Picture Genius 1.0.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Quick Install Maker 2.0.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\R Color Code 1.0.zip.vir/install_crack.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RandBack32 1.00.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Real-Time Rendering.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Registry Workshop 4.0.1.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RRS plugin for LCDC 1.4a.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SC DVD Ripper 1.0.0.0.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Serial Port Splitter 3.8.2.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SfbEmailVerifier 1.3.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Shell-and-Tube Heat Exchanger 1.1.0.0.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Site Coder 2.zip.vir/key_gen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Skater .NET Obfuscator Freeware Light 2.60.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SlovoEd Classic English-German 6.4.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SmarterMail Free Edition 5.5.3126.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SQL Help Builder 2.03.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Stereoscope Theatre Love & Romance 1.0.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SVG Link Agent 1.3.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Symantec.Antivirus.Corporate.Server.Edition.v8.1.0.825.Retail-SHOCK.ShareConnector.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\System Information 1.0.zip.vir/install.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Talking Alphabet 2.0.2.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ThumbPlus ActiveX Control 5.0.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Tomtom Navigator 6V Para Pocket Pc Nokia 6280.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Trackless 1.03.zip.vir/crac.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\TVants 1.0.0.59 Build 0834.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Project Manager Enterprise 1.1.zip.vir/key_gen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Video Converter 6.0.2.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vextractor 4.20.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vox Box 1.zip.vir/keygen.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WallMan 1.0.zip.vir/setup.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WinComm 2.03.zip.vir/install_patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Wine Organizer 3.6a.zip.vir/patch.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WTY-DTT 0.9.5 Beta.zip.vir/key_generator.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Zipsize 0.2.2.zip.vir/run.exe deleted: Trojan program Trojan-Downloader.Win32.Bagle.ajn File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\[APP-ITA].Ewido.Security.Suite.v3.5.Plus.zip.vir/run.exe Events ------ Time Name Status Reason ---- ---- ------ ------ 03/01/2009 18:42:22 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AcroPro80_efg.exe password protected 03/01/2009 18:42:23 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\FlashGet.EXE password protected 03/01/2009 18:42:23 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\flashget181en.exe password protected 03/01/2009 18:42:23 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\GUIDE.txt password protected 03/01/2009 18:42:23 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\KeyGen.exe password protected 03/01/2009 18:42:23 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\More Quality Full Downloads! Warez_Listings Index.url password protected 03/01/2009 18:42:23 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\plz read.txt password protected 03/01/2009 18:42:25 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AcroPro80_efg.exe password protected 03/01/2009 18:42:25 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\FlashGet.EXE password protected 03/01/2009 18:42:25 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\flashget181en.exe password protected 03/01/2009 18:42:25 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\GUIDE.txt password protected 03/01/2009 18:42:25 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\KeyGen.exe password protected 03/01/2009 18:42:25 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\More Quality Full Downloads! Warez_Listings Index.url password protected 03/01/2009 18:42:25 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\plz read.txt password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/Ad-Aware SE Default.skn password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/arrow1.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/arrow2.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bck1.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt11.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt12.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt13.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt21.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt22.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt23.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt31.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt32.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt33.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt41.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt42.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt43.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt51.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt52.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt53.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt61.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt62.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox1.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox2.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox3.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox4.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn1.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn2.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn3.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph1.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph2.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph3.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph4.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph5.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph6.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph7.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/main.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/preview.bmp password protected 03/01/2009 18:48:19 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/sprite1.bmp password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader1.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader1.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader10.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader10.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader11.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader11.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader12.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader12.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader13.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader13.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader14.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader14.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader15.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader15.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader16.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader16.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader17.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader17.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader18.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader18.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader19.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader19.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader2.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader2.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader20.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader20.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader21.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader21.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader22.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader22.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader23.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader23.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader24.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader24.zip/sbRecovery.ini password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader25.zip/sbRecovery.reg password protected 03/01/2009 19:21:50 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader25.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader26.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader26.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader27.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader27.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader28.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader28.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader29.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader29.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader3.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader3.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader30.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader30.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader31.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader31.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader4.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader4.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader5.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader5.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader6.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader6.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader7.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader7.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader8.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader8.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader9.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader9.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs2.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs2.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs3.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs3.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs4.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs4.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer10.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer10.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer11.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer11.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer12.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer12.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer13.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer13.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer14.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer14.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer15.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer15.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer16.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer16.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer17.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer17.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer18.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer18.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer19.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer19.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer20.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer20.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer21.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer21.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer22.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer22.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer23.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer23.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip/sbRecovery.ini password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip/sbRecovery.reg password protected 03/01/2009 19:21:51 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer5.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer5.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer6.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer6.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer7.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer7.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer8.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer8.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer9.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer9.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD1.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD1.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD2.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD2.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD3.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD3.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD4.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD4.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD5.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD5.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw1.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw1.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw2.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw2.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw3.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw3.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw4.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw4.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole1.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole1.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole2.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole2.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole3.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole3.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip/wmplibrary_v_0_12.db password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer10.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer10.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer11.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer11.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer12.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer12.zip/sbRecovery.ini password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer13.zip/sbRecovery.reg password protected 03/01/2009 19:21:52 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer13.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer14.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer14.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer15.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer15.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer16.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer16.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer17.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer17.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer18.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer18.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer19.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer19.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip/wmplibrary_v_0_12.db password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer4.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer4.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer5.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer5.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer6.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer6.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer7.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer7.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer8.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer8.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer9.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer9.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice1.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice1.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice2.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice2.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel1.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel1.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel2.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel2.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel3.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel3.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficePowerPoint.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficePowerPoint.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficePowerPoint1.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficePowerPoint1.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord1.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord1.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord2.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord2.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord3.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord3.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSPaint.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSPaint.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant1.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant1.zip/sbRecovery.ini password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant2.zip/sbRecovery.reg password protected 03/01/2009 19:21:53 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant2.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant3.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant3.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSWordpad.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSWordpad.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer1.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer1.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer2.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer2.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer3.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer3.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer4.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer4.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer5.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer5.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer6.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer6.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer7.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer7.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer8.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer8.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer9.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer9.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBaglehi.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBaglehi.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer11.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer11.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer12.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer12.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer13.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer13.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer14.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer14.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer16.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer16.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer17.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer17.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer18.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer18.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer19.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer19.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer20.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer20.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer21.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer21.zip/sbRecovery.ini password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip/sbRecovery.reg password protected 03/01/2009 19:21:54 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer23.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer23.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer24.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer24.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer25.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer25.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer26.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer26.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer27.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer27.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer28.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer28.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer29.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer29.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer30.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer30.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer31.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer31.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer32.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer32.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer33.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer33.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer34.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer34.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer35.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer35.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer36.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer36.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer37.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer37.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK1.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK1.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK10.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK10.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK11.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK11.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK12.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK12.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK13.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK13.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK14.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK14.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK15.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK15.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK16.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK16.zip/sbRecovery.ini password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK17.zip/sbRecovery.reg password protected 03/01/2009 19:21:55 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK17.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK18.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK18.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK19.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK19.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK2.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK2.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK20.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK20.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK21.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK21.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK22.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK22.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK23.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK23.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK24.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK24.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK25.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK25.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK26.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK26.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK3.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK3.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK4.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK4.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK5.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK5.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK6.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK6.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK7.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK7.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK8.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK8.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK9.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK9.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith1.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith1.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith2.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith2.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith3.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith3.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith4.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith4.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith5.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith5.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith6.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith6.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR1.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR1.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR2.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR2.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR3.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR3.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR4.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR4.zip/sbRecovery.ini password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR5.zip/sbRecovery.reg password protected 03/01/2009 19:21:56 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR5.zip/sbRecovery.ini password protected 03/01/2009 19:49:30 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AcroPro80_efg.exe password protected 03/01/2009 19:49:30 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\FlashGet.EXE password protected 03/01/2009 19:49:30 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\flashget181en.exe password protected 03/01/2009 19:49:30 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\GUIDE.txt password protected 03/01/2009 19:49:30 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\KeyGen.exe password protected 03/01/2009 19:49:30 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\More Quality Full Downloads! Warez_Listings Index.url password protected 03/01/2009 19:49:30 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\plz read.txt password protected 03/01/2009 19:49:31 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AcroPro80_efg.exe password protected 03/01/2009 19:49:31 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\FlashGet.EXE password protected 03/01/2009 19:49:31 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\flashget181en.exe password protected 03/01/2009 19:49:31 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\GUIDE.txt password protected 03/01/2009 19:49:31 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\KeyGen.exe password protected 03/01/2009 19:49:31 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\More Quality Full Downloads! Warez_Listings Index.url password protected 03/01/2009 19:49:31 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\plz read.txt password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/Ad-Aware SE Default.skn password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/arrow1.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/arrow2.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bck1.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt11.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt12.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt13.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt21.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt22.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt23.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt31.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt32.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt33.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt41.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt42.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt43.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt51.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt52.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt53.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt61.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt62.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox1.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox2.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox3.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox4.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn1.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn2.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn3.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph1.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph2.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph3.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph4.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph5.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph6.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph7.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/main.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/preview.bmp password protected 03/01/2009 19:55:26 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/sprite1.bmp password protected 03/01/2009 20:07:48 File: C:\DRIVERS\OTHER.EXE//LzExe/BIOSLOCK.PIF password protected 03/01/2009 20:07:48 File: C:\DRIVERS\OTHER.EXE//LzExe/BIOSLOCK.EXE password protected 03/01/2009 20:08:09 File: C:\DRIVERS\MCDBF\SOURCE1\OTHER.EXE//LzExe/BIOSLOCK.PIF password protected 03/01/2009 20:08:09 File: C:\DRIVERS\MCDBF\SOURCE1\OTHER.EXE//LzExe/BIOSLOCK.EXE password protected 03/01/2009 20:08:12 File: C:\DRIVERS\MCDBF\SOURCE1\TSADDON.EXE//LzExe/UNISHHS.ARJ/UPDTAT.BAT password protected 03/01/2009 21:01:17 File: C:\Program Files\eMule\Temp\002.part/ Kid - Ecole CM2 Maths 2007 - [ Full ].zip password protected 03/01/2009 21:01:17 File: C:\Program Files\eMule\Temp\002.part/ Kid - Ecole CM2 Maths 2007 - [ Full ].zip password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___.obj password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___S01A01.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___SxxIco.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___SxxIdt.txt password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___SxxInf.rtf password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___SxxZon.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___.obj password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___S01A01.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___SxxIco.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___SxxIdt.txt password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___SxxInf.rtf password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___SxxZon.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___.obj password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___S01A01.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___SxxIco.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___SxxIdt.txt password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___SxxInf.rtf password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___SxxZon.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___.obj password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___S01A01.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___SxxIco.smk password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___SxxIdt.txt password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___SxxInf.rtf password protected 03/01/2009 21:19:54 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___SxxZon.smk password protected 03/01/2009 22:04:53 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\winupgro.exe.vir detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:04:53 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\winupgro.exe.vir not disinfected postponed 03/01/2009 22:04:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\_srosa_.sys.zip/srosa.sys detected Trojan program 'Trojan-Downloader.Win32.Bagle.afl' 03/01/2009 22:04:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\_srosa_.sys.zip/srosa.sys not disinfected postponed 03/01/2009 22:05:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\386875.exe.vir detected virus 'Email-Worm.Win32.Bagle.majc' 03/01/2009 22:05:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\386875.exe.vir not disinfected postponed 03/01/2009 22:05:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\903578.exe.vir detected virus 'Email-Worm.Win32.Bagle.majc' 03/01/2009 22:05:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\903578.exe.vir not disinfected postponed 03/01/2009 22:05:06 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\data.oct.vir detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:06 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\data.oct.vir not disinfected postponed 03/01/2009 22:05:06 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\(Serial).Symantec.Livestate.Recovery.6.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:06 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\(Serial).Symantec.Livestate.Recovery.6.0.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:05:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\32bit Email Broadcaster 08.11.17.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\32bit Email Broadcaster 08.11.17.zip.vir/install.exe not disinfected postponed 03/01/2009 22:05:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\A123 AVI MPEG WMV ASF MOV FLV to Zune Converter 4.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\A123 AVI MPEG WMV ASF MOV FLV to Zune Converter 4.0.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:05:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ace DVD Backup 1.3.32.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ace DVD Backup 1.3.32.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:05:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AdvaSaR Ed 5.04.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AdvaSaR Ed 5.04.zip.vir/run.exe not disinfected postponed 03/01/2009 22:05:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Aimersoft DVD to 3GP Converter 1.1.62.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Aimersoft DVD to 3GP Converter 1.1.62.zip.vir/key_gen.exe not disinfected postponed 03/01/2009 22:05:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ali Landry 33 Screensaver 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ali Landry 33 Screensaver 1.0.zip.vir/serial.exe not disinfected postponed 03/01/2009 22:05:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ASP.NET Image Gallery 1.1.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ASP.NET Image Gallery 1.1.zip.vir/key_gen.exe not disinfected postponed 03/01/2009 22:05:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ATnotes 9.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ATnotes 9.5.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:05:30 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AudioManage 2.10.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:30 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AudioManage 2.10.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:05:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AutoQ2 1.0.9.9r3.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AutoQ2 1.0.9.9r3.zip.vir/run.exe not disinfected postponed 03/01/2009 22:05:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AVAST.4.6.PRO+KEY+TESTED.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AVAST.4.6.PRO+KEY+TESTED.zip.vir/run.exe not disinfected postponed 03/01/2009 22:05:38 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Azureus Turbo Accelerator 2.7.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:38 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Azureus Turbo Accelerator 2.7.0.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:05:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Babysitter Services Finder 1.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Babysitter Services Finder 1.0.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:05:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Be Mine Screensaver 2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Be Mine Screensaver 2.0.zip.vir/install.exe not disinfected postponed 03/01/2009 22:05:42 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Beach Cams PT 0.2.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:42 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Beach Cams PT 0.2.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:05:45 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Biometric HP Manager Enterprise 6.12.44.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:45 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Biometric HP Manager Enterprise 6.12.44.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:05:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Bitdefender Free Antivir Software.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Bitdefender Free Antivir Software.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:05:49 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Blade Runner Font 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:49 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Blade Runner Font 1.0.zip.vir/serial.exe not disinfected postponed 03/01/2009 22:05:51 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CadLib 3.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:51 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CadLib 3.5.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:05:53 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CCNA FlashCards 1.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:53 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CCNA FlashCards 1.0.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:05:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Citrix 1Y0-991 Practice Exam Test Questions.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Citrix 1Y0-991 Practice Exam Test Questions.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:05:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Claymore Time Sheets 2005 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Claymore Time Sheets 2005 1.0.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:05:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CodeWorker 4.5.1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:05:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CodeWorker 4.5.1.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:06:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Convert Image 1.96.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Convert Image 1.96.zip.vir/run.exe not disinfected postponed 03/01/2009 22:06:04 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CryptaFlix 1.11.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:04 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CryptaFlix 1.11.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:06:07 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DDObjects 0.9.95.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:07 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DDObjects 0.9.95.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:06:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DeepForm 1.1.1.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DeepForm 1.1.1.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:06:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Desktop Fay 2.8.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Desktop Fay 2.8.zip.vir/install.exe not disinfected postponed 03/01/2009 22:06:12 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DiskSurvey 1.0.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:12 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DiskSurvey 1.0.5.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:06:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Domeru DVD to iPod Converter 3.6.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Domeru DVD to iPod Converter 3.6.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:06:16 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Don's Alarm Clock 1.1.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:16 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Don's Alarm Clock 1.1.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:06:18 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Drag to MP3 1.0.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:18 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Drag to MP3 1.0.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:06:20 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Dragonfly Attack Screensaver.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:20 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Dragonfly Attack Screensaver.zip.vir/serial.exe not disinfected postponed 03/01/2009 22:06:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Duplicate DLL File Finder Software 7.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Duplicate DLL File Finder Software 7.0.zip.vir/install.exe not disinfected postponed 03/01/2009 22:06:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\e!Sankey 1.3.0.324.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\e!Sankey 1.3.0.324.zip.vir/key_gen.exe not disinfected postponed 03/01/2009 22:06:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Easy Peasy Passwords 2.3.1.17.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Easy Peasy Passwords 2.3.1.17.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:06:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Elecard Codec .NET SDK G4 1.1.80717.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Elecard Codec .NET SDK G4 1.1.80717.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:06:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\entOnly.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\entOnly.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:06:31 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EVE Online Images Widget 1.1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:31 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EVE Online Images Widget 1.1.zip.vir/install.exe not disinfected postponed 03/01/2009 22:06:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Event Engineer 1.0.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Event Engineer 1.0.zip.vir/key_gen.exe not disinfected postponed 03/01/2009 22:06:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Execute This! 1.3.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Execute This! 1.3.0.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:06:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EZ Contract Proposal 2.3.0.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EZ Contract Proposal 2.3.0.zip.vir/key_gen.exe not disinfected postponed 03/01/2009 22:06:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FeedStation 2.0 beta2.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FeedStation 2.0 beta2.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:06:38 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Filo 2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:38 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Filo 2.0.zip.vir/install.exe not disinfected postponed 03/01/2009 22:06:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FireCode 2004 1.00.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FireCode 2004 1.00.zip.vir/install.exe not disinfected postponed 03/01/2009 22:06:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\First Radio 89.1FM Israel 3.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\First Radio 89.1FM Israel 3.0.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:06:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Flawless Makeup Tips 3.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Flawless Makeup Tips 3.0.zip.vir/run.exe not disinfected postponed 03/01/2009 22:06:43 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\foo vis flame 0.93.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:43 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\foo vis flame 0.93.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:06:44 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Geforce Tweak Utility 3.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:44 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Geforce Tweak Utility 3.2.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:06:45 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GEODisk 3.3.4.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:45 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GEODisk 3.3.4.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:06:48 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GoodOK MP4 Converter 5.3.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:48 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GoodOK MP4 Converter 5.3.zip.vir/key_gen.exe not disinfected postponed 03/01/2009 22:06:49 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Guitar Ensemble 1.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:49 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Guitar Ensemble 1.0.zip.vir/run.exe not disinfected postponed 03/01/2009 22:06:50 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GZ Calendar 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:50 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GZ Calendar 1.0.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:06:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Hilary Duff Screensaver1.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Hilary Duff Screensaver1.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:06:54 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HMView 4.04.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:54 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HMView 4.04.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:06:56 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HoursClocked-Basic 001-004-002.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:56 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HoursClocked-Basic 001-004-002.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:06:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML to Flash Password 1.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:06:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML to Flash Password 1.0.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:07:01 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML-Handler for Eudora 3.1.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:01 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML-Handler for Eudora 3.1.zip.vir/serial.exe not disinfected postponed 03/01/2009 22:07:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTPT Console 2.06.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTPT Console 2.06.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:07:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Icesun Audio Converter 2.00.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Icesun Audio Converter 2.00.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:07:06 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Image++ 2.1.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:06 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Image++ 2.1.zip.vir/run.exe not disinfected postponed 03/01/2009 22:07:08 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Indian HoroScope 1.0.0.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:08 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Indian HoroScope 1.0.0.0.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:07:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iRep 2.5.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iRep 2.5.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:07:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iTunes Alarm Clock 2.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iTunes Alarm Clock 2.0.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:07:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAMDAT.Mobile.Tetris.Marathon.v1.8.16.S60.J2ME.Retail-daddyfatsax.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAMDAT.Mobile.Tetris.Marathon.v1.8.16.S60.J2ME.Retail-daddyfatsax.zip.vir/run.exe not disinfected postponed 03/01/2009 22:07:17 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAME 6.0.1.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:17 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAME 6.0.1.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:07:20 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Jvw filter email 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:20 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Jvw filter email 1.0.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:07:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ka Log Analyzer 1.65.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ka Log Analyzer 1.65.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:07:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\KingConvert For SamSung E768 4.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\KingConvert For SamSung E768 4.0.zip.vir/run.exe not disinfected postponed 03/01/2009 22:07:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\LDAPsearcher 1.1.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\LDAPsearcher 1.1.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:07:27 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Lomsel Shutdown 1.04.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:27 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Lomsel Shutdown 1.04.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:07:28 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\M3U Creator 1.0.1.4.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:28 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\M3U Creator 1.0.1.4.zip.vir/run.exe not disinfected postponed 03/01/2009 22:07:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Mini Log Book 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Mini Log Book 1.0.zip.vir/serial.exe not disinfected postponed 03/01/2009 22:07:31 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\mnoGoSearch for Windows Pro Oracle Edition Pro 3.2.40.1.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:31 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\mnoGoSearch for Windows Pro Oracle Edition Pro 3.2.40.1.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:07:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MoonSked 1.4.7.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MoonSked 1.4.7.zip.vir/serial.exe not disinfected postponed 03/01/2009 22:07:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\My Auction Search Browser for eBay 2.2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\My Auction Search Browser for eBay 2.2.0.zip.vir/install.exe not disinfected postponed 03/01/2009 22:07:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MyPhone Book Dialer 8.1.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MyPhone Book Dialer 8.1.0.zip.vir/install.exe not disinfected postponed 03/01/2009 22:07:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\News Talk ZB 1.0.0.0.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\News Talk ZB 1.0.0.0.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:07:38 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Nod32_v2+manual+plugin+(crack_de_por_vida)(español-spanish)por_borracho.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:38 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Nod32_v2+manual+plugin+(crack_de_por_vida)(español-spanish)por_borracho.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:07:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Norton AntiVirus and Internet Security LiveSubscribe Crack (Extends Subscription to 8-20-2116).zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Norton AntiVirus and Internet Security LiveSubscribe Crack (Extends Subscription to 8-20-2116).zip.vir/run.exe not disinfected postponed 03/01/2009 22:07:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Offline Explorer Pro 5.2.2878 Service Release 1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Offline Explorer Pro 5.2.2878 Service Release 1.zip.vir/install.exe not disinfected postponed 03/01/2009 22:07:42 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Omega Constellation Screen Saver.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:42 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Omega Constellation Screen Saver.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:07:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PaintFX 1.01.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PaintFX 1.01.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:07:47 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Pamela for Skype Professional Version 1.36.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:47 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Pamela for Skype Professional Version 1.36.zip.vir/serial.exe not disinfected postponed 03/01/2009 22:07:48 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PauseProcess 1.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:48 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PauseProcess 1.0.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:07:49 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PDF Password Remover 3.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:49 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PDF Password Remover 3.0.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:07:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Picture Spyglass Rev 4.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Picture Spyglass Rev 4.0.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:07:53 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PlotLab .NET 3.1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:53 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PlotLab .NET 3.1.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:07:54 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PopupAlert 2.02.0086.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:54 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PopupAlert 2.02.0086.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:07:56 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PrintController 2.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:56 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PrintController 2.0.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:07:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Profile Picture Genius 1.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:07:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Profile Picture Genius 1.0.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:08:00 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Quick Install Maker 2.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:00 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Quick Install Maker 2.0.zip.vir/run.exe not disinfected postponed 03/01/2009 22:08:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\R Color Code 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\R Color Code 1.0.zip.vir/install_crack.exe not disinfected postponed 03/01/2009 22:08:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RandBack32 1.00.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RandBack32 1.00.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:08:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Real-Time Rendering.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Real-Time Rendering.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:08:08 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Registry Workshop 4.0.1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:08 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Registry Workshop 4.0.1.zip.vir/install.exe not disinfected postponed 03/01/2009 22:08:10 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RRS plugin for LCDC 1.4a.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:10 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RRS plugin for LCDC 1.4a.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:08:12 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SC DVD Ripper 1.0.0.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:12 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SC DVD Ripper 1.0.0.0.zip.vir/run.exe not disinfected postponed 03/01/2009 22:08:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Serial Port Splitter 3.8.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Serial Port Splitter 3.8.2.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:08:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SfbEmailVerifier 1.3.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SfbEmailVerifier 1.3.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:08:17 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Shell-and-Tube Heat Exchanger 1.1.0.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:17 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Shell-and-Tube Heat Exchanger 1.1.0.0.zip.vir/run.exe not disinfected postponed 03/01/2009 22:08:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Site Coder 2.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Site Coder 2.zip.vir/key_gen.exe not disinfected postponed 03/01/2009 22:08:21 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Skater .NET Obfuscator Freeware Light 2.60.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:21 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Skater .NET Obfuscator Freeware Light 2.60.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:08:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SlovoEd Classic English-German 6.4.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SlovoEd Classic English-German 6.4.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:08:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SmarterMail Free Edition 5.5.3126.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SmarterMail Free Edition 5.5.3126.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:08:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SQL Help Builder 2.03.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SQL Help Builder 2.03.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:08:28 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Stereoscope Theatre Love & Romance 1.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:28 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Stereoscope Theatre Love & Romance 1.0.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:08:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SVG Link Agent 1.3.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SVG Link Agent 1.3.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:08:32 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Symantec.Antivirus.Corporate.Server.Edition.v8.1.0.825.Retail-SHOCK.ShareConnector.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:32 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Symantec.Antivirus.Corporate.Server.Edition.v8.1.0.825.Retail-SHOCK.ShareConnector.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:08:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\System Information 1.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\System Information 1.0.zip.vir/install.exe not disinfected postponed 03/01/2009 22:08:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Talking Alphabet 2.0.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Talking Alphabet 2.0.2.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:08:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ThumbPlus ActiveX Control 5.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ThumbPlus ActiveX Control 5.0.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:08:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Tomtom Navigator 6V Para Pocket Pc Nokia 6280.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Tomtom Navigator 6V Para Pocket Pc Nokia 6280.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:08:42 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Trackless 1.03.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:42 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Trackless 1.03.zip.vir/crac.exe not disinfected postponed 03/01/2009 22:08:43 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\TVants 1.0.0.59 Build 0834.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:43 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\TVants 1.0.0.59 Build 0834.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:08:45 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Project Manager Enterprise 1.1.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:45 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Project Manager Enterprise 1.1.zip.vir/key_gen.exe not disinfected postponed 03/01/2009 22:08:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Video Converter 6.0.2.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Video Converter 6.0.2.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:08:49 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vextractor 4.20.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:49 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vextractor 4.20.zip.vir/run.exe not disinfected postponed 03/01/2009 22:08:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vox Box 1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vox Box 1.zip.vir/keygen.exe not disinfected postponed 03/01/2009 22:08:55 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WallMan 1.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:55 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WallMan 1.0.zip.vir/setup.exe not disinfected postponed 03/01/2009 22:08:56 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WinComm 2.03.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:56 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WinComm 2.03.zip.vir/install_patch.exe not disinfected postponed 03/01/2009 22:08:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Wine Organizer 3.6a.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Wine Organizer 3.6a.zip.vir/patch.exe not disinfected postponed 03/01/2009 22:08:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WTY-DTT 0.9.5 Beta.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:08:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WTY-DTT 0.9.5 Beta.zip.vir/key_generator.exe not disinfected postponed 03/01/2009 22:09:00 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Zipsize 0.2.2.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:09:00 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Zipsize 0.2.2.zip.vir/run.exe not disinfected postponed 03/01/2009 22:09:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\[APP-ITA].Ewido.Security.Suite.v3.5.Plus.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 03/01/2009 22:09:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\[APP-ITA].Ewido.Security.Suite.v3.5.Plus.zip.vir/run.exe not disinfected postponed 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader1.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader1.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader10.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader10.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader11.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader11.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader12.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader12.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader13.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader13.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader14.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader14.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader15.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader15.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader16.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader16.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader17.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader17.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader18.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader18.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader19.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader19.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader2.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader2.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader20.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader20.zip/sbRecovery.ini password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader21.zip/sbRecovery.reg password protected 04/01/2009 01:49:28 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader21.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader22.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader22.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader23.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader23.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader24.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader24.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader25.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader25.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader26.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader26.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader27.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader27.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader28.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader28.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader29.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader29.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader3.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader3.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader30.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader30.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader31.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader31.zip/sbRecovery.ini password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader4.zip/sbRecovery.reg password protected 04/01/2009 01:49:29 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader4.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader5.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader5.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader6.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader6.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader7.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader7.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader8.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader8.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader9.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdobeAcrobatReader9.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs1.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs2.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs2.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs3.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs3.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs4.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommonDialogs4.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer1.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer10.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer10.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer11.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer11.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer12.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer12.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer13.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer13.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer14.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer14.zip/sbRecovery.ini password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer15.zip/sbRecovery.reg password protected 04/01/2009 01:49:30 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer15.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer16.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer16.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer17.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer17.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer18.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer18.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer19.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer19.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer2.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer20.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer20.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer21.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer21.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer22.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer22.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer23.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer23.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer3.zip/sbRecovery.ini password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip/sbRecovery.reg password protected 04/01/2009 01:49:31 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer4.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer5.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer5.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer6.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer6.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer7.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer7.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer8.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer8.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer9.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetExplorer9.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD1.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD1.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD2.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD2.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD3.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD3.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD4.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD4.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD5.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectD5.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw1.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw1.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw2.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw2.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw3.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw3.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw4.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSDirectDraw4.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole1.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole1.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole2.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole2.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole3.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSManagementConsole3.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip/wmplibrary_v_0_12.db password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer1.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer10.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer10.zip/sbRecovery.ini password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer11.zip/sbRecovery.reg password protected 04/01/2009 01:49:32 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer11.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer12.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer12.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer13.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer13.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer14.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer14.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer15.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer15.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer16.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer16.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer17.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer17.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer18.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer18.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer19.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer19.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip/wmplibrary_v_0_12.db password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer2.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer3.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer4.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer4.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer5.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer5.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer6.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer6.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer7.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer7.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer8.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer8.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer9.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSMediaPlayer9.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice1.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice1.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice2.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOffice2.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel1.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel1.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel2.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel2.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel3.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeExcel3.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficePowerPoint.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficePowerPoint.zip/sbRecovery.ini password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficePowerPoint1.zip/sbRecovery.reg password protected 04/01/2009 01:49:33 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficePowerPoint1.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord1.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord1.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord2.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord2.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord3.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSOfficeWord3.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSPaint.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSPaint.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant1.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant1.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant2.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant2.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant3.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSSearchAssistant3.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSWordpad.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MSWordpad.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer1.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer1.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer2.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer2.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer3.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer3.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer4.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer4.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer5.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer5.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer6.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer6.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer7.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer7.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer8.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer8.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer9.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RealOnePlayerakaRealPlayer9.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBaglehi.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBaglehi.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Windows.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer1.zip/sbRecovery.ini password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip/sbRecovery.reg password protected 04/01/2009 01:49:34 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer10.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer11.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer11.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer12.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer12.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer13.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer13.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer14.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer14.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer15.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer16.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer16.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer17.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer17.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer18.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer18.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer19.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer19.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer2.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer20.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer20.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer21.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer21.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer22.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer23.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer23.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer24.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer24.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer25.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer25.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer26.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer26.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer27.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer27.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer28.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer28.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer29.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer29.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer3.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer30.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer30.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer31.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer31.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer32.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer32.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer33.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer33.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer34.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer34.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer35.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer35.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer36.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer36.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer37.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer37.zip/sbRecovery.ini password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip/sbRecovery.reg password protected 04/01/2009 01:49:35 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer4.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer5.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer6.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer7.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer8.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsExplorer9.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK1.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK1.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK10.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK10.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK11.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK11.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK12.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK12.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK13.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK13.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK14.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK14.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK15.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK15.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK16.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK16.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK17.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK17.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK18.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK18.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK19.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK19.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK2.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK2.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK20.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK20.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK21.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK21.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK22.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK22.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK23.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK23.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK24.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK24.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK25.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK25.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK26.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK26.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK3.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK3.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK4.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK4.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK5.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK5.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK6.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK6.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK7.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK7.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK8.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK8.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK9.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsMediaSDK9.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith1.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith1.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith2.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith2.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith3.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith3.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith4.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith4.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith5.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith5.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith6.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WindowsOpenWith6.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR1.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR1.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR2.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR2.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR3.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR3.zip/sbRecovery.ini password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR4.zip/sbRecovery.reg password protected 04/01/2009 01:49:36 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR4.zip/sbRecovery.ini password protected 04/01/2009 01:49:37 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR5.zip/sbRecovery.reg password protected 04/01/2009 01:49:37 File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRAR5.zip/sbRecovery.ini password protected 04/01/2009 02:14:57 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AcroPro80_efg.exe password protected 04/01/2009 02:14:57 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\FlashGet.EXE password protected 04/01/2009 02:14:57 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\flashget181en.exe password protected 04/01/2009 02:14:57 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\GUIDE.txt password protected 04/01/2009 02:14:57 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\KeyGen.exe password protected 04/01/2009 02:14:57 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\More Quality Full Downloads! Warez_Listings Index.url password protected 04/01/2009 02:14:57 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen.rar/Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\plz read.txt password protected 04/01/2009 02:15:03 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AcroPro80_efg.exe password protected 04/01/2009 02:15:03 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\FlashGet.EXE password protected 04/01/2009 02:15:03 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\flashget181en.exe password protected 04/01/2009 02:15:03 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\GUIDE.txt password protected 04/01/2009 02:15:03 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\KeyGen.exe password protected 04/01/2009 02:15:03 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\More Quality Full Downloads! Warez_Listings Index.url password protected 04/01/2009 02:15:03 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat Professional 8 with KeyGen\Adobe Acrobat 8.rar/AdobeAcrobat8 KeyGen+flashget181en\plz read.txt password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/Ad-Aware SE Default.skn password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/arrow1.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/arrow2.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bck1.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt11.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt12.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt13.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt21.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt22.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt23.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt31.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt32.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt33.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt41.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt42.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt43.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt51.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt52.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt53.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt61.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/bt62.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox1.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox2.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox3.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/checkbox4.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn1.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn2.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/defbtn3.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph1.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph2.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph3.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph4.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph5.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph6.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/glyph7.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/main.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/preview.bmp password protected 04/01/2009 02:20:15 File: C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Maintenance PC\Divers Antivirus - procédures\aawsepersonal.exe//WISE0020.BIN/sprite1.bmp password protected 04/01/2009 02:31:08 File: C:\DRIVERS\OTHER.EXE//LzExe/BIOSLOCK.PIF password protected 04/01/2009 02:31:08 File: C:\DRIVERS\OTHER.EXE//LzExe/BIOSLOCK.EXE password protected 04/01/2009 02:31:25 File: C:\DRIVERS\MCDBF\SOURCE1\OTHER.EXE//LzExe/BIOSLOCK.PIF password protected 04/01/2009 02:31:25 File: C:\DRIVERS\MCDBF\SOURCE1\OTHER.EXE//LzExe/BIOSLOCK.EXE password protected 04/01/2009 02:31:27 File: C:\DRIVERS\MCDBF\SOURCE1\TSADDON.EXE//LzExe/UNISHHS.ARJ/UPDTAT.BAT password protected 04/01/2009 03:18:26 File: C:\Program Files\eMule\Temp\002.part/ Kid - Ecole CM2 Maths 2007 - [ Full ].zip password protected 04/01/2009 03:18:26 File: C:\Program Files\eMule\Temp\002.part/ Kid - Ecole CM2 Maths 2007 - [ Full ].zip password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___.obj password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___S01A01.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___SxxIco.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___SxxIdt.txt password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___SxxInf.rtf password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/DB___SxxZon.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___.obj password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___S01A01.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___SxxIco.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___SxxIdt.txt password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___SxxInf.rtf password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/EN___SxxZon.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___.obj password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___S01A01.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___SxxIco.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___SxxIdt.txt password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___SxxInf.rtf password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JM___SxxZon.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___.obj password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___S01A01.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___SxxIco.smk password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___SxxIdt.txt password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___SxxInf.rtf password protected 04/01/2009 03:35:09 File: C:\Program Files\Mindscape\Gdg9\Gdg.zat/JQ___SxxZon.smk password protected 04/01/2009 04:17:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\winupgro.exe.vir detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\winupgro.exe.vir not disinfected postponed 04/01/2009 04:17:06 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\_srosa_.sys.zip/srosa.sys detected Trojan program 'Trojan-Downloader.Win32.Bagle.afl' 04/01/2009 04:17:06 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\_srosa_.sys.zip/srosa.sys not disinfected postponed 04/01/2009 04:17:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\386875.exe.vir detected virus 'Email-Worm.Win32.Bagle.majc' 04/01/2009 04:17:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\386875.exe.vir not disinfected postponed 04/01/2009 04:17:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\903578.exe.vir detected virus 'Email-Worm.Win32.Bagle.majc' 04/01/2009 04:17:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\drivers\downld\903578.exe.vir not disinfected postponed 04/01/2009 04:17:14 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\data.oct.vir detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:14 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\data.oct.vir not disinfected postponed 04/01/2009 04:17:14 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\(Serial).Symantec.Livestate.Recovery.6.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:14 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\(Serial).Symantec.Livestate.Recovery.6.0.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:17:18 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\32bit Email Broadcaster 08.11.17.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:18 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\32bit Email Broadcaster 08.11.17.zip.vir/install.exe not disinfected postponed 04/01/2009 04:17:20 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\A123 AVI MPEG WMV ASF MOV FLV to Zune Converter 4.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:20 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\A123 AVI MPEG WMV ASF MOV FLV to Zune Converter 4.0.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:17:22 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ace DVD Backup 1.3.32.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:22 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ace DVD Backup 1.3.32.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:17:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AdvaSaR Ed 5.04.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AdvaSaR Ed 5.04.zip.vir/run.exe not disinfected postponed 04/01/2009 04:17:27 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Aimersoft DVD to 3GP Converter 1.1.62.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:27 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Aimersoft DVD to 3GP Converter 1.1.62.zip.vir/key_gen.exe not disinfected postponed 04/01/2009 04:17:28 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ali Landry 33 Screensaver 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:28 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ali Landry 33 Screensaver 1.0.zip.vir/serial.exe not disinfected postponed 04/01/2009 04:17:30 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ASP.NET Image Gallery 1.1.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:30 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ASP.NET Image Gallery 1.1.zip.vir/key_gen.exe not disinfected postponed 04/01/2009 04:17:32 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ATnotes 9.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:32 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ATnotes 9.5.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:17:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AudioManage 2.10.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AudioManage 2.10.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:17:35 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AutoQ2 1.0.9.9r3.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:35 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AutoQ2 1.0.9.9r3.zip.vir/run.exe not disinfected postponed 04/01/2009 04:17:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AVAST.4.6.PRO+KEY+TESTED.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\AVAST.4.6.PRO+KEY+TESTED.zip.vir/run.exe not disinfected postponed 04/01/2009 04:17:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Azureus Turbo Accelerator 2.7.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Azureus Turbo Accelerator 2.7.0.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:17:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Babysitter Services Finder 1.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Babysitter Services Finder 1.0.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:17:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Be Mine Screensaver 2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Be Mine Screensaver 2.0.zip.vir/install.exe not disinfected postponed 04/01/2009 04:17:44 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Beach Cams PT 0.2.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:44 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Beach Cams PT 0.2.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:17:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Biometric HP Manager Enterprise 6.12.44.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Biometric HP Manager Enterprise 6.12.44.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:17:48 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Bitdefender Free Antivir Software.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:48 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Bitdefender Free Antivir Software.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:17:50 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Blade Runner Font 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:50 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Blade Runner Font 1.0.zip.vir/serial.exe not disinfected postponed 04/01/2009 04:17:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CadLib 3.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CadLib 3.5.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:17:54 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CCNA FlashCards 1.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:54 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CCNA FlashCards 1.0.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:17:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Citrix 1Y0-991 Practice Exam Test Questions.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Citrix 1Y0-991 Practice Exam Test Questions.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:17:58 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Claymore Time Sheets 2005 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:58 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Claymore Time Sheets 2005 1.0.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:17:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CodeWorker 4.5.1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:17:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CodeWorker 4.5.1.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:18:01 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Convert Image 1.96.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:01 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Convert Image 1.96.zip.vir/run.exe not disinfected postponed 04/01/2009 04:18:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CryptaFlix 1.11.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\CryptaFlix 1.11.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:18:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DDObjects 0.9.95.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DDObjects 0.9.95.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:18:08 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DeepForm 1.1.1.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:08 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DeepForm 1.1.1.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:18:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Desktop Fay 2.8.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Desktop Fay 2.8.zip.vir/install.exe not disinfected postponed 04/01/2009 04:18:10 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DiskSurvey 1.0.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:10 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\DiskSurvey 1.0.5.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:18:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Domeru DVD to iPod Converter 3.6.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Domeru DVD to iPod Converter 3.6.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:18:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Don's Alarm Clock 1.1.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Don's Alarm Clock 1.1.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:18:16 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Drag to MP3 1.0.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:16 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Drag to MP3 1.0.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:18:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Dragonfly Attack Screensaver.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Dragonfly Attack Screensaver.zip.vir/serial.exe not disinfected postponed 04/01/2009 04:18:22 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Duplicate DLL File Finder Software 7.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:22 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Duplicate DLL File Finder Software 7.0.zip.vir/install.exe not disinfected postponed 04/01/2009 04:18:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\e!Sankey 1.3.0.324.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\e!Sankey 1.3.0.324.zip.vir/key_gen.exe not disinfected postponed 04/01/2009 04:18:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Easy Peasy Passwords 2.3.1.17.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Easy Peasy Passwords 2.3.1.17.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:18:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Elecard Codec .NET SDK G4 1.1.80717.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Elecard Codec .NET SDK G4 1.1.80717.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:18:27 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\entOnly.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:27 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\entOnly.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:18:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EVE Online Images Widget 1.1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EVE Online Images Widget 1.1.zip.vir/install.exe not disinfected postponed 04/01/2009 04:18:30 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Event Engineer 1.0.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:30 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Event Engineer 1.0.zip.vir/key_gen.exe not disinfected postponed 04/01/2009 04:18:31 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Execute This! 1.3.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:31 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Execute This! 1.3.0.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:18:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EZ Contract Proposal 2.3.0.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\EZ Contract Proposal 2.3.0.zip.vir/key_gen.exe not disinfected postponed 04/01/2009 04:18:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FeedStation 2.0 beta2.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FeedStation 2.0 beta2.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:18:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Filo 2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Filo 2.0.zip.vir/install.exe not disinfected postponed 04/01/2009 04:18:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FireCode 2004 1.00.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\FireCode 2004 1.00.zip.vir/install.exe not disinfected postponed 04/01/2009 04:18:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\First Radio 89.1FM Israel 3.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\First Radio 89.1FM Israel 3.0.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:18:38 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Flawless Makeup Tips 3.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:38 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Flawless Makeup Tips 3.0.zip.vir/run.exe not disinfected postponed 04/01/2009 04:18:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\foo vis flame 0.93.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\foo vis flame 0.93.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:18:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Geforce Tweak Utility 3.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Geforce Tweak Utility 3.2.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:18:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GEODisk 3.3.4.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GEODisk 3.3.4.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:18:44 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GoodOK MP4 Converter 5.3.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:44 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GoodOK MP4 Converter 5.3.zip.vir/key_gen.exe not disinfected postponed 04/01/2009 04:18:45 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Guitar Ensemble 1.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:45 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Guitar Ensemble 1.0.zip.vir/run.exe not disinfected postponed 04/01/2009 04:18:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GZ Calendar 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\GZ Calendar 1.0.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:18:47 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Hilary Duff Screensaver1.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:47 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Hilary Duff Screensaver1.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:18:50 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HMView 4.04.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:50 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HMView 4.04.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:18:51 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HoursClocked-Basic 001-004-002.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:51 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HoursClocked-Basic 001-004-002.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:18:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML to Flash Password 1.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:52 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML to Flash Password 1.0.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:18:54 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML-Handler for Eudora 3.1.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:54 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTML-Handler for Eudora 3.1.zip.vir/serial.exe not disinfected postponed 04/01/2009 04:18:56 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTPT Console 2.06.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:56 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\HTPT Console 2.06.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:18:58 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Icesun Audio Converter 2.00.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:58 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Icesun Audio Converter 2.00.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:18:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Image++ 2.1.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:18:59 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Image++ 2.1.zip.vir/run.exe not disinfected postponed 04/01/2009 04:19:00 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Indian HoroScope 1.0.0.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:00 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Indian HoroScope 1.0.0.0.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:19:01 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iRep 2.5.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:01 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iRep 2.5.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:19:03 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iTunes Alarm Clock 2.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:04 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\iTunes Alarm Clock 2.0.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:19:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAMDAT.Mobile.Tetris.Marathon.v1.8.16.S60.J2ME.Retail-daddyfatsax.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAMDAT.Mobile.Tetris.Marathon.v1.8.16.S60.J2ME.Retail-daddyfatsax.zip.vir/run.exe not disinfected postponed 04/01/2009 04:19:07 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAME 6.0.1.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:07 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\JAME 6.0.1.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:19:10 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Jvw filter email 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:10 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Jvw filter email 1.0.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:19:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ka Log Analyzer 1.65.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Ka Log Analyzer 1.65.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:19:12 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\KingConvert For SamSung E768 4.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:12 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\KingConvert For SamSung E768 4.0.zip.vir/run.exe not disinfected postponed 04/01/2009 04:19:14 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\LDAPsearcher 1.1.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:14 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\LDAPsearcher 1.1.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:19:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Lomsel Shutdown 1.04.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Lomsel Shutdown 1.04.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:19:16 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\M3U Creator 1.0.1.4.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:16 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\M3U Creator 1.0.1.4.zip.vir/run.exe not disinfected postponed 04/01/2009 04:19:17 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Mini Log Book 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:17 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Mini Log Book 1.0.zip.vir/serial.exe not disinfected postponed 04/01/2009 04:19:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\mnoGoSearch for Windows Pro Oracle Edition Pro 3.2.40.1.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\mnoGoSearch for Windows Pro Oracle Edition Pro 3.2.40.1.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:19:21 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MoonSked 1.4.7.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:21 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MoonSked 1.4.7.zip.vir/serial.exe not disinfected postponed 04/01/2009 04:19:22 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\My Auction Search Browser for eBay 2.2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:22 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\My Auction Search Browser for eBay 2.2.0.zip.vir/install.exe not disinfected postponed 04/01/2009 04:19:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MyPhone Book Dialer 8.1.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\MyPhone Book Dialer 8.1.0.zip.vir/install.exe not disinfected postponed 04/01/2009 04:19:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\News Talk ZB 1.0.0.0.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:24 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\News Talk ZB 1.0.0.0.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:19:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Nod32_v2+manual+plugin+(crack_de_por_vida)(español-spanish)por_borracho.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Nod32_v2+manual+plugin+(crack_de_por_vida)(español-spanish)por_borracho.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:19:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Norton AntiVirus and Internet Security LiveSubscribe Crack (Extends Subscription to 8-20-2116).zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Norton AntiVirus and Internet Security LiveSubscribe Crack (Extends Subscription to 8-20-2116).zip.vir/run.exe not disinfected postponed 04/01/2009 04:19:27 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Offline Explorer Pro 5.2.2878 Service Release 1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:27 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Offline Explorer Pro 5.2.2878 Service Release 1.zip.vir/install.exe not disinfected postponed 04/01/2009 04:19:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Omega Constellation Screen Saver.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Omega Constellation Screen Saver.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:19:32 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PaintFX 1.01.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:32 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PaintFX 1.01.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:19:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Pamela for Skype Professional Version 1.36.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:33 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Pamela for Skype Professional Version 1.36.zip.vir/serial.exe not disinfected postponed 04/01/2009 04:19:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PauseProcess 1.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PauseProcess 1.0.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:19:35 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PDF Password Remover 3.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:35 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PDF Password Remover 3.0.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:19:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Picture Spyglass Rev 4.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Picture Spyglass Rev 4.0.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:19:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PlotLab .NET 3.1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PlotLab .NET 3.1.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:19:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PopupAlert 2.02.0086.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PopupAlert 2.02.0086.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:19:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PrintController 2.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:41 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\PrintController 2.0.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:19:43 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Profile Picture Genius 1.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:43 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Profile Picture Genius 1.0.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:19:44 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Quick Install Maker 2.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:44 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Quick Install Maker 2.0.zip.vir/run.exe not disinfected postponed 04/01/2009 04:19:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\R Color Code 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:46 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\R Color Code 1.0.zip.vir/install_crack.exe not disinfected postponed 04/01/2009 04:19:47 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RandBack32 1.00.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:47 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RandBack32 1.00.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:19:50 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Real-Time Rendering.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:50 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Real-Time Rendering.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:19:53 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Registry Workshop 4.0.1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:53 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Registry Workshop 4.0.1.zip.vir/install.exe not disinfected postponed 04/01/2009 04:19:55 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RRS plugin for LCDC 1.4a.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:55 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\RRS plugin for LCDC 1.4a.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:19:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SC DVD Ripper 1.0.0.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SC DVD Ripper 1.0.0.0.zip.vir/run.exe not disinfected postponed 04/01/2009 04:19:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Serial Port Splitter 3.8.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:19:57 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Serial Port Splitter 3.8.2.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:20:01 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SfbEmailVerifier 1.3.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:01 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SfbEmailVerifier 1.3.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:20:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Shell-and-Tube Heat Exchanger 1.1.0.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:02 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Shell-and-Tube Heat Exchanger 1.1.0.0.zip.vir/run.exe not disinfected postponed 04/01/2009 04:20:04 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Site Coder 2.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:04 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Site Coder 2.zip.vir/key_gen.exe not disinfected postponed 04/01/2009 04:20:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Skater .NET Obfuscator Freeware Light 2.60.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:05 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Skater .NET Obfuscator Freeware Light 2.60.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:20:07 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SlovoEd Classic English-German 6.4.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:07 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SlovoEd Classic English-German 6.4.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:20:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SmarterMail Free Edition 5.5.3126.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:09 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SmarterMail Free Edition 5.5.3126.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:20:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SQL Help Builder 2.03.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:11 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SQL Help Builder 2.03.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:20:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Stereoscope Theatre Love & Romance 1.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:13 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Stereoscope Theatre Love & Romance 1.0.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:20:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SVG Link Agent 1.3.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:15 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\SVG Link Agent 1.3.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:20:18 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Symantec.Antivirus.Corporate.Server.Edition.v8.1.0.825.Retail-SHOCK.ShareConnector.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:18 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Symantec.Antivirus.Corporate.Server.Edition.v8.1.0.825.Retail-SHOCK.ShareConnector.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:20:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\System Information 1.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:19 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\System Information 1.0.zip.vir/install.exe not disinfected postponed 04/01/2009 04:20:20 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Talking Alphabet 2.0.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:21 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Talking Alphabet 2.0.2.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:20:21 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ThumbPlus ActiveX Control 5.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:21 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\ThumbPlus ActiveX Control 5.0.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:20:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Tomtom Navigator 6V Para Pocket Pc Nokia 6280.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:23 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Tomtom Navigator 6V Para Pocket Pc Nokia 6280.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:20:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Trackless 1.03.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:25 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Trackless 1.03.zip.vir/crac.exe not disinfected postponed 04/01/2009 04:20:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\TVants 1.0.0.59 Build 0834.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:26 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\TVants 1.0.0.59 Build 0834.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:20:28 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Project Manager Enterprise 1.1.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:28 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Project Manager Enterprise 1.1.zip.vir/key_gen.exe not disinfected postponed 04/01/2009 04:20:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Video Converter 6.0.2.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:29 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Universal Video Converter 6.0.2.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:20:30 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vextractor 4.20.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:30 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vextractor 4.20.zip.vir/run.exe not disinfected postponed 04/01/2009 04:20:32 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vox Box 1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:32 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Vox Box 1.zip.vir/keygen.exe not disinfected postponed 04/01/2009 04:20:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WallMan 1.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:34 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WallMan 1.0.zip.vir/setup.exe not disinfected postponed 04/01/2009 04:20:35 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WinComm 2.03.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:35 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WinComm 2.03.zip.vir/install_patch.exe not disinfected postponed 04/01/2009 04:20:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Wine Organizer 3.6a.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:36 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Wine Organizer 3.6a.zip.vir/patch.exe not disinfected postponed 04/01/2009 04:20:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WTY-DTT 0.9.5 Beta.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:37 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\WTY-DTT 0.9.5 Beta.zip.vir/key_generator.exe not disinfected postponed 04/01/2009 04:20:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Zipsize 0.2.2.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:39 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\Zipsize 0.2.2.zip.vir/run.exe not disinfected postponed 04/01/2009 04:20:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\[APP-ITA].Ewido.Security.Suite.v3.5.Plus.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 04:20:40 File: C:\Qoobox\Quarantine\C\Documents and Settings\romestan\Application Data\m\shared\[APP-ITA].Ewido.Security.Suite.v3.5.Plus.zip.vir/run.exe not disinfected postponed 04/01/2009 07:37:21 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\drivers\winupgro.exe.vir detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:05:57 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\drivers\winupgro.exe.vir deleted 04/01/2009 10:06:00 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\drivers\_srosa_.sys.zip/srosa.sys detected Trojan program 'Trojan-Downloader.Win32.Bagle.afl' 04/01/2009 10:06:00 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\drivers\_srosa_.sys.zip/srosa.sys deleted 04/01/2009 10:06:02 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\drivers\downld\386875.exe.vir detected virus 'Email-Worm.Win32.Bagle.majc' 04/01/2009 10:06:02 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\drivers\downld\386875.exe.vir deleted 04/01/2009 10:06:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\drivers\downld\903578.exe.vir detected virus 'Email-Worm.Win32.Bagle.majc' 04/01/2009 10:06:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\drivers\downld\903578.exe.vir deleted 04/01/2009 10:06:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\data.oct.vir detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\data.oct.vir deleted 04/01/2009 10:06:05 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\(serial).symantec.livestate.recovery.6.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:08 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\(serial).symantec.livestate.recovery.6.0.zip.vir/install_crack.exe deleted 04/01/2009 10:06:11 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\32bit email broadcaster 08.11.17.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:13 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\32bit email broadcaster 08.11.17.zip.vir/install.exe deleted 04/01/2009 10:06:17 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\a123 avi mpeg wmv asf mov flv to zune converter 4.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:18 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\a123 avi mpeg wmv asf mov flv to zune converter 4.0.zip.vir/patch.exe deleted 04/01/2009 10:06:21 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ace dvd backup 1.3.32.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:24 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ace dvd backup 1.3.32.zip.vir/setup.exe deleted 04/01/2009 10:06:28 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\advasar ed 5.04.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:30 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\advasar ed 5.04.zip.vir/run.exe deleted 04/01/2009 10:06:33 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\aimersoft dvd to 3gp converter 1.1.62.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:34 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\aimersoft dvd to 3gp converter 1.1.62.zip.vir/key_gen.exe deleted 04/01/2009 10:06:36 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ali landry 33 screensaver 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:37 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ali landry 33 screensaver 1.0.zip.vir/serial.exe deleted 04/01/2009 10:06:39 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\asp.net image gallery 1.1.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:41 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\asp.net image gallery 1.1.zip.vir/key_gen.exe deleted 04/01/2009 10:06:43 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\atnotes 9.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:44 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\atnotes 9.5.zip.vir/install_crack.exe deleted 04/01/2009 10:06:45 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\audiomanage 2.10.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:48 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\audiomanage 2.10.zip.vir/install_patch.exe deleted 04/01/2009 10:06:53 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\autoq2 1.0.9.9r3.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:53 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\autoq2 1.0.9.9r3.zip.vir/run.exe deleted 04/01/2009 10:06:55 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\avast.4.6.pro+key+tested.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:06:58 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\avast.4.6.pro+key+tested.zip.vir/run.exe deleted 04/01/2009 10:07:01 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\azureus turbo accelerator 2.7.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:02 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\azureus turbo accelerator 2.7.0.zip.vir/patch.exe deleted 04/01/2009 10:07:02 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\babysitter services finder 1.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:03 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\babysitter services finder 1.0.zip.vir/patch.exe deleted 04/01/2009 10:07:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\be mine screensaver 2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:07 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\be mine screensaver 2.0.zip.vir/install.exe deleted 04/01/2009 10:07:10 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\beach cams pt 0.2.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:14 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\beach cams pt 0.2.zip.vir/keygen.exe deleted 04/01/2009 10:07:17 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\biometric hp manager enterprise 6.12.44.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:19 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\biometric hp manager enterprise 6.12.44.zip.vir/setup.exe deleted 04/01/2009 10:07:20 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\bitdefender free antivir software.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:23 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\bitdefender free antivir software.zip.vir/install_patch.exe deleted 04/01/2009 10:07:25 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\blade runner font 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:29 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\blade runner font 1.0.zip.vir/serial.exe deleted 04/01/2009 10:07:40 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\cadlib 3.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:41 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\cadlib 3.5.zip.vir/install_crack.exe deleted 04/01/2009 10:07:43 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ccna flashcards 1.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:46 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ccna flashcards 1.0.zip.vir/install_patch.exe deleted 04/01/2009 10:07:50 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\citrix 1y0-991 practice exam test questions.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:50 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\citrix 1y0-991 practice exam test questions.zip.vir/crac.exe deleted 04/01/2009 10:07:51 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\claymore time sheets 2005 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:52 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\claymore time sheets 2005 1.0.zip.vir/install_crack.exe deleted 04/01/2009 10:07:55 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\codeworker 4.5.1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:07:58 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\codeworker 4.5.1.zip.vir/keygen.exe deleted 04/01/2009 10:08:00 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\convert image 1.96.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:02 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\convert image 1.96.zip.vir/run.exe deleted 04/01/2009 10:08:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\cryptaflix 1.11.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:07 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\cryptaflix 1.11.zip.vir/install_crack.exe deleted 04/01/2009 10:08:11 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ddobjects 0.9.95.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:13 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ddobjects 0.9.95.zip.vir/patch.exe deleted 04/01/2009 10:08:22 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\deepform 1.1.1.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:23 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\deepform 1.1.1.zip.vir/patch.exe deleted 04/01/2009 10:08:24 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\desktop fay 2.8.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:26 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\desktop fay 2.8.zip.vir/install.exe deleted 04/01/2009 10:08:28 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\disksurvey 1.0.5.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:31 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\disksurvey 1.0.5.zip.vir/install_crack.exe deleted 04/01/2009 10:08:34 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\domeru dvd to ipod converter 3.6.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:34 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\domeru dvd to ipod converter 3.6.zip.vir/install_patch.exe deleted 04/01/2009 10:08:36 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\don's alarm clock 1.1.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:38 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\don's alarm clock 1.1.zip.vir/install_patch.exe deleted 04/01/2009 10:08:41 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\drag to mp3 1.0.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:44 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\drag to mp3 1.0.zip.vir/keygen.exe deleted 04/01/2009 10:08:47 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\dragonfly attack screensaver.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:49 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\dragonfly attack screensaver.zip.vir/serial.exe deleted 04/01/2009 10:08:59 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\duplicate dll file finder software 7.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:08:59 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\duplicate dll file finder software 7.0.zip.vir/install.exe deleted 04/01/2009 10:09:00 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\e!sankey 1.3.0.324.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:01 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\e!sankey 1.3.0.324.zip.vir/key_gen.exe deleted 04/01/2009 10:09:03 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\easy peasy passwords 2.3.1.17.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\easy peasy passwords 2.3.1.17.zip.vir/install_crack.exe deleted 04/01/2009 10:09:05 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\elecard codec .net sdk g4 1.1.80717.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:08 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\elecard codec .net sdk g4 1.1.80717.zip.vir/keygen.exe deleted 04/01/2009 10:09:11 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\entonly.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:12 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\entonly.zip.vir/install_crack.exe deleted 04/01/2009 10:09:14 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\eve online images widget 1.1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:15 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\eve online images widget 1.1.zip.vir/install.exe deleted 04/01/2009 10:09:16 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\event engineer 1.0.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:18 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\event engineer 1.0.zip.vir/key_gen.exe deleted 04/01/2009 10:09:20 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\execute this! 1.3.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:21 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\execute this! 1.3.0.zip.vir/patch.exe deleted 04/01/2009 10:09:23 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ez contract proposal 2.3.0.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:23 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ez contract proposal 2.3.0.zip.vir/key_gen.exe deleted 04/01/2009 10:09:25 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\feedstation 2.0 beta2.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:26 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\feedstation 2.0 beta2.zip.vir/install_patch.exe deleted 04/01/2009 10:09:27 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\filo 2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:36 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\filo 2.0.zip.vir/install.exe deleted 04/01/2009 10:09:38 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\firecode 2004 1.00.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:38 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\firecode 2004 1.00.zip.vir/install.exe deleted 04/01/2009 10:09:40 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\first radio 89.1fm israel 3.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:40 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\first radio 89.1fm israel 3.0.zip.vir/install_patch.exe deleted 04/01/2009 10:09:42 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\flawless makeup tips 3.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:43 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\flawless makeup tips 3.0.zip.vir/run.exe deleted 04/01/2009 10:09:45 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\foo vis flame 0.93.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:46 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\foo vis flame 0.93.zip.vir/crac.exe deleted 04/01/2009 10:09:48 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\geforce tweak utility 3.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:48 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\geforce tweak utility 3.2.zip.vir/key_generator.exe deleted 04/01/2009 10:09:50 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\geodisk 3.3.4.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:53 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\geodisk 3.3.4.zip.vir/keygen.exe deleted 04/01/2009 10:09:55 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\goodok mp4 converter 5.3.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:56 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\goodok mp4 converter 5.3.zip.vir/key_gen.exe deleted 04/01/2009 10:09:58 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\guitar ensemble 1.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:09:58 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\guitar ensemble 1.0.zip.vir/run.exe deleted 04/01/2009 10:10:00 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\gz calendar 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:02 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\gz calendar 1.0.zip.vir/install_crack.exe deleted 04/01/2009 10:10:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\hilary duff screensaver1.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:06 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\hilary duff screensaver1.zip.vir/install_crack.exe deleted 04/01/2009 10:10:15 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\hmview 4.04.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:16 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\hmview 4.04.zip.vir/key_generator.exe deleted 04/01/2009 10:10:19 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\hoursclocked-basic 001-004-002.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:20 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\hoursclocked-basic 001-004-002.zip.vir/setup.exe deleted 04/01/2009 10:10:22 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\html to flash password 1.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:24 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\html to flash password 1.0.zip.vir/patch.exe deleted 04/01/2009 10:10:27 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\html-handler for eudora 3.1.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:29 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\html-handler for eudora 3.1.zip.vir/serial.exe deleted 04/01/2009 10:10:32 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\htpt console 2.06.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:34 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\htpt console 2.06.zip.vir/patch.exe deleted 04/01/2009 10:10:36 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\icesun audio converter 2.00.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:39 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\icesun audio converter 2.00.zip.vir/keygen.exe deleted 04/01/2009 10:10:40 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\image++ 2.1.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:41 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\image++ 2.1.zip.vir/run.exe deleted 04/01/2009 10:10:47 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\indian horoscope 1.0.0.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:48 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\indian horoscope 1.0.0.0.zip.vir/install_crack.exe deleted 04/01/2009 10:10:50 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\irep 2.5.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:52 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\irep 2.5.zip.vir/keygen.exe deleted 04/01/2009 10:10:55 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\itunes alarm clock 2.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:10:57 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\itunes alarm clock 2.0.zip.vir/setup.exe deleted 04/01/2009 10:10:59 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\jamdat.mobile.tetris.marathon.v1.8.16.s60.j2me.retail-daddyfatsax.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:03 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\jamdat.mobile.tetris.marathon.v1.8.16.s60.j2me.retail-daddyfatsax.zip.vir/run.exe deleted 04/01/2009 10:11:10 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\jame 6.0.1.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:13 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\jame 6.0.1.zip.vir/install_crack.exe deleted 04/01/2009 10:11:15 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\jvw filter email 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:18 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\jvw filter email 1.0.zip.vir/install_crack.exe deleted 04/01/2009 10:11:21 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ka log analyzer 1.65.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:22 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ka log analyzer 1.65.zip.vir/crac.exe deleted 04/01/2009 10:11:23 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\kingconvert for samsung e768 4.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:25 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\kingconvert for samsung e768 4.0.zip.vir/run.exe deleted 04/01/2009 10:11:27 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ldapsearcher 1.1.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:28 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\ldapsearcher 1.1.zip.vir/install_patch.exe deleted 04/01/2009 10:11:29 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\lomsel shutdown 1.04.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:30 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\lomsel shutdown 1.04.zip.vir/crac.exe deleted 04/01/2009 10:11:32 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\m3u creator 1.0.1.4.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:32 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\m3u creator 1.0.1.4.zip.vir/run.exe deleted 04/01/2009 10:11:33 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\mini log book 1.0.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:36 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\mini log book 1.0.zip.vir/serial.exe deleted 04/01/2009 10:11:43 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\mnogosearch for windows pro oracle edition pro 3.2.40.1.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:46 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\mnogosearch for windows pro oracle edition pro 3.2.40.1.zip.vir/setup.exe deleted 04/01/2009 10:11:48 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\moonsked 1.4.7.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:48 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\moonsked 1.4.7.zip.vir/serial.exe deleted 04/01/2009 10:11:50 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\my auction search browser for ebay 2.2.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:51 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\my auction search browser for ebay 2.2.0.zip.vir/install.exe deleted 04/01/2009 10:11:52 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\myphone book dialer 8.1.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:53 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\myphone book dialer 8.1.0.zip.vir/install.exe deleted 04/01/2009 10:11:54 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\news talk zb 1.0.0.0.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:56 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\news talk zb 1.0.0.0.zip.vir/keygen.exe deleted 04/01/2009 10:11:58 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\nod32_v2+manual+plugin+(crack_de_por_vida)(espaã±ol-spanish)por_borracho.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:11:58 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\nod32_v2+manual+plugin+(crack_de_por_vida)(espaã±ol-spanish)por_borracho.zip.vir/key_generator.exe deleted 04/01/2009 10:11:59 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\norton antivirus and internet security livesubscribe crack (extends subscription to 8-20-2116).zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:00 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\norton antivirus and internet security livesubscribe crack (extends subscription to 8-20-2116).zip.vir/run.exe deleted 04/01/2009 10:12:01 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\offline explorer pro 5.2.2878 service release 1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:03 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\offline explorer pro 5.2.2878 service release 1.zip.vir/install.exe deleted 04/01/2009 10:12:04 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\omega constellation screen saver.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:08 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\omega constellation screen saver.zip.vir/install_crack.exe deleted 04/01/2009 10:12:19 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\paintfx 1.01.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:20 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\paintfx 1.01.zip.vir/key_generator.exe deleted 04/01/2009 10:12:21 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\pamela for skype professional version 1.36.zip.vir/serial.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:21 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\pamela for skype professional version 1.36.zip.vir/serial.exe deleted 04/01/2009 10:12:22 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\pauseprocess 1.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:24 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\pauseprocess 1.0.zip.vir/setup.exe deleted 04/01/2009 10:12:25 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\pdf password remover 3.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:28 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\pdf password remover 3.0.zip.vir/crac.exe deleted 04/01/2009 10:12:31 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\picture spyglass rev 4.0.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:31 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\picture spyglass rev 4.0.zip.vir/install_patch.exe deleted 04/01/2009 10:12:32 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\plotlab .net 3.1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:33 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\plotlab .net 3.1.zip.vir/keygen.exe deleted 04/01/2009 10:12:35 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\popupalert 2.02.0086.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:37 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\popupalert 2.02.0086.zip.vir/key_generator.exe deleted 04/01/2009 10:12:38 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\printcontroller 2.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:41 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\printcontroller 2.0.zip.vir/patch.exe deleted 04/01/2009 10:12:43 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\profile picture genius 1.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:44 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\profile picture genius 1.0.zip.vir/crac.exe deleted 04/01/2009 10:12:45 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\quick install maker 2.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:47 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\quick install maker 2.0.zip.vir/run.exe deleted 04/01/2009 10:12:49 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\r color code 1.0.zip.vir/install_crack.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:50 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\r color code 1.0.zip.vir/install_crack.exe deleted 04/01/2009 10:12:51 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\randback32 1.00.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:12:55 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\randback32 1.00.zip.vir/keygen.exe deleted 04/01/2009 10:13:06 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\real-time rendering.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:07 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\real-time rendering.zip.vir/install_patch.exe deleted 04/01/2009 10:13:11 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\registry workshop 4.0.1.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:12 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\registry workshop 4.0.1.zip.vir/install.exe deleted 04/01/2009 10:13:13 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\rrs plugin for lcdc 1.4a.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:15 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\rrs plugin for lcdc 1.4a.zip.vir/setup.exe deleted 04/01/2009 10:13:17 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\sc dvd ripper 1.0.0.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:18 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\sc dvd ripper 1.0.0.0.zip.vir/run.exe deleted 04/01/2009 10:13:19 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\serial port splitter 3.8.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:22 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\serial port splitter 3.8.2.zip.vir/key_generator.exe deleted 04/01/2009 10:13:24 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\sfbemailverifier 1.3.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:25 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\sfbemailverifier 1.3.zip.vir/key_generator.exe deleted 04/01/2009 10:13:27 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\shell-and-tube heat exchanger 1.1.0.0.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:29 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\shell-and-tube heat exchanger 1.1.0.0.zip.vir/run.exe deleted 04/01/2009 10:13:31 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\site coder 2.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:33 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\site coder 2.zip.vir/key_gen.exe deleted 04/01/2009 10:13:35 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\skater .net obfuscator freeware light 2.60.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:43 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\skater .net obfuscator freeware light 2.60.zip.vir/key_generator.exe deleted 04/01/2009 10:13:46 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\slovoed classic english-german 6.4.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:47 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\slovoed classic english-german 6.4.zip.vir/keygen.exe deleted 04/01/2009 10:13:49 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\smartermail free edition 5.5.3126.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:50 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\smartermail free edition 5.5.3126.zip.vir/crac.exe deleted 04/01/2009 10:13:52 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\sql help builder 2.03.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:54 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\sql help builder 2.03.zip.vir/patch.exe deleted 04/01/2009 10:13:56 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\stereoscope theatre love & romance 1.0.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:13:58 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\stereoscope theatre love & romance 1.0.zip.vir/crac.exe deleted 04/01/2009 10:14:00 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\svg link agent 1.3.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:03 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\svg link agent 1.3.zip.vir/install_patch.exe deleted 04/01/2009 10:14:11 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\symantec.antivirus.corporate.server.edition.v8.1.0.825.retail-shock.shareconnector.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:11 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\symantec.antivirus.corporate.server.edition.v8.1.0.825.retail-shock.shareconnector.zip.vir/crac.exe deleted 04/01/2009 10:14:13 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\system information 1.0.zip.vir/install.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:14 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\system information 1.0.zip.vir/install.exe deleted 04/01/2009 10:14:16 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\talking alphabet 2.0.2.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:16 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\talking alphabet 2.0.2.zip.vir/key_generator.exe deleted 04/01/2009 10:14:17 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\thumbplus activex control 5.0.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:21 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\thumbplus activex control 5.0.zip.vir/patch.exe deleted 04/01/2009 10:14:23 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\tomtom navigator 6v para pocket pc nokia 6280.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:25 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\tomtom navigator 6v para pocket pc nokia 6280.zip.vir/install_patch.exe deleted 04/01/2009 10:14:27 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\trackless 1.03.zip.vir/crac.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:28 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\trackless 1.03.zip.vir/crac.exe deleted 04/01/2009 10:14:29 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\tvants 1.0.0.59 build 0834.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:32 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\tvants 1.0.0.59 build 0834.zip.vir/key_generator.exe deleted 04/01/2009 10:14:40 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\universal project manager enterprise 1.1.zip.vir/key_gen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:40 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\universal project manager enterprise 1.1.zip.vir/key_gen.exe deleted 04/01/2009 10:14:41 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\universal video converter 6.0.2.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:43 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\universal video converter 6.0.2.zip.vir/setup.exe deleted 04/01/2009 10:14:45 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\vextractor 4.20.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:47 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\vextractor 4.20.zip.vir/run.exe deleted 04/01/2009 10:14:50 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\vox box 1.zip.vir/keygen.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:52 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\vox box 1.zip.vir/keygen.exe deleted 04/01/2009 10:14:54 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\wallman 1.0.zip.vir/setup.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:55 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\wallman 1.0.zip.vir/setup.exe deleted 04/01/2009 10:14:57 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\wincomm 2.03.zip.vir/install_patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:14:57 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\wincomm 2.03.zip.vir/install_patch.exe deleted 04/01/2009 10:14:59 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\wine organizer 3.6a.zip.vir/patch.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:15:00 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\wine organizer 3.6a.zip.vir/patch.exe deleted 04/01/2009 10:15:01 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\wty-dtt 0.9.5 beta.zip.vir/key_generator.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:15:02 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\wty-dtt 0.9.5 beta.zip.vir/key_generator.exe deleted 04/01/2009 10:15:10 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\zipsize 0.2.2.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:15:12 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\zipsize 0.2.2.zip.vir/run.exe deleted 04/01/2009 10:15:14 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\[app-ita].ewido.security.suite.v3.5.plus.zip.vir/run.exe detected Trojan program 'Trojan-Downloader.Win32.Bagle.ajn' 04/01/2009 10:15:15 File: c:\qoobox\quarantine\c\documents and settings\romestan\application data\m\shared\[app-ita].ewido.security.suite.v3.5.plus.zip.vir/run.exe deleted Statistics ---------- Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted ------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ --------- All objects 177132 131 131 0 0 5782 2590 545 6 System memory 779 0 0 0 0 0 3 0 0 Startup objects 807 0 0 0 0 2 36 0 0 Disk boot sectors 2 0 0 0 0 0 0 0 0 Mes documents 4530 0 0 0 0 163 49 52 0 Mail databases 2635 0 0 0 0 965 7 0 0 Poste de travail 168379 131 131 0 0 4652 2495 493 6 HDD (C:) 0 0 0 0 0 0 0 0 0 Settings -------- Parameter Value --------- ----- Security Level Recommended Action Prompt for action when the scan is complete Run mode Manually File types Scan all files Scan only new and changed files No Scan archives All Scan embedded OLE objects All Skip if object is larger than No Skip if scan takes longer than No Parse email formats No Scan password-protected archives No Enable iChecker technology No Enable iSwift technology No Show detected threats on "Detected" tab Yes Rootkits search Yes Deep rootkits search No Use heuristic analyzer Yes Quarantine ---------- Status Object Size Added ------ ------ ---- ----- Backup ------ Status Object Size ------ ------ ---- Merci pour votre analyse
  4. Bonjour, j'ai démarré le scan avec kaspersky mais il a progressé de 10 % en 2 heures. Est-ce que c'est normal ? je continue ou il y a un problème ? merci
  5. Désolée, je pensais apporter mon aide, et n'avais pas l'intention de vous outrepasser. Pouvez-vous poursuivre votre diagnostic ?
  6. bonjour, en attendant votre réponse hier je me suis permise de passer mon ordi à l'analyse de Elibagla (en mode sans echec + normal) qui a décontaminé 9 fichiers infectés par Bagle. Ensuite j'ai passé aussi Dt Web qui n'a rien trouvé bien sûr. Par acquis de conscience voici un rapport Hijakthis, pouvez vous me dire si tout va bien ? D'autre part, je souhaiterai nettoyer un peu le Pc des restes inutiles de programmes désinstallés, les clés de registre etc... mais je sais que c'est un peu compliqué, pouvez-vous m'aider ? Merci beaucoup. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:19:11, on 02/01/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\WINDOWS\system32\igfxtray.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\devldr32.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Documents and Settings\romestan\Local Settings\Temporary Internet Files\Content.IE5\1XJQAT3R\HiJackThis[1].exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/fichier...ion_3_0_4_0.cab O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/a...gnerADP-1.1.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.1.6.cab O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 7653 bytes
  7. Merci pour votre réponse rapide, voici donc le rapport de Combofix : ComboFix 08-12-31.01 - romestan 2009-01-01 21:25:02.1 - NTFSx86 Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.759.597 [GMT 1:00] Lancé depuis: c:\documents and settings\romestan\Bureau\romes.exe * Un nouveau point de restauration a été créé . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\romestan\Application Data\drivers\downld c:\documents and settings\romestan\Application Data\drivers\downld\107781.exe c:\documents and settings\romestan\Application Data\drivers\downld\108640.exe c:\documents and settings\romestan\Application Data\drivers\downld\108984.exe c:\documents and settings\romestan\Application Data\drivers\downld\1565765.exe c:\documents and settings\romestan\Application Data\drivers\downld\1582109.exe c:\documents and settings\romestan\Application Data\drivers\downld\1582250.exe c:\documents and settings\romestan\Application Data\drivers\downld\1591828.exe c:\documents and settings\romestan\Application Data\drivers\downld\1699500.exe c:\documents and settings\romestan\Application Data\drivers\downld\1702671.exe c:\documents and settings\romestan\Application Data\drivers\downld\1703187.exe c:\documents and settings\romestan\Application Data\drivers\downld\182140.exe c:\documents and settings\romestan\Application Data\drivers\downld\1852046.exe c:\documents and settings\romestan\Application Data\drivers\downld\189656.exe c:\documents and settings\romestan\Application Data\drivers\downld\189671.exe c:\documents and settings\romestan\Application Data\drivers\downld\1911937.exe c:\documents and settings\romestan\Application Data\drivers\downld\1913250.exe c:\documents and settings\romestan\Application Data\drivers\downld\1913375.exe c:\documents and settings\romestan\Application Data\drivers\downld\1933546.exe c:\documents and settings\romestan\Application Data\drivers\downld\1935031.exe c:\documents and settings\romestan\Application Data\drivers\downld\1935734.exe c:\documents and settings\romestan\Application Data\drivers\downld\1937343.exe c:\documents and settings\romestan\Application Data\drivers\downld\1938421.exe c:\documents and settings\romestan\Application Data\drivers\downld\1938953.exe c:\documents and settings\romestan\Application Data\drivers\downld\1967562.exe c:\documents and settings\romestan\Application Data\drivers\downld\1968515.exe c:\documents and settings\romestan\Application Data\drivers\downld\1969015.exe c:\documents and settings\romestan\Application Data\drivers\downld\1983546.exe c:\documents and settings\romestan\Application Data\drivers\downld\1985796.exe c:\documents and settings\romestan\Application Data\drivers\downld\1986921.exe c:\documents and settings\romestan\Application Data\drivers\downld\2050406.exe c:\documents and settings\romestan\Application Data\drivers\downld\2052359.exe c:\documents and settings\romestan\Application Data\drivers\downld\2052578.exe c:\documents and settings\romestan\Application Data\drivers\downld\246093.exe c:\documents and settings\romestan\Application Data\drivers\downld\296625.exe c:\documents and settings\romestan\Application Data\drivers\downld\298828.exe c:\documents and settings\romestan\Application Data\drivers\downld\298921.exe c:\documents and settings\romestan\Application Data\drivers\downld\317312.exe c:\documents and settings\romestan\Application Data\drivers\downld\319859.exe c:\documents and settings\romestan\Application Data\drivers\downld\320515.exe c:\documents and settings\romestan\Application Data\drivers\downld\321843.exe c:\documents and settings\romestan\Application Data\drivers\downld\323093.exe c:\documents and settings\romestan\Application Data\drivers\downld\323750.exe c:\documents and settings\romestan\Application Data\drivers\downld\350203.exe c:\documents and settings\romestan\Application Data\drivers\downld\351312.exe c:\documents and settings\romestan\Application Data\drivers\downld\351656.exe c:\documents and settings\romestan\Application Data\drivers\downld\364031.exe c:\documents and settings\romestan\Application Data\drivers\downld\364828.exe c:\documents and settings\romestan\Application Data\drivers\downld\365281.exe c:\documents and settings\romestan\Application Data\drivers\downld\386875.exe c:\documents and settings\romestan\Application Data\drivers\downld\406187.exe c:\documents and settings\romestan\Application Data\drivers\downld\407468.exe c:\documents and settings\romestan\Application Data\drivers\downld\407921.exe c:\documents and settings\romestan\Application Data\drivers\downld\577468.exe c:\documents and settings\romestan\Application Data\drivers\downld\581187.exe c:\documents and settings\romestan\Application Data\drivers\downld\581203.exe c:\documents and settings\romestan\Application Data\drivers\downld\586093.exe c:\documents and settings\romestan\Application Data\drivers\downld\609734.exe c:\documents and settings\romestan\Application Data\drivers\downld\610562.exe c:\documents and settings\romestan\Application Data\drivers\downld\610890.exe c:\documents and settings\romestan\Application Data\drivers\downld\74203.exe c:\documents and settings\romestan\Application Data\drivers\downld\745796.exe c:\documents and settings\romestan\Application Data\drivers\downld\79593.exe c:\documents and settings\romestan\Application Data\drivers\downld\808171.exe c:\documents and settings\romestan\Application Data\drivers\downld\808890.exe c:\documents and settings\romestan\Application Data\drivers\downld\808984.exe c:\documents and settings\romestan\Application Data\drivers\downld\825875.exe c:\documents and settings\romestan\Application Data\drivers\downld\827265.exe c:\documents and settings\romestan\Application Data\drivers\downld\828046.exe c:\documents and settings\romestan\Application Data\drivers\downld\830593.exe c:\documents and settings\romestan\Application Data\drivers\downld\832015.exe c:\documents and settings\romestan\Application Data\drivers\downld\832828.exe c:\documents and settings\romestan\Application Data\drivers\downld\85171.exe c:\documents and settings\romestan\Application Data\drivers\downld\861843.exe c:\documents and settings\romestan\Application Data\drivers\downld\863734.exe c:\documents and settings\romestan\Application Data\drivers\downld\864187.exe c:\documents and settings\romestan\Application Data\drivers\downld\877906.exe c:\documents and settings\romestan\Application Data\drivers\downld\878750.exe c:\documents and settings\romestan\Application Data\drivers\downld\879203.exe c:\documents and settings\romestan\Application Data\drivers\downld\903578.exe c:\documents and settings\romestan\Application Data\drivers\downld\969265.exe c:\documents and settings\romestan\Application Data\drivers\downld\969765.exe c:\documents and settings\romestan\Application Data\drivers\downld\969906.exe c:\documents and settings\romestan\Application Data\drivers\srosa.sys c:\documents and settings\romestan\Application Data\drivers\srosa2.sys c:\documents and settings\romestan\Application Data\drivers\winupgro.exe c:\documents and settings\romestan\Application Data\m c:\documents and settings\romestan\Application Data\m\data.oct c:\documents and settings\romestan\Application Data\m\flec006.exe c:\documents and settings\romestan\Application Data\m\list.oct c:\documents and settings\romestan\Application Data\m\shared\(Serial).Symantec.Livestate.Recovery.6.0.zip c:\documents and settings\romestan\Application Data\m\shared\[APP-ITA].Ewido.Security.Suite.v3.5.Plus.zip c:\documents and settings\romestan\Application Data\m\shared\32bit Email Broadcaster 08.11.17.zip c:\documents and settings\romestan\Application Data\m\shared\A123 AVI MPEG WMV ASF MOV FLV to Zune Converter 4.0.zip c:\documents and settings\romestan\Application Data\m\shared\Ace DVD Backup 1.3.32.zip c:\documents and settings\romestan\Application Data\m\shared\AdvaSaR Ed 5.04.zip c:\documents and settings\romestan\Application Data\m\shared\Aimersoft DVD to 3GP Converter 1.1.62.zip c:\documents and settings\romestan\Application Data\m\shared\Ali Landry 33 Screensaver 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\ASP.NET Image Gallery 1.1.zip c:\documents and settings\romestan\Application Data\m\shared\ATnotes 9.5.zip c:\documents and settings\romestan\Application Data\m\shared\AudioManage 2.10.zip c:\documents and settings\romestan\Application Data\m\shared\AutoQ2 1.0.9.9r3.zip c:\documents and settings\romestan\Application Data\m\shared\AVAST.4.6.PRO+KEY+TESTED.zip c:\documents and settings\romestan\Application Data\m\shared\Azureus Turbo Accelerator 2.7.0.zip c:\documents and settings\romestan\Application Data\m\shared\Babysitter Services Finder 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\Be Mine Screensaver 2.0.zip c:\documents and settings\romestan\Application Data\m\shared\Beach Cams PT 0.2.zip c:\documents and settings\romestan\Application Data\m\shared\Biometric HP Manager Enterprise 6.12.44.zip c:\documents and settings\romestan\Application Data\m\shared\Bitdefender Free Antivir Software.zip c:\documents and settings\romestan\Application Data\m\shared\Blade Runner Font 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\CadLib 3.5.zip c:\documents and settings\romestan\Application Data\m\shared\CCNA FlashCards 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\Citrix 1Y0-991 Practice Exam Test Questions.zip c:\documents and settings\romestan\Application Data\m\shared\Claymore Time Sheets 2005 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\CodeWorker 4.5.1.zip c:\documents and settings\romestan\Application Data\m\shared\Convert Image 1.96.zip c:\documents and settings\romestan\Application Data\m\shared\CryptaFlix 1.11.zip c:\documents and settings\romestan\Application Data\m\shared\DDObjects 0.9.95.zip c:\documents and settings\romestan\Application Data\m\shared\DeepForm 1.1.1.zip c:\documents and settings\romestan\Application Data\m\shared\Desktop Fay 2.8.zip c:\documents and settings\romestan\Application Data\m\shared\DiskSurvey 1.0.5.zip c:\documents and settings\romestan\Application Data\m\shared\Domeru DVD to iPod Converter 3.6.zip c:\documents and settings\romestan\Application Data\m\shared\Don's Alarm Clock 1.1.zip c:\documents and settings\romestan\Application Data\m\shared\Drag to MP3 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\Dragonfly Attack Screensaver.zip c:\documents and settings\romestan\Application Data\m\shared\Duplicate DLL File Finder Software 7.0.zip c:\documents and settings\romestan\Application Data\m\shared\e!Sankey 1.3.0.324.zip c:\documents and settings\romestan\Application Data\m\shared\Easy Peasy Passwords 2.3.1.17.zip c:\documents and settings\romestan\Application Data\m\shared\Elecard Codec .NET SDK G4 1.1.80717.zip c:\documents and settings\romestan\Application Data\m\shared\entOnly.zip c:\documents and settings\romestan\Application Data\m\shared\EVE Online Images Widget 1.1.zip c:\documents and settings\romestan\Application Data\m\shared\Event Engineer 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\Execute This! 1.3.0.zip c:\documents and settings\romestan\Application Data\m\shared\EZ Contract Proposal 2.3.0.zip c:\documents and settings\romestan\Application Data\m\shared\FeedStation 2.0 beta2.zip c:\documents and settings\romestan\Application Data\m\shared\Filo 2.0.zip c:\documents and settings\romestan\Application Data\m\shared\FireCode 2004 1.00.zip c:\documents and settings\romestan\Application Data\m\shared\First Radio 89.1FM Israel 3.0.zip c:\documents and settings\romestan\Application Data\m\shared\Flawless Makeup Tips 3.0.zip c:\documents and settings\romestan\Application Data\m\shared\foo vis flame 0.93.zip c:\documents and settings\romestan\Application Data\m\shared\Geforce Tweak Utility 3.2.zip c:\documents and settings\romestan\Application Data\m\shared\GEODisk 3.3.4.zip c:\documents and settings\romestan\Application Data\m\shared\GoodOK MP4 Converter 5.3.zip c:\documents and settings\romestan\Application Data\m\shared\Guitar Ensemble 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\GZ Calendar 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\Hilary Duff Screensaver1.zip c:\documents and settings\romestan\Application Data\m\shared\HMView 4.04.zip c:\documents and settings\romestan\Application Data\m\shared\HoursClocked-Basic 001-004-002.zip c:\documents and settings\romestan\Application Data\m\shared\HTML-Handler for Eudora 3.1.zip c:\documents and settings\romestan\Application Data\m\shared\HTML to Flash Password 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\HTPT Console 2.06.zip c:\documents and settings\romestan\Application Data\m\shared\Icesun Audio Converter 2.00.zip c:\documents and settings\romestan\Application Data\m\shared\Image++ 2.1.zip c:\documents and settings\romestan\Application Data\m\shared\Indian HoroScope 1.0.0.0.zip c:\documents and settings\romestan\Application Data\m\shared\iRep 2.5.zip c:\documents and settings\romestan\Application Data\m\shared\iTunes Alarm Clock 2.0.zip c:\documents and settings\romestan\Application Data\m\shared\JAMDAT.Mobile.Tetris.Marathon.v1.8.16.S60.J2ME.Retail-daddyfatsax.zip c:\documents and settings\romestan\Application Data\m\shared\JAME 6.0.1.zip c:\documents and settings\romestan\Application Data\m\shared\Jvw filter email 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\Ka Log Analyzer 1.65.zip c:\documents and settings\romestan\Application Data\m\shared\KingConvert For SamSung E768 4.0.zip c:\documents and settings\romestan\Application Data\m\shared\LDAPsearcher 1.1.zip c:\documents and settings\romestan\Application Data\m\shared\Lomsel Shutdown 1.04.zip c:\documents and settings\romestan\Application Data\m\shared\M3U Creator 1.0.1.4.zip c:\documents and settings\romestan\Application Data\m\shared\Mini Log Book 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\mnoGoSearch for Windows Pro Oracle Edition Pro 3.2.40.1.zip c:\documents and settings\romestan\Application Data\m\shared\MoonSked 1.4.7.zip c:\documents and settings\romestan\Application Data\m\shared\My Auction Search Browser for eBay 2.2.0.zip c:\documents and settings\romestan\Application Data\m\shared\MyPhone Book Dialer 8.1.0.zip c:\documents and settings\romestan\Application Data\m\shared\News Talk ZB 1.0.0.0.zip c:\documents and settings\romestan\Application Data\m\shared\Nod32_v2+manual+plugin+(crack_de_por_vida)(español-spanish)por_borracho.zip c:\documents and settings\romestan\Application Data\m\shared\Norton AntiVirus and Internet Security LiveSubscribe Crack (Extends Subscription to 8-20-2116).zip c:\documents and settings\romestan\Application Data\m\shared\Offline Explorer Pro 5.2.2878 Service Release 1.zip c:\documents and settings\romestan\Application Data\m\shared\Omega Constellation Screen Saver.zip c:\documents and settings\romestan\Application Data\m\shared\PaintFX 1.01.zip c:\documents and settings\romestan\Application Data\m\shared\Pamela for Skype Professional Version 1.36.zip c:\documents and settings\romestan\Application Data\m\shared\PauseProcess 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\PDF Password Remover 3.0.zip c:\documents and settings\romestan\Application Data\m\shared\Picture Spyglass Rev 4.0.zip c:\documents and settings\romestan\Application Data\m\shared\PlotLab .NET 3.1.zip c:\documents and settings\romestan\Application Data\m\shared\PopupAlert 2.02.0086.zip c:\documents and settings\romestan\Application Data\m\shared\PrintController 2.0.zip c:\documents and settings\romestan\Application Data\m\shared\Profile Picture Genius 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\Quick Install Maker 2.0.zip c:\documents and settings\romestan\Application Data\m\shared\R Color Code 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\RandBack32 1.00.zip c:\documents and settings\romestan\Application Data\m\shared\Real-Time Rendering.zip c:\documents and settings\romestan\Application Data\m\shared\Registry Workshop 4.0.1.zip c:\documents and settings\romestan\Application Data\m\shared\RRS plugin for LCDC 1.4a.zip c:\documents and settings\romestan\Application Data\m\shared\SC DVD Ripper 1.0.0.0.zip c:\documents and settings\romestan\Application Data\m\shared\Serial Port Splitter 3.8.2.zip c:\documents and settings\romestan\Application Data\m\shared\SfbEmailVerifier 1.3.zip c:\documents and settings\romestan\Application Data\m\shared\Shell-and-Tube Heat Exchanger 1.1.0.0.zip c:\documents and settings\romestan\Application Data\m\shared\Site Coder 2.zip c:\documents and settings\romestan\Application Data\m\shared\Skater .NET Obfuscator Freeware Light 2.60.zip c:\documents and settings\romestan\Application Data\m\shared\SlovoEd Classic English-German 6.4.zip c:\documents and settings\romestan\Application Data\m\shared\SmarterMail Free Edition 5.5.3126.zip c:\documents and settings\romestan\Application Data\m\shared\SQL Help Builder 2.03.zip c:\documents and settings\romestan\Application Data\m\shared\Stereoscope Theatre Love & Romance 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\SVG Link Agent 1.3.zip c:\documents and settings\romestan\Application Data\m\shared\Symantec.Antivirus.Corporate.Server.Edition.v8.1.0.825.Retail-SHOCK.ShareConnector.zip c:\documents and settings\romestan\Application Data\m\shared\System Information 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\Talking Alphabet 2.0.2.zip c:\documents and settings\romestan\Application Data\m\shared\ThumbPlus ActiveX Control 5.0.zip c:\documents and settings\romestan\Application Data\m\shared\Tomtom Navigator 6V Para Pocket Pc Nokia 6280.zip c:\documents and settings\romestan\Application Data\m\shared\Trackless 1.03.zip c:\documents and settings\romestan\Application Data\m\shared\TVants 1.0.0.59 Build 0834.zip c:\documents and settings\romestan\Application Data\m\shared\Universal Project Manager Enterprise 1.1.zip c:\documents and settings\romestan\Application Data\m\shared\Universal Video Converter 6.0.2.zip c:\documents and settings\romestan\Application Data\m\shared\Vextractor 4.20.zip c:\documents and settings\romestan\Application Data\m\shared\Vox Box 1.zip c:\documents and settings\romestan\Application Data\m\shared\WallMan 1.0.zip c:\documents and settings\romestan\Application Data\m\shared\WinComm 2.03.zip c:\documents and settings\romestan\Application Data\m\shared\Wine Organizer 3.6a.zip c:\documents and settings\romestan\Application Data\m\shared\WTY-DTT 0.9.5 Beta.zip c:\documents and settings\romestan\Application Data\m\shared\Zipsize 0.2.2.zip c:\documents and settings\romestan\Application Data\m\srvlist.oct c:\program files\autorun.inf c:\program files\Softwin\BitDefender10\bdmcon.exe c:\windows\IE4 Error Log.txt c:\windows\system32\ban_list.txt c:\windows\system32\mdelk.exe c:\windows\system32\wintems.exe . ((((((((((((((((((((((((((((((((((((((( Pilotes/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_SROSA -------\Legacy_SROSA ((((((((((((((((((((((((((((( Fichiers créés du 2008-12-01 au 2009-01-01 )))))))))))))))))))))))))))))))))))) . 2009-01-01 19:02 . 2009-01-01 21:22 54,156 --ah----- c:\windows\QTFont.qfn 2009-01-01 19:02 . 2009-01-01 21:22 1,409 --a------ c:\windows\QTFont.for 2008-12-31 18:31 . 2008-12-31 18:31 <REP> d-------- c:\program files\Panda Security 2008-12-31 17:04 . 2008-12-31 17:04 10 --a------ c:\windows\bdinit.ini 2008-12-31 16:43 . 2009-01-01 21:27 <REP> d--h----- c:\documents and settings\romestan\Application Data\drivers 2008-12-31 16:11 . 1999-03-13 21:57 829,440 --a------ c:\windows\system32\MMAudioX.OCX 2008-12-31 16:11 . 1999-03-13 14:09 286,720 --a------ c:\windows\system32\MMTypesX.OCX 2008-12-31 16:11 . 2000-10-02 00:00 119,568 --a------ c:\windows\system32\VB6FR.DLL 2008-12-31 16:11 . 1997-11-06 13:28 71,702 --a------ c:\windows\system32\SLIDER.hlp 2008-12-31 16:11 . 1999-05-18 17:21 63,408 --a------ c:\windows\system32\HSLIDE32.OCX 2008-12-31 16:11 . 1999-05-18 17:21 62,896 --a------ c:\windows\system32\VSLIDE32.OCX 2008-12-31 16:11 . 1998-09-23 03:07 61,952 --a------ c:\windows\system32\MMRegOCX.EXE 2008-12-31 16:11 . 1998-09-23 02:38 37,376 --a------ c:\windows\system32\Axdist.exe 2008-12-31 16:11 . 2002-01-12 21:52 36,864 --a------ c:\windows\system32\VolumeControl.ocx 2008-12-31 16:11 . 1998-07-13 00:00 32,768 --a------ c:\windows\system32\CmDlgFR.dll 2008-12-31 16:11 . 2001-08-01 20:23 794 --a------ c:\windows\system32\MMAudioX.lic 2008-12-31 16:11 . 1996-04-01 20:08 422 --a------ c:\windows\system32\Slider.lic 2008-12-31 16:04 . 1998-10-01 15:21 24,064 --a------ c:\program files\UNSTUB.EXE 2008-12-31 16:04 . 1998-10-01 15:22 11,264 --a------ c:\program files\_SETUP.DLL 2008-12-31 16:04 . 1998-10-01 15:20 8,192 --a------ c:\program files\_ISDEL.EXE 2008-12-28 14:00 . 2008-12-28 14:07 <REP> d-------- c:\documents and settings\Elisa Lucie Emma\Application Data\Bella Sara 2008-12-27 17:25 . 2008-12-27 17:26 <REP> d-------- c:\program files\Windows Media Connect 2 2008-12-27 17:11 . 2008-12-27 17:11 <REP> d-------- c:\windows\system32\LogFiles 2008-12-27 17:11 . 2008-12-27 17:15 <REP> d-------- c:\windows\system32\drivers\UMDF 2008-12-27 10:31 . 2002-08-30 12:00 115,200 --a------ c:\windows\system32\dllcache\calc.exe 2008-12-26 18:21 . 2008-12-29 18:08 <REP> d-------- c:\documents and settings\romestan\Application Data\Bella Sara 2008-12-26 18:17 . 2008-12-26 18:17 <REP> d-------- c:\program files\Codemasters 2008-12-13 11:55 . 2008-12-13 11:55 27,024 --a------ c:\documents and settings\Elisa Lucie Emma\Application Data\GDIPFONTCACHEV1.DAT 2008-12-12 19:15 . 2008-12-12 19:15 <REP> d-------- C:\TLCWIN . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-31 17:10 --------- d-----w c:\program files\Fichiers communs\Softwin 2008-12-31 15:48 81,984 ----a-w c:\windows\system32\bdod.bin 2008-12-31 15:45 --------- d-----w c:\program files\eMule 2008-12-23 08:45 --------- d-----w c:\documents and settings\romestan\Application Data\uTorrent 2008-12-13 06:37 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll 2008-12-08 17:12 27,024 ----a-w c:\documents and settings\romestan\Application Data\GDIPFONTCACHEV1.DAT 2008-11-30 17:34 --------- d-----w c:\program files\Mindscape 2008-11-30 17:31 --------- d--h--w c:\program files\InstallShield Installation Information 2008-11-29 11:28 --------- d-----w c:\program files\Hachette Multimédia 2008-11-24 16:46 --------- d-----w c:\program files\bayardKids 2008-11-24 16:44 --------- d-----w c:\program files\Fichiers communs\Adobe AIR 2008-11-21 10:05 --------- d-----w c:\documents and settings\Elisa Lucie Emma\Application Data\bayardKids.08AE7BFC096D057FBA48C7E4F898C35F7FA11BBA.1 2008-11-21 08:56 --------- d-----w c:\documents and settings\Elisa Lucie Emma\Application Data\Bitdefender 2008-11-19 11:11 --------- d-----w c:\program files\Fichiers communs\InstallShield 2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys 2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll 2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll 2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll 2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll 2008-10-16 13:12 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe 2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll 2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll 2008-10-16 13:11 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe 2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll 2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe 2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll 2008-10-15 07:06 633,632 ------w c:\windows\system32\dllcache\iexplore.exe 2008-10-15 07:04 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll 2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll 2008-10-03 10:03 247,326 ------w c:\windows\system32\dllcache\strmdll.dll 2005-04-05 12:46 700,978 ----a-w c:\program files\Setup.exe 2005-03-31 14:07 537,933 -c--a-w c:\program files\start.dir 2005-03-21 14:01 0 -c--a-w c:\program files\abb3e 2004-01-05 11:11 946 ----a-w c:\program files\SETUP.PDF 2004-01-05 11:11 664 ----a-w c:\program files\SETUP.PKG 2004-01-05 11:11 5,657,144 ----a-w c:\program files\_SETUP.1 2004-01-05 11:11 5 ----a-w c:\program files\DISK1.ID 2004-01-05 11:11 41 ----a-w c:\program files\SETUP.INI 2004-01-05 11:11 385 ----a-w c:\program files\SETUP.ISS 2004-01-05 11:11 208,265 ----a-w c:\program files\_SETUP.LIB 1998-11-12 15:49 70,547 ----a-w c:\program files\SETUP.INS 1998-10-01 14:20 320,411 ----a-w c:\program files\_INST32I.EX_ 2008-04-14 02:33 617,472 --sha-w c:\windows\system32\comctl32.dll 2008-04-14 02:33 1,028,096 --sha-w c:\windows\system32\mfc42.dll 2002-08-30 11:00 57,344 --sha-w c:\windows\system32\mfc42loc.dll 2008-04-14 02:33 413,696 --sha-w c:\windows\system32\msvcp60.dll 2002-08-30 11:00 253,952 -csha-w c:\windows\system32\msvcrt20.dll 2008-04-14 02:33 30,749 --sha-w c:\windows\system32\vbajet32.dll 2008-08-05 10:57 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008080520080806\index.dat . ((((((((((((((((((((((((((((((((( Points de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976] "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-12-31 185896] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648] "BDAgent"="c:\program files\Softwin\BitDefender10\bdagent.exe" [2009-01-01 69632] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-07-14 77824] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "GrpConv"="grpconv -o" [X] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"= ctwdm32.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] ---hs---- 2008-04-14 03:34 1695232 c:\program files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2007-07-14 18:24 77824 c:\program files\QuickTime\qttask.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\utorrent.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\eMule\\emule.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= R3 fbxusb;FreeBox USB Network Adapter;c:\windows\system32\DRIVERS\fbxusb.sys [2007-07-14 18848] R3 STAC97NA;SigmaTel 3D Environmental Audio;c:\windows\system32\drivers\stac97na.sys [1979-12-31 296179] R3 STAC97NH;STAC97NH;c:\windows\system32\drivers\stac97nh.sys [1979-12-31 231983] S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{836cb125-322f-11dc-b534-806d6172696f}] \Shell\AutoRun\command - Q:\autostart.exe . . ------- Examen supplémentaire ------- . uStart Page = hxxp://www.google.fr/ uDefault_Search_URL = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Ajouter au fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convertir en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convertir la cible du lien en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convertir la sélection en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convertir la sélection en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convertir les liens sélectionnés en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_4_0.cab c:\windows\Downloaded Program Files\hardwaredetection.inf c:\windows\system32\msvcp60.dll - c:\windows\system32\atl.dll c:\windows\Downloaded Program Files\AdVerifierADP.dll c:\windows\Downloaded Program Files\AdSignerADP.dll O16 -: {88764F69-3831-4EC1-B40B-FF21D8381345} hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.1.cab c:\windows\Downloaded Program Files\AdSignerADP.inf FF - ProfilePath - . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-01 21:31:30 Windows 5.1.2600 Service Pack 3 NTFS Recherche de processus cachés ... Recherche d'éléments en démarrage automatique cachés ... Recherche de fichiers cachés ... Scan terminé avec succès Fichiers cachés: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\srosa] [HKEY_LOCAL_MACHINE\system\ControlSet003\Services\EverestDriver] "ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt" . --------------------- DLLs chargées dans les processus actifs --------------------- - - - - - - - > 'winlogon.exe'(884) c:\windows\system32\igfxsrvc.dll c:\windows\system32\hccutils.DLL . Heure de fin: 2009-01-01 21:34:17 ComboFix-quarantined-files.txt 2009-01-01 20:33:56 ComboFix2.txt 2007-07-27 20:26:22 Avant-CF: 14,469,197,824 octets libres Après-CF: 14,900,813,824 octets libres 419 --- E O F --- 2008-12-29 02:08:19
  8. Bonjour et d'abord trés bonne année 2009 à tous les connectés...qu'elle vous apporte bonheur et vous epargne la crise ! Moi je démarre mal : je suspecte une infection car : - mon Bit Defender s'est mystérieusement fermé d'un coup, impossible de le démarrer ou le réinstaller. - Je suis parvenue à télécharger hijackthis pour commencer la pré désinfection mais impossible de le lancer, comme tous les autres antivirus que vous proposez d'ailleurs. - mes fênêtres se figent régulièrement. - J'ai essayé le démarrage en mode sans échec mais il n'y parvient pas et redemarre windows normalement. Quid ? merci de votre aide...
  9. -qu'appelles-tu l'antivirus Windows?? One Care?? non : c'est le centre de sécurité avec pare-feu et antivirus -disposes-tu de l'antivirus BitDefender ou de la suite sécurité BitDefender? C'est bit defender V10 plus A+
  10. Bonsoir à tous et surtout trés bonne année pour vous et vos proches... Vous avez déjà résolu pas mal de mes petits bobos infos, et merci encore d'être là. Aujourd'hui je me pose une question de base : j'ai sur mon Pc 3 antivirus : Bit Defender (acheté et tout et tout), Antivir (installé lors de vos manip pour éradiquer un sale virus et qui depuis est resté en résident) et l'antivirus windows. Visiblement ils cohabitent mal mais je ne sais pas lequel garder. en sachant que j'ai un faible pour Antivir qui a été génial lors de la derniere vermifugation du PC ! Vos conseils éclairés ? merci bcp et à bientôt
  11. bonsoir à tous, comme je sais que vous êtes des pros, je suis sûre que vous allez pouvoir me répondre en deux secondes. J'ai ce message d'erreur qui apparait chq fois que je fais Envoyer / recevoir sur Outlook, la connexion est coupée. Impossible de trouver l'hôte pop.free.fr. Vérifiez que vous avez entré correctement le nom du serveur. Compte : , Serveur : 'pop.free.fr', Protocole : POP3, Port : 110, Sécurisé (SSL) : Non, Erreur de socket : 11001, Numéro d'erreur : 0x800CCC0D Qd je débranche ma Freebox 5 fois (pour réinitialiser) ça repart... Avez vous une idée de la manip à faire ?? Merci d'avance
  12. crissou

    rajout barrettes de mémoire

    Et bien bonsoir à tous, et merci pour toutes ces infos, je vais faire le tri. donc sachant que 60 euros ça fait cher, et que je sais bidouiller un peu mon hard, je vais mener l'enquête sur les deux fronts...et vous donnerai le résultat des courses. Sachant aussi que je suis une fille, si je me fais un beau décolleté bronzé, ça peut marcher dans une boutique de pc pour la ristourne ? non parce que sur le marché aux fruits, en provence, ça marche !! on sait jamais... Merci à tous et bonne soirée...
  13. Bonjour à tous, Sur les conseils de Charles Ingals (après deux semaines de lutte antivirus sur mon pc), il faut que je passe de 256 à 512 Mo de ram. Comment faire : j'ai une tour Powermate de Nec. Est-ce qu'il faut que je démonte pour sortir mes barrettes et chercher les memes dans les magasins ? cela existe-t-il en standard ? on peut commander chez qui sur le net ? Merci de m'éclairer un peu je patauge.
  14. Voila tcleaner : ********ToolsCleaner! (A.Rothstein) V1.0******** Nettoyage commence le 03/08/2007 a 15:54:16,14 *************************************** -SdFix = Trouve! -SdFix.exe = Suppression effectuee! -Diaghelp = Trouve! BIt Defender n'a plus envoyé de message, est-ce que tt est ok ? Où dois-je poster pour un conseil sur le rajout de barrettes de mémoire, je voudrais pas qu'on ferme mon post !! Merci Charles et bonne continuation sur ce super forum
  15. Salut, voici le rapport bit defender : //----------------------------------------------------------------- // // Produit BitDefender Antivirus Plus v10 // Produit 10.2 // // Créé le: 03/08/2007 14:23:19 // //----------------------------------------------------------------- Statistiques Chemin cible: C:\ Dossiers : 2506 Fichiers : 106623 Processus Mémoire analysés : 25 Archives : 7961 Fichiers enpaquetés : 5652 Virus trouvés : 1 Fichiers infectés : 4 Processus Mémoire infectés : 0 Fichiers suspects : 0 Alertes : 0 Fichiers désinfectés : 0 Fichiers effacés : 0 Fichiers déplacés : 0 Erreurs I/O : 25 Temps d'analyse :=00:41:41 Fichiers/seconde :42 Statistiques Spywares Registres analysés : 1694 Registres infectés : 0 Cookies analysés : 30 Cookies infectés : 0 Fichiers spyware infectés : 0 Menaces Spyware détectées : 0 Définitions virus : 719780 Plugins d'analyse : 16 Plugins archives : 41 Plug-ins décompression : 6 Plug-ins messagerie : 6 Plug-ins système : 5 Options d'analyse Détection [X] Analyser le secteur de boot [X] Processus mémoire [X] Analyser les archives [X] Analyser les fichiers enpaquetés [X] Analyser la messagerie Masque fichiers [ ] Programmes [X] Tous les fichiers [ ] Extensions définies par l'utilisateur: [ ] Exclure les extensions: ; Action Objets infectés [ ] Ignorer [X] Désinfecter [ ] Effacer [ ] Mettre en quarantaine [ ] Demander l'action Seconde action [ ] Ignorer [ ] Effacer [X] Mettre en quarantaine [ ] Demander l'action Options d'analyse [X] Activer les alertes [X] Activer l'heuristique [ ] Afficher tous les fichiers dans le journal [X] Fichier journal: C:\Documents and Settings\All Users\Application Data\Bitdefender\Desktop\Profiles\Logs\deep_scan\1186143799.log Options d'analyse Spyware [X] Analyse contre les risques non-viraux [ ] Ecarter de l'analyse les dialers et les applications [X] Clés de registres [X] Cookies Résumé: C:\Documents and Settings\romestan\Local Settings\Temp\_AS96.tmp\ahk.cab=>pskahk.dll Infecté: Generic.Malware.SIMDWYNVdprn.D9407F4E C:\Documents and Settings\romestan\Local Settings\Temp\_AS96.tmp\ahk.cab=>pskahk.dll Désinfection impossible C:\Documents and Settings\romestan\Local Settings\Temp\_AS96.tmp\ahk.cab=>pskahk.dll Déplacement impossible C:\Documents and Settings\romestan\Local Settings\Temp\_AS99.tmp\ahk.cab=>pskahk.dll Infecté: Generic.Malware.SIMDWYNVdprn.D9407F4E C:\Documents and Settings\romestan\Local Settings\Temp\_AS99.tmp\ahk.cab=>pskahk.dll Désinfection impossible C:\Documents and Settings\romestan\Local Settings\Temp\_AS99.tmp\ahk.cab=>pskahk.dll Déplacement impossible C:\Documents and Settings\romestan\Local Settings\Temp\_ASAB.tmp\ahk.cab=>pskahk.dll Infecté: Generic.Malware.SIMDWYNVdprn.D9407F4E C:\Documents and Settings\romestan\Local Settings\Temp\_ASAB.tmp\ahk.cab=>pskahk.dll Désinfection impossible C:\Documents and Settings\romestan\Local Settings\Temp\_ASAB.tmp\ahk.cab=>pskahk.dll Déplacement impossible C:\Documents and Settings\romestan\Local Settings\Temp\_ASD6.tmp\ahk.cab=>pskahk.dll Infecté: Generic.Malware.SIMDWYNVdprn.D9407F4E C:\Documents and Settings\romestan\Local Settings\Temp\_ASD6.tmp\ahk.cab=>pskahk.dll Désinfection impossible C:\Documents and Settings\romestan\Local Settings\Temp\_ASD6.tmp\ahk.cab=>pskahk.dll Déplacement impossible je m'occupe de la restauration et du nettoyage et je reposte, A + Merci Jok pour tes encouragements, c'était chose facile de réussir avec l'aide de Charles Ingals. Merci à vous tous pour être là qd on est tt seul devant une machine qui nous abandonne... j'ai besoin de mon PC tous les jours pour des choses courantes ; j'ai 3 enfants et suis en campagne, donc il me relie à la "vraie vie" de consommation... d'où mon acharnement.
  16. salut voila le rapport kapersky : KASPERSKY ON-LINE SCANNER REPORT Thursday, August 02, 2007 4:10:00 PM Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version : 5.0.83.0 Dernière mise à jour de la base antivirus Kaspersky : 2/08/2007 Enregistrements dans la base antivirus Kaspersky : 347990 Paramètres d'analyse Analyser avec la base antivirus suivante standard Analyser les archives vrai Analyser les bases de messagerie vrai Cible de l'analyse Poste de travail A:\ C:\ Q:\ R:\ Statistiques de l'analyse Total d'objets analysés 33734 Nombre de virus trouvés 1 Nombre d'objets infectés 1 / 0 Nombre d'objets suspects 0 Durée de l'analyse 01:08:02 Nom de l'objet infecté Nom du virus Dernière action C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Application Data\Bitdefender\Desktop\Profiles\asdict.dat L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Bureau\WinPFind3u\MovedFiles\WINDOWS\2pack.exe Infecté : Backdoor.Win32.SpyBoter.fb ignoré C:\Documents and Settings\romestan\Cookies\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Application Data\Identities\{F9097B72-395C-4E07-A518-31AE2BD2E4DD}\Microsoft\Outlook Express\Boîte de réception.dbx L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Application Data\Identities\{F9097B72-395C-4E07-A518-31AE2BD2E4DD}\Microsoft\Outlook Express\Folders.dbx L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Application Data\Identities\{F9097B72-395C-4E07-A518-31AE2BD2E4DD}\Microsoft\Outlook Express\Offline.dbx L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Application Data\Identities\{F9097B72-395C-4E07-A518-31AE2BD2E4DD}\Microsoft\Outlook Express\Pop3uidl.dbx L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Historique\History.IE5\MSHist012007080220070803\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Temp\_AS96.tmp\ahk.cab L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Temp\_AS99.tmp\ahk.cab L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Temp\_ASAB.tmp\ahk.cab L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Temp\_ASD6.tmp\ahk.cab L'objet est verrouillé ignoré C:\Documents and Settings\romestan\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\romestan\NTUSER.DAT L'objet est verrouillé ignoré C:\Documents and Settings\romestan\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Program Files\Softwin\BitDefender10\aspdict.dat L'objet est verrouillé ignoré C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré C:\WINDOWS\SoftwareDistribution\EventCache\{ED1A6D9F-6DEB-4326-8BD8-8CE62CA708EB}.bin L'objet est verrouillé ignoré C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré C:\WINDOWS\system32\bdss.log L'objet est verrouillé ignoré C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré C:\WINDOWS\Temp\tmp00007337\tmp00000000 L'objet est verrouillé ignoré C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré Analyse terminée. je le savais... et le rapport windfind : [Registry - Non-Microsoft Only] Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3} deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} deleted successfully. [Files/Folders - Created Within 30 days] C:\WINDOWS\SYSTEM32\drivers\ssmdrv.sys moved successfully. [Files/Folders - Modified Within 30 days] C:\ComboFix moved successfully. C:\QooBox\Quarantine\Registry_backups moved successfully. C:\QooBox\Quarantine moved successfully. C:\QooBox moved successfully. Folder move failed. C:\SDFix\backups_old1\HOSTS scheduled to be moved on reboot. C:\SDFix\backups_old1 moved successfully. Folder move failed. C:\SDFix\backups\HOSTS scheduled to be moved on reboot. C:\SDFix\backups moved successfully. C:\SDFix\apps\Replace moved successfully. C:\SDFix\apps moved successfully. C:\SDFix moved successfully. C:\WINDOWS\catchme.exe moved successfully. [ Extra Files ] C:\WINDOWS\System32\x moved successfully. < End of log > Created on 08/02/2007 16:11:12 voila voila, je crois que je vais me jeter par la fenetre. Est-ce que les pirates sont severement punis pour nous emm.. autant ?? merci pour ton aide
  17. Hello; j'arrive pas à telecharger Activescan . Je reessaierai demain. En plus, j'ai encore un message virus de bit defender, d'un certain GenericMalware. Je te poste un hijackthis au cas où. Je vais me changer les idées, là, je sature. A+ Logfile of HijackThis v1.99.1 Scan saved at 22:23:36, on 01/08/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\WINDOWS\system32\devldr32.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\Program Files\internet explorer\iexplore.exe C:\Documents and Settings\romestan\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing) O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
  18. Salut, Voila le Report.txt SDFix: Version 1.94 Run by romestan on 01/08/2007 at 19:58 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Restoring Missing Security Center Service Restoring Missing SharedAccess Service Rebooting... Normal Mode: Checking Files: No Trojan Files Found Removing Temp Files... ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files: --------------- Files with Hidden Attributes: C:\Documents and Settings\romestan\Bureau\WinPFind3u\MovedFiles\WINDOWS\2pack.exe C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0004.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0284.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0292.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL1758.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3125.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3375.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3690.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Peyrolles\~WRL0796.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\tsouin tsouin\~WRL3039.tmp C:\WINDOWS\system32\config\DEFAULT.tmp.LOG C:\WINDOWS\system32\config\SAM.tmp.LOG C:\WINDOWS\system32\config\SECURITY.tmp.LOG C:\WINDOWS\system32\config\SOFTWARE.tmp.LOG C:\WINDOWS\system32\config\SYSTEM.tmp.LOG Finished Hijackthis : Logfile of HijackThis v1.99.1 Scan saved at 20:16:38, on 01/08/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\WINDOWS\system32\devldr32.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\notepad.exe C:\Documents and Settings\romestan\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing) O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) le rapport windfind qui s'est ouvert ds le bloc-notes (pas de fichier avec date et heure ??) WinPFind3 logfile created on: 01/08/2007 21:10:05 WinPFind3U by OldTimer - Version 1.0.39 Folder = C:\Documents and Settings\romestan\Bureau\WinPFind3u\ Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) Internet Explorer (Version = 6.0.2900.2180) 247,48 Mb Total Physical Memory | 124,10 Mb Available Physical Memory | 50,14% Memory free 508,30 Mb Paging File | 121,07 Mb Available in Paging File | 23,82% Paging File free Paging file location(s): C:\pagefile.sys 144 288; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 35,25 Gb Total Space | 29,35 Gb Free Space | 83,27% Space Free D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded Computer Name: SN200412170005 Current User Name: romestan Logged in as Administrator. Current Boot Mode: Normal [Processes - Non-Microsoft Only] bdagent.exe -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 26/03/2007 15:49:46 | Attr = ] bdmcon.exe -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 14/07/2007 21:32:44 | Attr = ] bdss.exe -> %CommonProgramFiles%\Softwin\BitDefender Scan Server\bdss.exe -> [Ver = | Size = 81920 bytes | Modified Date = 19/01/2007 16:12:56 | Attr = ] devldr32.exe -> %System32%\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Modified Date = 23/08/2001 17:47:34 | Attr = ] livesrv.exe -> %CommonProgramFiles%\Softwin\BitDefender Update Service\livesrv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 18 | Size = 237568 bytes | Modified Date = 14/07/2007 21:33:04 | Attr = ] slserv.exe -> %System32%\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 05/05/2002 09:29:34 | Attr = ] vsserv.exe -> %ProgramFiles%\Softwin\BitDefender10\vsserv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 1, 147 | Size = 462848 bytes | Modified Date = 14/07/2007 21:32:52 | Attr = ] winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.38.0 | Size = 322048 bytes | Modified Date = 23/06/2007 15:15:54 | Attr = ] xcommsvr.exe -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 09/11/2006 13:33:04 | Attr = ] [Win32 Services - Non-Microsoft Only] (bdss) BitDefender Scan Server [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Scan Server\bdss.exe -> [Ver = | Size = 81920 bytes | Modified Date = 19/01/2007 16:12:56 | Attr = ] (dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 225280 bytes | Modified Date = 20/08/2004 01:09:52 | Attr = ] (LIVESRV) BitDefender Desktop Update Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Update Service\livesrv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 18 | Size = 237568 bytes | Modified Date = 14/07/2007 21:33:04 | Attr = ] (SLService) SmartLinkService [Win32_Own | Auto | Running] -> %System32%\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 05/05/2002 09:29:34 | Attr = ] (VSSERV) BitDefender Virus Shield [Win32_Own | Auto | Running] -> %ProgramFiles%\Softwin\BitDefender10\vsserv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 1, 147 | Size = 462848 bytes | Modified Date = 14/07/2007 21:32:52 | Attr = ] (XCOMM) BitDefender Communicator [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 09/11/2006 13:33:04 | Attr = ] [Registry - Non-Microsoft Only] < Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> BDAgent -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 26/03/2007 15:49:46 | Attr = ] BDMCon -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 14/07/2007 21:32:44 | Attr = ] < OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL -> Installed = 1 -> MAPI -> Installed = 1 -> MSFS -> Installed = 1 -> < AppInit_DLLs [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> sockspy.dll -> %System32%\sockspy.dll -> [Ver = | Size = 73728 bytes | Modified Date = 26/01/2006 20:19:52 | Attr = ] < SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> igfxcui -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 315392 bytes | Modified Date = 13/12/2002 07:09:16 | Attr = ] < CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoCDBurning -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> < CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 36 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> ÿÿÿÿ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> < HOSTS File > (686 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 127.0.0.1 localhost -> -> < Internet Explorer Settings > -> -> HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome -> HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKLM: Local Page -> %SystemRoot%\system32\blank.htm -> HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKLM: Start Page -> about:blank -> HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> HKCU: Local Page -> C:\WINDOWS\system32\blank.htm -> HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKCU: Start Page -> http://www.google.fr/ -> HKCU: ProxyEnable -> 0 -> < Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> msn.com [ - ] -> -> < BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %SystemDrive%\APPS\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx [AcroIEHlprObj Class] -> [Ver = 1, 0, 0, 1 | Size = 37808 bytes | Modified Date = 16/04/2001 16:39:02 | Attr = ] {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 31/05/2005 01:04:00 | Attr = ] {549B5CA7-4A86-11D7-A4DF-000874180BB3} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found < Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found < Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> E&xporter vers Microsoft Excel -> -> File not found < User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> SV1 -> -> < DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {9112AFD1-4BD4-4285-AFE7-48BFAE17DD2B} -> (Intel® PRO/100 VE Network Connection) -> {E54B0B60-E0CA-4847-99A6-8BF3DB3AF3F9} -> () -> {EA06B917-0C19-44AD-88F2-6A85EFDA9002} -> (Carte réseau 1394) -> < Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp -> Reg Data - Key not found -> File not found msdaipp -> Reg Data - Key not found -> File not found < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://download.macromedia.com/pub/shockwa...ash/swflash.cab -> DirectAnimation Java Classes -> - CodeBase = file://C:\WINDOWS\Java\classes\dajava.cab -> Microsoft XML Parser for Java -> - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab -> [Registry - Additional Scans - Non-Microsoft Only] < Security Settings > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 3 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Service de transfert intelligent en arrière-plan -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> Rpcss; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Transfère des fichiers en tâche de fond en utilisant la bande passante du réseau lors de ses périodes d'inactivité. Si le service est arrêté, des fonctionnalités telles que Windows Update et MSN Explorer ne pourront plus télécharger automatiquement des programmes et d'autres informations. Si ce service est désactivé, tous les services qui en dépendent explicitement peuvent présenter des problèmes de transfert de fichiers s'ils ne disposent pas d'un mécanisme sûr de remplacement pour transférer les fichier -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\FailureActions -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> C:\WINDOWS\System32\qmgr.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> Root\LEGACY_BITS00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\system32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 2276 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{8AD6DD74-8038-4A9C-93E1-EF429F4F5416} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{2F5A5EAE-C9EE-4099-A0E3-AB75B1617E66} -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> Root\LEGACY_SHAREDACCESS00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %systemroot%\system32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Mises à jour automatiques -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Active le téléchargement et l'installation de mises à jour Windows critiques. Si le service est désactivé, le système d'exploitation peut être mis à jour manuellement sur le site Web de Windows Update. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\System32\wuauserv.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> Root\LEGACY_WUAUSERV00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> < Uninstall List > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ -> {1D643CD0-4DD6-11D7-A4E0-000874180BB3} -> Microsoft Money -> {22524CA1-515C-4153-9807-52AE65F73B5F} -> BitDefender Antivirus Plus v10 -> {350C940c-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP -> {8855FF30-19CE-4CB1-A654-87B38369CCE1} -> Sonic RecordNow DX -> {8C64E149-54BA-11D6-91B1-00500462BE80} -> Extension Système de Microsoft Money -> {9111040C-6000-11D3-8CFE-0050048383C9} -> Microsoft Office XP Professional -> EPSON Printer and Utilities -> EPSON Logiciel imprimante -> EPSON Scanner -> EPSON Scan -> EVEREST Home Edition_is1 -> EVEREST Home Edition v2.20 -> Free.fr -> Free - Kit de connexion -> HijackThis -> HijackThis 1.99.1 -> KB873339 -> Correctif Windows XP - KB873339 -> KB885835 -> Correctif Windows XP - KB885835 -> KB885836 -> Correctif Windows XP - KB885836 -> KB888302 -> Correctif Windows XP - KB888302 -> KB890046 -> Mise à jour de sécurité pour Windows XP (KB890046) -> KB890859 -> Correctif Windows XP - KB890859 -> KB891781 -> Correctif Windows XP - KB891781 -> KB893756 -> Mise à jour de sécurité pour Windows XP (KB893756) -> KB893803v2 -> Windows Installer 3.1 (KB893803) -> KB896358 -> Mise à jour de sécurité pour Windows XP (KB896358) -> KB896423 -> Mise à jour de sécurité pour Windows XP (KB896423) -> KB896424 -> Mise à jour de sécurité pour Windows XP (KB896424) -> KB896428 -> Mise à jour de sécurité pour Windows XP (KB896428) -> KB898458 -> Mise à jour de sécurité pour Step by Step Interactive Training (KB898458) -> KB898461 -> Mise à jour pour Windows XP (KB898461) -> KB899587 -> Mise à jour de sécurité pour Windows XP (KB899587) -> KB899591 -> Mise à jour de sécurité pour Windows XP (KB899591) -> KB900725 -> Mise à jour de sécurité pour Windows XP (KB900725) -> KB901017 -> Mise à jour de sécurité pour Windows XP (KB901017) -> KB901214 -> Mise à jour de sécurité pour Windows XP (KB901214) -> KB902400 -> Mise à jour de sécurité pour Windows XP (KB902400) -> KB904706 -> Mise à jour de sécurité pour Windows XP (KB904706) -> KB905414 -> Mise à jour de sécurité pour Windows XP (KB905414) -> KB905749 -> Mise à jour de sécurité pour Windows XP (KB905749) -> KB908519 -> Mise à jour de sécurité pour Windows XP (KB908519) -> KB908531 -> Mise à jour pour Windows XP (KB908531) -> KB910437 -> Mise à jour pour Windows XP (KB910437) -> KB911280 -> Mise à jour pour Windows XP (KB911280) -> KB911562 -> Mise à jour de sécurité pour Windows XP (KB911562) -> KB911564 -> Mise à jour de sécurité pour Lecteur Windows Media (KB911564) -> KB911565 -> Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565) -> KB911927 -> Mise à jour de sécurité pour Windows XP (KB911927) -> KB912919 -> Mise à jour de sécurité pour Windows XP (KB912919) -> KB913580 -> Mise à jour de sécurité pour Windows XP (KB913580) -> KB914388 -> Mise à jour de sécurité pour Windows XP (KB914388) -> KB914389 -> Mise à jour de sécurité pour Windows XP (KB914389) -> KB917344 -> Mise à jour de sécurité pour Windows XP (KB917344) -> KB917422 -> Mise à jour de sécurité pour Windows XP (KB917422) -> KB917734_WMP8 -> Mise à jour de sécurité pour Lecteur Windows Media 8 (KB917734) -> KB917953 -> Mise à jour de sécurité pour Windows XP (KB917953) -> KB919007 -> Mise à jour de sécurité pour Windows XP (KB919007) -> KB920670 -> Mise à jour de sécurité pour Windows XP (KB920670) -> KB920683 -> Mise à jour de sécurité pour Windows XP (KB920683) -> KB920685 -> Mise à jour de sécurité pour Windows XP (KB920685) -> KB921398 -> Mise à jour de sécurité pour Windows XP (KB921398) -> KB921883 -> Mise à jour de sécurité pour Windows XP (KB921883) -> KB922616 -> Mise à jour de sécurité pour Windows XP (KB922616) -> KB922819 -> Mise à jour de sécurité pour Windows XP (KB922819) -> KB923191 -> Mise à jour de sécurité pour Windows XP (KB923191) -> KB923414 -> Mise à jour de sécurité pour Windows XP (KB923414) -> KB924191 -> Mise à jour de sécurité pour Windows XP (KB924191) -> KB924496 -> Mise à jour de sécurité pour Windows XP (KB924496) -> PROSet -> Intel® PRO Ethernet Adapter and Software -> ShockwaveFlash -> Adobe Flash Player 9 ActiveX -> SigmaTel C-Major -> SigmaTel C-Major Audio -> Spybot - Search & Destroy_is1 -> Spybot - Search & Destroy 1.4 -> T r o j a n R e m o v e r_is1 -> Trojan Remover 6.6.1 -> Windows XP Service Pack -> Windows XP Service Pack 2 -> [Files/Folders - Created Within 30 days] 1d445837b1976b19ea6acbd2c817 -> %SystemDrive%\1d445837b1976b19ea6acbd2c817 -> [Folder | Created Date = 16/07/2007 21:54:49 | Attr = ] APPS -> %SystemDrive%\APPS -> [Folder | Created Date = 14/07/2007 16:57:48 | Attr = ] Bases -> %SystemDrive%\Bases -> [Folder | Created Date = 17/07/2007 14:35:10 | Attr = ] BOOT.BAK -> %SystemDrive%\BOOT.BAK -> [Ver = | Size = 193 bytes | Created Date = 14/07/2007 18:22:08 | Attr = RHS] cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 14/07/2007 18:21:59 | Attr = RHS] ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 27/07/2007 21:12:03 | Attr = ] DIVTOOLS -> %SystemDrive%\DIVTOOLS -> [Folder | Created Date = 14/07/2007 16:58:00 | Attr = H ] Downloads -> %SystemDrive%\Downloads -> [Folder | Created Date = 17/07/2007 14:35:10 | Attr = ] DRIVERS -> %SystemDrive%\DRIVERS -> [Folder | Created Date = 14/07/2007 16:57:48 | Attr = H ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 259575808 bytes | Created Date = 02/01/1601 23:00:00 | Attr = HS] hijackthis -> %SystemDrive%\hijackthis -> [Folder | Created Date = 16/07/2007 16:20:33 | Attr = ] IO.SYS -> %SystemDrive%\IO.SYS -> [Ver = | Size = 0 bytes | Created Date = 29/07/2007 00:35:50 | Attr = RHS] Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Created Date = 17/07/2007 14:33:51 | Attr = ] MSDOS.SYS -> %SystemDrive%\MSDOS.SYS -> [Ver = | Size = 0 bytes | Created Date = 29/07/2007 00:35:50 | Attr = RHS] PNP -> %SystemDrive%\PNP -> [Folder | Created Date = 14/07/2007 16:58:46 | Attr = H ] QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 27/07/2007 21:14:55 | Attr = ] RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Created Date = 14/07/2007 18:26:49 | Attr = HS] SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 29/07/2007 00:26:53 | Attr = ] UPDFLOP.TAG -> %SystemDrive%\UPDFLOP.TAG -> [Ver = | Size = 0 bytes | Created Date = 14/07/2007 17:00:32 | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Created Date = 23/07/2007 15:14:30 | Attr = H ] $MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Created Date = 24/07/2007 09:09:56 | Attr = H ] $NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [Folder | Created Date = 30/07/2007 20:45:23 | Attr = H ] $NtUninstallKB833987$ -> %SystemRoot%\$NtUninstallKB833987$ -> [Folder | Created Date = 16/07/2007 21:54:19 | Attr = H ] $NtUninstallKB835409$ -> %SystemRoot%\$NtUninstallKB835409$ -> [Folder | Created Date = 23/07/2007 15:15:23 | Attr = H ] $NtUninstallKB835732$ -> %SystemRoot%\$NtUninstallKB835732$ -> [Folder | Created Date = 16/07/2007 21:55:00 | Attr = H ] $NtUninstallKB840987$ -> %SystemRoot%\$NtUninstallKB840987$ -> [Folder | Created Date = 16/07/2007 21:58:45 | Attr = H ] $NtUninstallKB842773$ -> %SystemRoot%\$NtUninstallKB842773$ -> [Folder | Created Date = 24/07/2007 09:10:50 | Attr = H ] $NtUninstallKB873339$ -> %SystemRoot%\$NtUninstallKB873339$ -> [Folder | Created Date = 30/07/2007 21:15:52 | Attr = H ] $NtUninstallKB873339_0$ -> %SystemRoot%\$NtUninstallKB873339_0$ -> [Folder | Created Date = 27/07/2007 19:17:16 | Attr = H ] $NtUninstallKB885835$ -> %SystemRoot%\$NtUninstallKB885835$ -> [Folder | Created Date = 30/07/2007 21:16:20 | Attr = H ] $NtUninstallKB885835_0$ -> %SystemRoot%\$NtUninstallKB885835_0$ -> [Folder | Created Date = 24/07/2007 09:13:43 | Attr = H ] $NtUninstallKB885836$ -> %SystemRoot%\$NtUninstallKB885836$ -> [Folder | Created Date = 30/07/2007 21:17:18 | Attr = H ] $NtUninstallKB885836_0$ -> %SystemRoot%\$NtUninstallKB885836_0$ -> [Folder | Created Date = 27/07/2007 19:18:50 | Attr = H ] $NtUninstallKB888302$ -> %SystemRoot%\$NtUninstallKB888302$ -> [Folder | Created Date = 30/07/2007 21:17:34 | Attr = H ] $NtUninstallKB888302_0$ -> %SystemRoot%\$NtUninstallKB888302_0$ -> [Folder | Created Date = 27/07/2007 19:10:47 | Attr = H ] $NtUninstallKB890046$ -> %SystemRoot%\$NtUninstallKB890046$ -> [Folder | Created Date = 30/07/2007 21:17:50 | Attr = H ] $NtUninstallKB890046_0$ -> %SystemRoot%\$NtUninstallKB890046_0$ -> [Folder | Created Date = 27/07/2007 19:13:09 | Attr = H ] $NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Created Date = 30/07/2007 21:18:07 | Attr = H ] $NtUninstallKB890859_0$ -> %SystemRoot%\$NtUninstallKB890859_0$ -> [Folder | Created Date = 27/07/2007 19:05:53 | Attr = H ] $NtUninstallKB891781$ -> %SystemRoot%\$NtUninstallKB891781$ -> [Folder | Created Date = 30/07/2007 21:18:32 | Attr = H ] $NtUninstallKB891781_0$ -> %SystemRoot%\$NtUninstallKB891781_0$ -> [Folder | Created Date = 27/07/2007 19:13:29 | Attr = H ] $NtUninstallKB893756$ -> %SystemRoot%\$NtUninstallKB893756$ -> [Folder | Created Date = 30/07/2007 21:18:48 | Attr = H ] $NtUninstallKB893756_0$ -> %SystemRoot%\$NtUninstallKB893756_0$ -> [Folder | Created Date = 27/07/2007 19:17:41 | Attr = H ] $NtUninstallKB896358$ -> %SystemRoot%\$NtUninstallKB896358$ -> [Folder | Created Date = 30/07/2007 21:19:04 | Attr = H ] $NtUninstallKB896358_0$ -> %SystemRoot%\$NtUninstallKB896358_0$ -> [Folder | Created Date = 24/07/2007 09:08:53 | Attr = H ] $NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Created Date = 30/07/2007 21:19:20 | Attr = H ] $NtUninstallKB896423_0$ -> %SystemRoot%\$NtUninstallKB896423_0$ -> [Folder | Created Date = 24/07/2007 09:11:28 | Attr = H ] $NtUninstallKB896424$ -> %SystemRoot%\$NtUninstallKB896424$ -> [Folder | Created Date = 30/07/2007 21:19:39 | Attr = H ] $NtUninstallKB896424_0$ -> %SystemRoot%\$NtUninstallKB896424_0$ -> [Folder | Created Date = 24/07/2007 09:12:09 | Attr = H ] $NtUninstallKB896428$ -> %SystemRoot%\$NtUninstallKB896428$ -> [Folder | Created Date = 30/07/2007 21:20:42 | Attr = H ] $NtUninstallKB896428_0$ -> %SystemRoot%\$NtUninstallKB896428_0$ -> [Folder | Created Date = 27/07/2007 19:09:15 | Attr = H ] $NtUninstallKB898458$ -> %SystemRoot%\$NtUninstallKB898458$ -> [Folder | Created Date = 24/07/2007 09:08:17 | Attr = H ] $NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Created Date = 23/07/2007 15:19:50 | Attr = H ] $NtUninstallKB899587$ -> %SystemRoot%\$NtUninstallKB899587$ -> [Folder | Created Date = 30/07/2007 21:21:09 | Attr = H ] $NtUninstallKB899587_0$ -> %SystemRoot%\$NtUninstallKB899587_0$ -> [Folder | Created Date = 24/07/2007 09:14:38 | Attr = H ] $NtUninstallKB899591$ -> %SystemRoot%\$NtUninstallKB899591$ -> [Folder | Created Date = 30/07/2007 21:21:28 | Attr = H ] $NtUninstallKB899591_0$ -> %SystemRoot%\$NtUninstallKB899591_0$ -> [Folder | Created Date = 24/07/2007 09:12:26 | Attr = H ] $NtUninstallKB900725$ -> %SystemRoot%\$NtUninstallKB900725$ -> [Folder | Created Date = 30/07/2007 21:21:48 | Attr = H ] $NtUninstallKB900725_0$ -> %SystemRoot%\$NtUninstallKB900725_0$ -> [Folder | Created Date = 23/07/2007 15:19:20 | Attr = H ] $NtUninstallKB901017$ -> %SystemRoot%\$NtUninstallKB901017$ -> [Folder | Created Date = 30/07/2007 21:22:19 | Attr = H ] $NtUninstallKB901017_0$ -> %SystemRoot%\$NtUninstallKB901017_0$ -> [Folder | Created Date = 27/07/2007 19:18:06 | Attr = H ] $NtUninstallKB901214$ -> %SystemRoot%\$NtUninstallKB901214$ -> [Folder | Created Date = 30/07/2007 21:22:37 | Attr = H ] $NtUninstallKB901214_0$ -> %SystemRoot%\$NtUninstallKB901214_0$ -> [Folder | Created Date = 27/07/2007 19:11:50 | Attr = H ] $NtUninstallKB902400$ -> %SystemRoot%\$NtUninstallKB902400$ -> [Folder | Created Date = 30/07/2007 21:25:40 | Attr = H ] $NtUninstallKB902400_0$ -> %SystemRoot%\$NtUninstallKB902400_0$ -> [Folder | Created Date = 27/07/2007 19:13:58 | Attr = H ] $NtUninstallKB904706$ -> %SystemRoot%\$NtUninstallKB904706$ -> [Folder | Created Date = 23/07/2007 15:22:42 | Attr = H ] $NtUninstallKB905414$ -> %SystemRoot%\$NtUninstallKB905414$ -> [Folder | Created Date = 30/07/2007 21:26:09 | Attr = H ] $NtUninstallKB905414_0$ -> %SystemRoot%\$NtUninstallKB905414_0$ -> [Folder | Created Date = 23/07/2007 15:22:05 | Attr = H ] $NtUninstallKB905495$ -> %SystemRoot%\$NtUninstallKB905495$ -> [Folder | Created Date = 27/07/2007 19:15:19 | Attr = H ] $NtUninstallKB905749$ -> %SystemRoot%\$NtUninstallKB905749$ -> [Folder | Created Date = 30/07/2007 21:26:35 | Attr = H ] $NtUninstallKB905749_0$ -> %SystemRoot%\$NtUninstallKB905749_0$ -> [Folder | Created Date = 27/07/2007 19:09:32 | Attr = H ] $NtUninstallKB908519$ -> %SystemRoot%\$NtUninstallKB908519$ -> [Folder | Created Date = 30/07/2007 21:27:03 | Attr = H ] $NtUninstallKB908519_0$ -> %SystemRoot%\$NtUninstallKB908519_0$ -> [Folder | Created Date = 27/07/2007 19:08:53 | Attr = H ] $NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Created Date = 30/07/2007 21:27:33 | Attr = H ] $NtUninstallKB908531_0$ -> %SystemRoot%\$NtUninstallKB908531_0$ -> [Folder | Created Date = 23/07/2007 15:17:02 | Attr = H ] $NtUninstallKB910437$ -> %SystemRoot%\$NtUninstallKB910437$ -> [Folder | Created Date = 30/07/2007 21:27:52 | Attr = H ] $NtUninstallKB910437_0$ -> %SystemRoot%\$NtUninstallKB910437_0$ -> [Folder | Created Date = 27/07/2007 19:15:45 | Attr = H ] $NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Created Date = 30/07/2007 21:28:10 | Attr = H ] $NtUninstallKB911280_0$ -> %SystemRoot%\$NtUninstallKB911280_0$ -> [Folder | Created Date = 24/07/2007 09:11:47 | Attr = H ] $NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Created Date = 30/07/2007 21:28:27 | Attr = H ] $NtUninstallKB911562_0$ -> %SystemRoot%\$NtUninstallKB911562_0$ -> [Folder | Created Date = 27/07/2007 19:17:29 | Attr = H ] $NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Created Date = 23/07/2007 15:27:02 | Attr = H ] $NtUninstallKB911565$ -> %SystemRoot%\$NtUninstallKB911565$ -> [Folder | Created Date = 30/07/2007 22:11:28 | Attr = H ] $NtUninstallKB911567-OE6SP1-20060316.165634$ -> %SystemRoot%\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> [Folder | Created Date = 27/07/2007 19:09:51 | Attr = H ] $NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Created Date = 30/07/2007 21:28:42 | Attr = H ] $NtUninstallKB911927_0$ -> %SystemRoot%\$NtUninstallKB911927_0$ -> [Folder | Created Date = 24/07/2007 09:13:01 | Attr = H ] $NtUninstallKB912919$ -> %SystemRoot%\$NtUninstallKB912919$ -> [Folder | Created Date = 30/07/2007 21:29:02 | Attr = H ] $NtUninstallKB912919_0$ -> %SystemRoot%\$NtUninstallKB912919_0$ -> [Folder | Created Date = 27/07/2007 19:10:26 | Attr = H ] $NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Created Date = 30/07/2007 21:29:18 | Attr = H ] $NtUninstallKB913580_0$ -> %SystemRoot%\$NtUninstallKB913580_0$ -> [Folder | Created Date = 23/07/2007 15:16:12 | Attr = H ] $NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Created Date = 30/07/2007 21:29:35 | Attr = H ] $NtUninstallKB914388_0$ -> %SystemRoot%\$NtUninstallKB914388_0$ -> [Folder | Created Date = 27/07/2007 19:12:50 | Attr = H ] $NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Created Date = 30/07/2007 21:29:51 | Attr = H ] $NtUninstallKB914389_0$ -> %SystemRoot%\$NtUninstallKB914389_0$ -> [Folder | Created Date = 27/07/2007 19:07:38 | Attr = H ] $NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Created Date = 30/07/2007 21:30:07 | Attr = H ] $NtUninstallKB917344_0$ -> %SystemRoot%\$NtUninstallKB917344_0$ -> [Folder | Created Date = 27/07/2007 19:12:27 | Attr = H ] $NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Created Date = 30/07/2007 21:30:23 | Attr = H ] $NtUninstallKB917422_0$ -> %SystemRoot%\$NtUninstallKB917422_0$ -> [Folder | Created Date = 27/07/2007 19:11:24 | Attr = H ] $NtUninstallKB917734_WMP8$ -> %SystemRoot%\$NtUninstallKB917734_WMP8$ -> [Folder | Created Date = 23/07/2007 15:21:35 | Attr = H ] $NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Created Date = 30/07/2007 21:30:39 | Attr = H ] $NtUninstallKB917953_0$ -> %SystemRoot%\$NtUninstallKB917953_0$ -> [Folder | Created Date = 27/07/2007 19:12:08 | Attr = H ] $NtUninstallKB918439-IE6SP1-20060530.145346$ -> %SystemRoot%\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> [Folder | Created Date = 27/07/2007 19:16:08 | Attr = H ] $NtUninstallKB918899-IE6SP1-20060725.123917$ -> %SystemRoot%\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> [Folder | Created Date = 23/07/2007 15:17:53 | Attr = H ] $NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Created Date = 30/07/2007 21:31:08 | Attr = H ] $NtUninstallKB919007_0$ -> %SystemRoot%\$NtUninstallKB919007_0$ -> [Folder | Created Date = 23/07/2007 15:23:17 | Attr = H ] $NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Created Date = 30/07/2007 21:31:25 | Attr = H ] $NtUninstallKB920670_0$ -> %SystemRoot%\$NtUninstallKB920670_0$ -> [Folder | Created Date = 23/07/2007 15:25:55 | Attr = H ] $NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Created Date = 30/07/2007 21:31:49 | Attr = H ] $NtUninstallKB920683_0$ -> %SystemRoot%\$NtUninstallKB920683_0$ -> [Folder | Created Date = 23/07/2007 15:14:33 | Attr = H ] $NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Created Date = 30/07/2007 21:32:07 | Attr = H ] $NtUninstallKB920685_0$ -> %SystemRoot%\$NtUninstallKB920685_0$ -> [Folder | Created Date = 27/07/2007 19:17:54 | Attr = H ] $NtUninstallKB921398$ -> %SystemRoot%\$NtUninstallKB921398$ -> [Folder | Created Date = 30/07/2007 22:12:08 | Attr = H ] $NtUninstallKB921883$ -> %SystemRoot%\$NtUninstallKB921883$ -> [Folder | Created Date = 30/07/2007 21:32:25 | Attr = H ] $NtUninstallKB921883_0$ -> %SystemRoot%\$NtUninstallKB921883_0$ -> [Folder | Created Date = 27/07/2007 19:18:37 | Attr = H ] $NtUninstallKB922616$ -> %SystemRoot%\$NtUninstallKB922616$ -> [Folder | Created Date = 30/07/2007 21:32:42 | Attr = H ] $NtUninstallKB922616_0$ -> %SystemRoot%\$NtUninstallKB922616_0$ -> [Folder | Created Date = 24/07/2007 09:12:44 | Attr = H ] $NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Created Date = 30/07/2007 21:33:02 | Attr = H ] $NtUninstallKB922819_0$ -> %SystemRoot%\$NtUninstallKB922819_0$ -> [Folder | Created Date = 24/07/2007 09:14:16 | Attr = H ] $NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Created Date = 30/07/2007 21:33:18 | Attr = H ] $NtUninstallKB923191_0$ -> %SystemRoot%\$NtUninstallKB923191_0$ -> [Folder | Created Date = 23/07/2007 15:20:15 | Attr = H ] $NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Created Date = 30/07/2007 21:33:35 | Attr = H ] $NtUninstallKB923414_0$ -> %SystemRoot%\$NtUninstallKB923414_0$ -> [Folder | Created Date = 24/07/2007 09:13:19 | Attr = H ] $NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Created Date = 30/07/2007 21:33:50 | Attr = H ] $NtUninstallKB924191_0$ -> %SystemRoot%\$NtUninstallKB924191_0$ -> [Folder | Created Date = 27/07/2007 19:20:18 | Attr = H ] $NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Created Date = 30/07/2007 21:34:06 | Attr = H ] $NtUninstallKB924496_0$ -> %SystemRoot%\$NtUninstallKB924496_0$ -> [Folder | Created Date = 27/07/2007 19:16:58 | Attr = H ] $NtUninstallKB925486-IE6SP1-20060918.120000$ -> %SystemRoot%\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> [Folder | Created Date = 24/07/2007 09:10:31 | Attr = H ] $NtUninstallQ327979$ -> %SystemRoot%\$NtUninstallQ327979$ -> [Folder | Created Date = 14/07/2007 18:11:50 | Attr = H ] $NtUninstallq330512$ -> %SystemRoot%\$NtUninstallq330512$ -> [Folder | Created Date = 14/07/2007 18:12:01 | Attr = H ] $NtUninstallQ330909$ -> %SystemRoot%\$NtUninstallQ330909$ -> [Folder | Created Date = 14/07/2007 18:12:09 | Attr = H ] $NtUninstallQ331060$ -> %SystemRoot%\$NtUninstallQ331060$ -> [Folder | Created Date = 14/07/2007 18:12:15 | Attr = H ] $NtUninstallQ331816$ -> %SystemRoot%\$NtUninstallQ331816$ -> [Folder | Created Date = 14/07/2007 18:12:22 | Attr = H ] $NtUninstallQ810020$ -> %SystemRoot%\$NtUninstallQ810020$ -> [Folder | Created Date = 14/07/2007 18:12:28 | Attr = H ] $NtUninstallQ815411$ -> %SystemRoot%\$NtUninstallQ815411$ -> [Folder | Created Date = 14/07/2007 18:12:34 | Attr = H ] AcrobatSetupStatus.ini -> %SystemRoot%\AcrobatSetupStatus.ini -> [Ver = | Size = 72 bytes | Created Date = 14/07/2007 18:23:10 | Attr = ] catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Created Date = 27/07/2007 21:12:19 | Attr = ] CDE CX6600FGD.ini -> %SystemRoot%\CDE CX6600FGD.ini -> [Ver = | Size = 25 bytes | Created Date = 14/07/2007 22:12:46 | Attr = ] Drivers -> %SystemRoot%\Drivers -> [Folder | Created Date = 14/07/2007 18:15:46 | Attr = ] EHome -> %SystemRoot%\EHome -> [Folder | Created Date = 30/07/2007 20:45:11 | Attr = ] erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 27/07/2007 21:18:34 | Attr = ] ERUNT -> %SystemRoot%\ERUNT -> [Folder | Created Date = 29/07/2007 00:35:30 | Attr = ] Favoris -> %SystemRoot%\Favoris -> [Folder | Created Date = 28/07/2007 10:00:25 | Attr = R ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Created Date = 27/07/2007 19:06:32 | Attr = ] jautoexp.dat -> %SystemRoot%\jautoexp.dat -> [Ver = | Size = 6550 bytes | Created Date = 23/07/2007 15:24:39 | Attr = ] Minidump -> %SystemRoot%\Minidump -> [Folder | Created Date = 26/07/2007 22:17:32 | Attr = ] Modio -> %SystemRoot%\Modio -> [Folder | Created Date = 14/07/2007 18:12:58 | Attr = ] NEC.BMP -> %SystemRoot%\NEC.BMP -> [Ver = | Size = 149262 bytes | Created Date = 14/07/2007 18:15:08 | Attr = ] nircmd.exe -> %SystemRoot%\nircmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 27/07/2007 21:12:19 | Attr = ] ODBC.INI -> %SystemRoot%\ODBC.INI -> [Ver = | Size = 385 bytes | Created Date = 31/07/2007 14:53:00 | Attr = ] peernet -> %SystemRoot%\peernet -> [Folder | Created Date = 30/07/2007 21:04:15 | Attr = ] Profiles -> %SystemRoot%\Profiles -> [Folder | Created Date = 14/07/2007 18:23:11 | Attr = ] provisioning -> %SystemRoot%\provisioning -> [Folder | Created Date = 30/07/2007 21:04:12 | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Created Date = 24/07/2007 10:09:04 | Attr = ] RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Created Date = 14/07/2007 18:15:32 | Attr = ] REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Created Date = 14/07/2007 18:29:00 | Attr = ] RESTORE.INS -> %SystemRoot%\RESTORE.INS -> [Ver = | Size = 1501198 bytes | Created Date = 14/07/2007 18:26:20 | Attr = ] ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [Folder | Created Date = 30/07/2007 20:57:29 | Attr = ] ShellNew -> %SystemRoot%\ShellNew -> [Folder | Created Date = 31/07/2007 14:50:22 | Attr = ] sl.lng -> %SystemRoot%\sl.lng -> [Ver = | Size = 49354 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] SmCfg.exe -> %SystemRoot%\SmCfg.exe -> [Ver = 2, 80, 1, 0 | Size = 61440 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] smscfg.ini -> %SystemRoot%\smscfg.ini -> [Ver = | Size = 61 bytes | Created Date = 14/07/2007 18:26:48 | Attr = ] SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Created Date = 17/07/2007 08:11:09 | Attr = ] unvise32qt.exe -> %SystemRoot%\unvise32qt.exe -> MindVision [Ver = 2.8.3 | Size = 86016 bytes | Created Date = 14/07/2007 18:24:04 | Attr = ] WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Created Date = 30/07/2007 21:07:58 | Attr = ] $ncsp$.inf -> %System32%\$ncsp$.inf -> [Ver = | Size = 333 bytes | Created Date = 14/07/2007 18:26:44 | Attr = ] amr_cpl.dll -> %System32%\amr_cpl.dll -> [Ver = 2, 81, 0, 0 | Size = 139264 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Created Date = 14/07/2007 19:20:20 | Attr = ] bits -> %System32%\bits -> [Folder | Created Date = 24/07/2007 09:10:54 | Attr = ] ctwdm32.dll -> %System32%\ctwdm32.dll -> Creative Technology Ltd. [Ver = 5.0.0.2001 | Size = 4096 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] devcon32.dll -> %System32%\devcon32.dll -> Creative Technology Ltd. [Ver = 4.06.651 | Size = 256512 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] devldr32.exe -> %System32%\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] EPPRTDRV.CAB -> %System32%\EPPRTDRV.CAB -> [Ver = | Size = 288201 bytes | Created Date = 14/07/2007 22:14:02 | Attr = ] EPSETUP.CAB -> %System32%\EPSETUP.CAB -> [Ver = | Size = 443573 bytes | Created Date = 14/07/2007 22:14:00 | Attr = ] EPSTP32U.CAB -> %System32%\EPSTP32U.CAB -> [Ver = | Size = 591071 bytes | Created Date = 14/07/2007 22:14:00 | Attr = ] EPSTP32U.DAT -> %System32%\EPSTP32U.DAT -> [Ver = | Size = 6390 bytes | Created Date = 14/07/2007 22:14:00 | Attr = R ] eps_icon.avi -> %System32%\eps_icon.avi -> [Ver = | Size = 8284 bytes | Created Date = 14/07/2007 22:14:03 | Attr = ] esccmd.dll -> %System32%\esccmd.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 22528 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ] escimgd.dll -> %System32%\escimgd.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 46080 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ] escwiad.dll -> %System32%\escwiad.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 29696 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ] E_DCINST.DLL -> %System32%\E_DCINST.DLL -> SEIKO EPSON CORP. [Ver = 1, 0, 0, 1 | Size = 31744 bytes | Created Date = 15/07/2007 08:55:22 | Attr = ] E_FBCB9EE.DLL -> %System32%\E_FBCB9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 2, 0, 0, 27 | Size = 64000 bytes | Created Date = 15/07/2007 08:55:15 | Attr = ] E_FBCH9EE.DLL -> %System32%\E_FBCH9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 1, 1, 0, 0 | Size = 34304 bytes | Created Date = 15/07/2007 08:55:16 | Attr = ] E_FLM9EE.DLL -> %System32%\E_FLM9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 5, 1, 0, 0 | Size = 79654 bytes | Created Date = 15/07/2007 08:55:15 | Attr = ] hccutils.dll -> %System32%\hccutils.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 114688 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] hkcmd.exe -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 114688 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] iAlmCoIn_0_v9.dll -> %System32%\iAlmCoIn_0_v9.dll -> Intel Corporation [Ver = 1.00.1000.1 | Size = 61440 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmdd5.dll -> %System32%\ialmdd5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 435266 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmdev5.dll -> %System32%\ialmdev5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 192507 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmdnt5.dll -> %System32%\ialmdnt5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 114236 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmgdev.dll -> %System32%\ialmgdev.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 188416 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmgicd.dll -> %System32%\ialmgicd.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 1859584 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmrem.dll -> %System32%\ialmrem.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 57344 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmrnt5.dll -> %System32%\ialmrnt5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 33792 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxcfg.exe -> %System32%\igfxcfg.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 483328 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxcpl.cpl -> %System32%\igfxcpl.cpl -> Intel Corporation [Ver = 3,0,0,1992 | Size = 94208 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxdev.dll -> %System32%\igfxdev.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 147456 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxdgps.dll -> %System32%\igfxdgps.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 45056 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxdiag.exe -> %System32%\igfxdiag.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxdo.dll -> %System32%\igfxdo.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 86016 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxeud.dll -> %System32%\igfxeud.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 221184 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxexps.dll -> %System32%\igfxexps.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 32768 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxext.exe -> %System32%\igfxext.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 86016 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhara.lhp -> %System32%\igfxhara.lhp -> [Ver = | Size = 55633 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxharb.lhp -> %System32%\igfxharb.lhp -> [Ver = | Size = 55654 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhchs.lhp -> %System32%\igfxhchs.lhp -> [Ver = | Size = 55426 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhcht.lhp -> %System32%\igfxhcht.lhp -> [Ver = | Size = 56139 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhcsy.lhp -> %System32%\igfxhcsy.lhp -> [Ver = | Size = 58343 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhdan.lhp -> %System32%\igfxhdan.lhp -> [Ver = | Size = 56933 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhdeu.lhp -> %System32%\igfxhdeu.lhp -> [Ver = | Size = 58017 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhell.lhp -> %System32%\igfxhell.lhp -> [Ver = | Size = 58791 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxheng.lhp -> %System32%\igfxheng.lhp -> [Ver = | Size = 55186 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhenu.lhp -> %System32%\igfxhenu.lhp -> [Ver = | Size = 55002 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhesp.lhp -> %System32%\igfxhesp.lhp -> [Ver = | Size = 56980 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhfin.lhp -> %System32%\igfxhfin.lhp -> [Ver = | Size = 57762 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhfra.lhp -> %System32%\igfxhfra.lhp -> [Ver = | Size = 56829 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhfrc.lhp -> %System32%\igfxhfrc.lhp -> [Ver = | Size = 56735 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhheb.lhp -> %System32%\igfxhheb.lhp -> [Ver = | Size = 61249 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhhun.lhp -> %System32%\igfxhhun.lhp -> [Ver = | Size = 59369 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhita.lhp -> %System32%\igfxhita.lhp -> [Ver = | Size = 56548 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhjpn.lhp -> %System32%\igfxhjpn.lhp -> [Ver = | Size = 57858 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhk.dll -> %System32%\igfxhk.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 118784 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhkor.lhp -> %System32%\igfxhkor.lhp -> [Ver = | Size = 63399 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhnld.lhp -> %System32%\igfxhnld.lhp -> [Ver = | Size = 57353 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhnor.lhp -> %System32%\igfxhnor.lhp -> [Ver = | Size = 56813 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhplk.lhp -> %System32%\igfxhplk.lhp -> [Ver = | Size = 58108 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhptb.lhp -> %System32%\igfxhptb.lhp -> [Ver = | Size = 56119 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhptg.lhp -> %System32%\igfxhptg.lhp -> [Ver = | Size = 56649 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhrus.lhp -> %System32%\igfxhrus.lhp -> [Ver = | Size = 58767 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhsve.lhp -> %System32%\igfxhsve.lhp -> [Ver = | Size = 56636 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhtha.lhp -> %System32%\igfxhtha.lhp -> [Ver = | Size = 59797 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhtrk.lhp -> %System32%\igfxhtrk.lhp -> [Ver = | Size = 57768 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxpph.dll -> %System32%\igfxpph.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 204800 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrara.lrc -> %System32%\igfxrara.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrarb.lrc -> %System32%\igfxrarb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrchs.lrc -> %System32%\igfxrchs.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrcht.lrc -> %System32%\igfxrcht.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrcsy.lrc -> %System32%\igfxrcsy.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrdan.lrc -> %System32%\igfxrdan.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrdeu.lrc -> %System32%\igfxrdeu.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrell.lrc -> %System32%\igfxrell.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 163840 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxreng.lrc -> %System32%\igfxreng.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrenu.lrc -> %System32%\igfxrenu.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxres.dll -> %System32%\igfxres.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:17:29 | Attr = ] igfxresp.lrc -> %System32%\igfxresp.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxress.dll -> %System32%\igfxress.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 503808 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrfin.lrc -> %System32%\igfxrfin.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrfra.lrc -> %System32%\igfxrfra.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrfrc.lrc -> %System32%\igfxrfrc.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrheb.lrc -> %System32%\igfxrheb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrhun.lrc -> %System32%\igfxrhun.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrita.lrc -> %System32%\igfxrita.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrjpn.lrc -> %System32%\igfxrjpn.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrkor.lrc -> %System32%\igfxrkor.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrnld.lrc -> %System32%\igfxrnld.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrnor.lrc -> %System32%\igfxrnor.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrplk.lrc -> %System32%\igfxrplk.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrptb.lrc -> %System32%\igfxrptb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrptg.lrc -> %System32%\igfxrptg.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrrus.lrc -> %System32%\igfxrrus.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrsve.lrc -> %System32%\igfxrsve.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrtha.lrc -> %System32%\igfxrtha.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrtrk.lrc -> %System32%\igfxrtrk.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxsrvc.dll -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 315392 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxtray.exe -> %System32%\igfxtray.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] javasup.vxd -> %System32%\javasup.vxd -> [Ver = | Size = 7315 bytes | Created Date = 23/07/2007 15:24:40 | Attr = ] minirec.exe -> %System32%\minirec.exe -> SmartLink [Ver = 1.0 (8.1.2001) | Size = 163840 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] mpeg2data.ax -> %System32%\mpeg2data.ax -> [Ver = | Size = 118272 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ] msdvbnp.ax -> %System32%\msdvbnp.ax -> [Ver = | Size = 56832 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ] ntio.sys -> %System32%\ntio.sys -> [Ver = | Size = 34000 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] ntio404.sys -> %System32%\ntio404.sys -> [Ver = | Size = 34560 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] ntio411.sys -> %System32%\ntio411.sys -> [Ver = | Size = 35648 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] ntio412.sys -> %System32%\ntio412.sys -> [Ver = | Size = 35424 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] ntio804.sys -> %System32%\ntio804.sys -> [Ver = | Size = 34560 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] PreInstall -> %System32%\PreInstall -> [Folder | Created Date = 23/07/2007 15:19:56 | Attr = ] psisdecd.dll -> %System32%\psisdecd.dll -> [Ver = | Size = 363520 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ] psisrndr.ax -> %System32%\psisrndr.ax -> [Ver = | Size = 33280 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ] QuickTime -> %System32%\QuickTime -> [Folder | Created Date = 14/07/2007 18:23:54 | Attr = ] ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Created Date = 14/07/2007 18:13:07 | Attr = ] sblfx.dll -> %System32%\sblfx.dll -> Creative Technology Ltd. [Ver = 5.12.01.3210 | Size = 495616 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] secupd.dat -> %System32%\secupd.dat -> [Ver = | Size = 4569 bytes | Created Date = 29/07/2007 20:02:52 | Attr = ] secupd.sig -> %System32%\secupd.sig -> [Ver = | Size = 7208 bytes | Created Date = 29/07/2007 20:02:52 | Attr = ] sfman32.dll -> %System32%\sfman32.dll -> Creative Technology Ltd. [Ver = 4.06.501 | Size = 51200 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] slcpappl.chm -> %System32%\slcpappl.chm -> [Ver = | Size = 136104 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] slcpappl.cpl -> %System32%\slcpappl.cpl -> SmartLink [Ver = 2, 92, 0, 2 | Size = 339968 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] SLLights.dll -> %System32%\SLLights.dll -> [Ver = 2, 0, 9, 9 | Size = 405504 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] slmh.cab -> %System32%\slmh.cab -> [Ver = | Size = 351388 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] slmh.exe -> %System32%\slmh.exe -> SmartLink [Ver = 2, 92, 0, 3 | Size = 372736 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] SoftwareDistribution -> %System32%\SoftwareDistribution -> [Folder | Created Date = 17/07/2007 08:12:20 | Attr = ] swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Created Date = 27/07/2007 21:12:18 | Attr = ] swsc.exe -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.0 | Size = 370688 bytes | Created Date = 27/07/2007 21:12:15 | Attr = ] swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 27/07/2007 21:12:15 | Attr = ] unacev2.dll -> %System32%\unacev2.dll -> [Ver = | Size = 75264 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ] UNRAR3.dll -> %System32%\UNRAR3.dll -> [Ver = | Size = 153088 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ] vfind.exe -> %System32%\vfind.exe -> [Ver = | Size = 49152 bytes | Created Date = 27/07/2007 21:12:18 | Attr = ] zonedoff.reg -> %System32%\zonedoff.reg -> [Ver = | Size = 113 bytes | Created Date = 23/07/2007 15:24:19 | Attr = ] zonedon.reg -> %System32%\zonedon.reg -> [Ver = | Size = 113 bytes | Created Date = 23/07/2007 15:24:20 | Attr = ] ztvunace26.dll -> %System32%\ztvunace26.dll -> [Ver = | Size = 77312 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ] ztvunrar36.dll -> %System32%\ztvunrar36.dll -> [Ver = | Size = 162304 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ] 2gmgsmt.sf2 -> %System32%\drivers\2gmgsmt.sf2 -> [Ver = | Size = 2104298 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] a302.sys -> %System32%\drivers\a302.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 11319 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a303.sys -> %System32%\drivers\a303.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 27703 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a304.sys -> %System32%\drivers\a304.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 45111 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a305.sys -> %System32%\drivers\a305.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 11319 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a306.sys -> %System32%\drivers\a306.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 16439 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a307.sys -> %System32%\drivers\a307.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 20535 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a308.sys -> %System32%\drivers\a308.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 10807 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a309.sys -> %System32%\drivers\a309.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 25655 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a310.sys -> %System32%\drivers\a310.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 32823 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a311.sys -> %System32%\drivers\a311.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 31799 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a312.sys -> %System32%\drivers\a312.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 10807 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a313.sys -> %System32%\drivers\a313.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 35895 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a314.sys -> %System32%\drivers\a314.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 17463 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ctlfacem.sys -> %System32%\drivers\ctlfacem.sys -> Creative Technology Ltd. [Ver = 5.12.01.2108 built by: WinDDK | Size = 6912 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] ctljystk.sys -> %System32%\drivers\ctljystk.sys -> Creative Technology Ltd. [Ver = 5.1.2501.0 built by: WinDDK | Size = 3712 bytes | Created Date = 14/07/2007 18:08:52 | Attr = ] emu10k1m.sys -> %System32%\drivers\emu10k1m.sys -> Creative Technology Ltd. [Ver = 5.12.01.3300 built by: WinDDK | Size = 283904 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] fbxusb.sys -> %System32%\drivers\fbxusb.sys -> FreeBox SA [Ver = 1.2.0.0 | Size = 18848 bytes | Created Date = 14/07/2007 19:31:27 | Attr = R ] ialmkchw.sys -> %System32%\drivers\ialmkchw.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 78144 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmnt5.sys -> %System32%\drivers\ialmnt5.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 87579 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmsbw.sys -> %System32%\drivers\ialmsbw.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 108480 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] KProcCheck.sys -> %System32%\drivers\KProcCheck.sys -> [Ver = | Size = 4096 bytes | Created Date = 26/07/2007 22:17:01 | Attr = ] netwlan5.img -> %System32%\drivers\netwlan5.img -> [Ver = | Size = 67866 bytes | Created Date = 29/07/2007 20:02:52 | Attr = ] sfmanm.sys -> %System32%\drivers\sfmanm.sys -> Creative Technology Ltd. [Ver = 4.10.3300 | Size = 36480 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] ssmdrv.sys -> %System32%\drivers\ssmdrv.sys -> Avira GmbH [Ver = 7.0.1.1 | Size = 28352 bytes | Created Date = 14/07/2007 18:50:45 | Attr = ] vch.sys -> %System32%\drivers\vch.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 20021 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] wa301a.sys -> %System32%\drivers\wa301a.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 30775 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] wa301b.sys -> %System32%\drivers\wa301b.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 30775 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] winddx.sys -> %System32%\drivers\winddx.sys -> Smart Link Ltd. [Ver = 2.80.02 | Size = 42328 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] [Files/Folders - Modified Within 30 days] 1d445837b1976b19ea6acbd2c817 -> %SystemDrive%\1d445837b1976b19ea6acbd2c817 -> [Folder | Modified Date = 16/07/2007 22:56:28 | Attr = ] APPS -> %SystemDrive%\APPS -> [Folder | Modified Date = 14/07/2007 19:24:22 | Attr = ] Bases -> %SystemDrive%\Bases -> [Folder | Modified Date = 17/07/2007 15:36:36 | Attr = ] BOOT.BAK -> %SystemDrive%\BOOT.BAK -> [Ver = | Size = 193 bytes | Modified Date = 14/07/2007 19:17:44 | Attr = RHS] BOOT.INI -> %SystemDrive%\BOOT.INI -> [Ver = | Size = 291 bytes | Modified Date = 30/07/2007 22:08:26 | Attr = RHS] cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 14/07/2007 19:22:10 | Attr = RHS] ComboFix -> %SystemDrive%\ComboFix -> [Folder | Modified Date = 27/07/2007 22:29:28 | Attr = ] DIVTOOLS -> %SystemDrive%\DIVTOOLS -> [Folder | Modified Date = 14/07/2007 17:58:00 | Attr = H ] Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 14/07/2007 19:43:22 | Attr = ] Downloads -> %SystemDrive%\Downloads -> [Folder | Modified Date = 26/07/2007 15:49:52 | Attr = ] DRIVERS -> %SystemDrive%\DRIVERS -> [Folder | Modified Date = 14/07/2007 19:44:30 | Attr = H ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 259575808 bytes | Modified Date = 01/08/2007 20:04:48 | Attr = HS] hijackthis -> %SystemDrive%\hijackthis -> [Folder | Modified Date = 16/07/2007 18:17:02 | Attr = ] IO.SYS -> %SystemDrive%\IO.SYS -> [Ver = | Size = 0 bytes | Modified Date = 29/07/2007 01:35:52 | Attr = RHS] Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Modified Date = 18/07/2007 09:48:56 | Attr = ] MSDOS.SYS -> %SystemDrive%\MSDOS.SYS -> [Ver = | Size = 0 bytes | Modified Date = 29/07/2007 01:35:52 | Attr = RHS] NTDETECT.COM -> %SystemDrive%\NTDETECT.COM -> [Ver = | Size = 47564 bytes | Modified Date = 30/07/2007 21:51:50 | Attr = RHS] PNP -> %SystemDrive%\PNP -> [Folder | Modified Date = 14/07/2007 17:58:46 | Attr = H ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 31/07/2007 22:01:20 | Attr = R ] QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 27/07/2007 22:14:56 | Attr = ] RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 14/07/2007 20:12:42 | Attr = HS] SDFix -> %SystemDrive%\SDFix -> [Folder | Modified Date = 01/08/2007 20:06:54 | Attr = ] System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 30/07/2007 22:46:06 | Attr = HS] UPDFLOP.TAG -> %SystemDrive%\UPDFLOP.TAG -> [Ver = | Size = 0 bytes | Modified Date = 14/07/2007 18:00:32 | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 01/08/2007 20:05:32 | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 01/08/2007 11:23:00 | Attr = H ] $MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Modified Date = 24/07/2007 10:10:04 | Attr = H ] $NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [Folder | Modified Date = 30/07/2007 21:50:26 | Attr = H ] $NtUninstallKB833987$ -> %SystemRoot%\$NtUninstallKB833987$ -> [Folder | Modified Date = 16/07/2007 22:54:20 | Attr = H ] $NtUninstallKB835409$ -> %SystemRoot%\$NtUninstallKB835409$ -> [Folder | Modified Date = 23/07/2007 16:15:26 | Attr = H ] $NtUninstallKB835732$ -> %SystemRoot%\$NtUninstallKB835732$ -> [Folder | Modified Date = 27/07/2007 20:18:26 | Attr = H ] $NtUninstallKB840987$ -> %SystemRoot%\$NtUninstallKB840987$ -> [Folder | Modified Date = 16/07/2007 22:58:52 | Attr = H ] $NtUninstallKB842773$ -> %SystemRoot%\$NtUninstallKB842773$ -> [Folder | Modified Date = 24/07/2007 10:10:54 | Attr = H ] $NtUninstallKB873339$ -> %SystemRoot%\$NtUninstallKB873339$ -> [Folder | Modified Date = 30/07/2007 22:15:54 | Attr = H ] $NtUninstallKB873339_0$ -> %SystemRoot%\$NtUninstallKB873339_0$ -> [Folder | Modified Date = 27/07/2007 20:17:18 | Attr = H ] $NtUninstallKB885835$ -> %SystemRoot%\$NtUninstallKB885835$ -> [Folder | Modified Date = 30/07/2007 22:16:22 | Attr = H ] $NtUninstallKB885835_0$ -> %SystemRoot%\$NtUninstallKB885835_0$ -> [Folder | Modified Date = 24/07/2007 10:13:46 | Attr = H ] $NtUninstallKB885836$ -> %SystemRoot%\$NtUninstallKB885836$ -> [Folder | Modified Date = 30/07/2007 22:17:20 | Attr = H ] $NtUninstallKB885836_0$ -> %SystemRoot%\$NtUninstallKB885836_0$ -> [Folder | Modified Date = 27/07/2007 20:18:52 | Attr = H ] $NtUninstallKB888302$ -> %SystemRoot%\$NtUninstallKB888302$ -> [Folder | Modified Date = 30/07/2007 22:17:36 | Attr = H ] $NtUninstallKB888302_0$ -> %SystemRoot%\$NtUninstallKB888302_0$ -> [Folder | Modified Date = 27/07/2007 20:10:50 | Attr = H ] $NtUninstallKB890046$ -> %SystemRoot%\$NtUninstallKB890046$ -> [Folder | Modified Date = 30/07/2007 22:17:52 | Attr = H ] $NtUninstallKB890046_0$ -> %SystemRoot%\$NtUninstallKB890046_0$ -> [Folder | Modified Date = 27/07/2007 20:13:12 | Attr = H ] $NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Modified Date = 30/07/2007 22:18:10 | Attr = H ] $NtUninstallKB890859_0$ -> %SystemRoot%\$NtUninstallKB890859_0$ -> [Folder | Modified Date = 27/07/2007 20:05:56 | Attr = H ] $NtUninstallKB891781$ -> %SystemRoot%\$NtUninstallKB891781$ -> [Folder | Modified Date = 30/07/2007 22:18:34 | Attr = H ] $NtUninstallKB891781_0$ -> %SystemRoot%\$NtUninstallKB891781_0$ -> [Folder | Modified Date = 27/07/2007 20:13:30 | Attr = H ] $NtUninstallKB893756$ -> %SystemRoot%\$NtUninstallKB893756$ -> [Folder | Modified Date = 30/07/2007 22:18:50 | Attr = H ] $NtUninstallKB893756_0$ -> %SystemRoot%\$NtUninstallKB893756_0$ -> [Folder | Modified Date = 27/07/2007 20:17:44 | Attr = H ] $NtUninstallKB896358$ -> %SystemRoot%\$NtUninstallKB896358$ -> [Folder | Modified Date = 30/07/2007 22:19:06 | Attr = H ] $NtUninstallKB896358_0$ -> %SystemRoot%\$NtUninstallKB896358_0$ -> [Folder | Modified Date = 24/07/2007 10:08:56 | Attr = H ] $NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Modified Date = 30/07/2007 22:19:22 | Attr = H ] $NtUninstallKB896423_0$ -> %SystemRoot%\$NtUninstallKB896423_0$ -> [Folder | Modified Date = 24/07/2007 10:11:30 | Attr = H ] $NtUninstallKB896424$ -> %SystemRoot%\$NtUninstallKB896424$ -> [Folder | Modified Date = 30/07/2007 22:19:42 | Attr = H ] $NtUninstallKB896424_0$ -> %SystemRoot%\$NtUninstallKB896424_0$ -> [Folder | Modified Date = 24/07/2007 10:12:12 | Attr = H ] $NtUninstallKB896428$ -> %SystemRoot%\$NtUninstallKB896428$ -> [Folder | Modified Date = 30/07/2007 22:20:44 | Attr = H ] $NtUninstallKB896428_0$ -> %SystemRoot%\$NtUninstallKB896428_0$ -> [Folder | Modified Date = 27/07/2007 20:09:18 | Attr = H ] $NtUninstallKB898458$ -> %SystemRoot%\$NtUninstallKB898458$ -> [Folder | Modified Date = 24/07/2007 10:08:20 | Attr = H ] $NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Modified Date = 23/07/2007 16:19:52 | Attr = H ] $NtUninstallKB899587$ -> %SystemRoot%\$NtUninstallKB899587$ -> [Folder | Modified Date = 30/07/2007 22:21:12 | Attr = H ] $NtUninstallKB899587_0$ -> %SystemRoot%\$NtUninstallKB899587_0$ -> [Folder | Modified Date = 24/07/2007 10:14:42 | Attr = H ] $NtUninstallKB899591$ -> %SystemRoot%\$NtUninstallKB899591$ -> [Folder | Modified Date = 30/07/2007 22:21:30 | Attr = H ] $NtUninstallKB899591_0$ -> %SystemRoot%\$NtUninstallKB899591_0$ -> [Folder | Modified Date = 24/07/2007 10:12:30 | Attr = H ] $NtUninstallKB900725$ -> %SystemRoot%\$NtUninstallKB900725$ -> [Folder | Modified Date = 30/07/2007 22:21:50 | Attr = H ] $NtUninstallKB900725_0$ -> %SystemRoot%\$NtUninstallKB900725_0$ -> [Folder | Modified Date = 23/07/2007 16:19:22 | Attr = H ] $NtUninstallKB901017$ -> %SystemRoot%\$NtUninstallKB901017$ -> [Folder | Modified Date = 30/07/2007 22:22:22 | Attr = H ] $NtUninstallKB901017_0$ -> %SystemRoot%\$NtUninstallKB901017_0$ -> [Folder | Modified Date = 27/07/2007 20:18:08 | Attr = H ] $NtUninstallKB901214$ -> %SystemRoot%\$NtUninstallKB901214$ -> [Folder | Modified Date = 30/07/2007 22:22:40 | Attr = H ] $NtUninstallKB901214_0$ -> %SystemRoot%\$NtUninstallKB901214_0$ -> [Folder | Modified Date = 27/07/2007 20:11:52 | Attr = H ] $NtUninstallKB902400$ -> %SystemRoot%\$NtUninstallKB902400$ -> [Folder | Modified Date = 30/07/2007 22:25:44 | Attr = H ] $NtUninstallKB902400_0$ -> %SystemRoot%\$NtUninstallKB902400_0$ -> [Folder | Modified Date = 27/07/2007 20:14:02 | Attr = H ] $NtUninstallKB904706$ -> %SystemRoot%\$NtUninstallKB904706$ -> [Folder | Modified Date = 23/07/2007 16:22:44 | Attr = H ] $NtUninstallKB905414$ -> %SystemRoot%\$NtUninstallKB905414$ -> [Folder | Modified Date = 30/07/2007 22:26:12 | Attr = H ] $NtUninstallKB905414_0$ -> %SystemRoot%\$NtUninstallKB905414_0$ -> [Folder | Modified Date = 23/07/2007 16:22:08 | Attr = H ] $NtUninstallKB905495$ -> %SystemRoot%\$NtUninstallKB905495$ -> [Folder | Modified Date = 27/07/2007 20:15:22 | Attr = H ] $NtUninstallKB905749$ -> %SystemRoot%\$NtUninstallKB905749$ -> [Folder | Modified Date = 30/07/2007 22:26:38 | Attr = H ] $NtUninstallKB905749_0$ -> %SystemRoot%\$NtUninstallKB905749_0$ -> [Folder | Modified Date = 27/07/2007 20:09:34 | Attr = H ] $NtUninstallKB908519$ -> %SystemRoot%\$NtUninstallKB908519$ -> [Folder | Modified Date = 30/07/2007 22:27:06 | Attr = H ] $NtUninstallKB908519_0$ -> %SystemRoot%\$NtUninstallKB908519_0$ -> [Folder | Modified Date = 27/07/2007 20:08:56 | Attr = H ] $NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Modified Date = 30/07/2007 22:27:36 | Attr = H ] $NtUninstallKB908531_0$ -> %SystemRoot%\$NtUninstallKB908531_0$ -> [Folder | Modified Date = 23/07/2007 16:17:04 | Attr = H ] $NtUninstallKB910437$ -> %SystemRoot%\$NtUninstallKB910437$ -> [Folder | Modified Date = 30/07/2007 22:27:54 | Attr = H ] $NtUninstallKB910437_0$ -> %SystemRoot%\$NtUninstallKB910437_0$ -> [Folder | Modified Date = 27/07/2007 20:15:48 | Attr = H ] $NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Modified Date = 30/07/2007 22:28:14 | Attr = H ] $NtUninstallKB911280_0$ -> %SystemRoot%\$NtUninstallKB911280_0$ -> [Folder | Modified Date = 24/07/2007 10:11:50 | Attr = H ] $NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Modified Date = 30/07/2007 22:28:30 | Attr = H ] $NtUninstallKB911562_0$ -> %SystemRoot%\$NtUninstallKB911562_0$ -> [Folder | Modified Date = 27/07/2007 20:17:32 | Attr = H ] $NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Modified Date = 23/07/2007 16:27:04 | Attr = H ] $NtUninstallKB911565$ -> %SystemRoot%\$NtUninstallKB911565$ -> [Folder | Modified Date = 30/07/2007 23:11:30 | Attr = H ] $NtUninstallKB911567-OE6SP1-20060316.165634$ -> %SystemRoot%\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> [Folder | Modified Date = 27/07/2007 20:09:56 | Attr = H ] $NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Modified Date = 30/07/2007 22:28:46 | Attr = H ] $NtUninstallKB911927_0$ -> %SystemRoot%\$NtUninstallKB911927_0$ -> [Folder | Modified Date = 24/07/2007 10:13:04 | Attr = H ] $NtUninstallKB912919$ -> %SystemRoot%\$NtUninstallKB912919$ -> [Folder | Modified Date = 30/07/2007 22:29:04 | Attr = H ] $NtUninstallKB912919_0$ -> %SystemRoot%\$NtUninstallKB912919_0$ -> [Folder | Modified Date = 27/07/2007 20:10:28 | Attr = H ] $NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Modified Date = 30/07/2007 22:29:20 | Attr = H ] $NtUninstallKB913580_0$ -> %SystemRoot%\$NtUninstallKB913580_0$ -> [Folder | Modified Date = 23/07/2007 16:16:16 | Attr = H ] $NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Modified Date = 30/07/2007 22:29:38 | Attr = H ] $NtUninstallKB914388_0$ -> %SystemRoot%\$NtUninstallKB914388_0$ -> [Folder | Modified Date = 27/07/2007 20:12:52 | Attr = H ] $NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Modified Date = 30/07/2007 22:29:54 | Attr = H ] $NtUninstallKB914389_0$ -> %SystemRoot%\$NtUninstallKB914389_0$ -> [Folder | Modified Date = 27/07/2007 20:07:42 | Attr = H ] $NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Modified Date = 30/07/2007 22:30:10 | Attr = H ] $NtUninstallKB917344_0$ -> %SystemRoot%\$NtUninstallKB917344_0$ -> [Folder | Modified Date = 27/07/2007 20:12:30 | Attr = H ] $NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Modified Date = 30/07/2007 22:30:26 | Attr = H ] $NtUninstallKB917422_0$ -> %SystemRoot%\$NtUninstallKB917422_0$ -> [Folder | Modified Date = 27/07/2007 20:11:28 | Attr = H ] $NtUninstallKB917734_WMP8$ -> %SystemRoot%\$NtUninstallKB917734_WMP8$ -> [Folder | Modified Date = 23/07/2007 16:21:38 | Attr = H ] $NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Modified Date = 30/07/2007 22:30:42 | Attr = H ] $NtUninstallKB917953_0$ -> %SystemRoot%\$NtUninstallKB917953_0$ -> [Folder | Modified Date = 27/07/2007 20:12:10 | Attr = H ] $NtUninstallKB918439-IE6SP1-20060530.145346$ -> %SystemRoot%\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> [Folder | Modified Date = 27/07/2007 20:16:10 | Attr = H ] $NtUninstallKB918899-IE6SP1-20060725.123917$ -> %SystemRoot%\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> [Folder | Modified Date = 23/07/2007 16:18:04 | Attr = H ] $NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Modified Date = 30/07/2007 22:31:10 | Attr = H ] $NtUninstallKB919007_0$ -> %SystemRoot%\$NtUninstallKB919007_0$ -> [Folder | Modified Date = 23/07/2007 16:23:20 | Attr = H ] $NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Modified Date = 30/07/2007 22:31:28 | Attr = H ] $NtUninstallKB920670_0$ -> %SystemRoot%\$NtUninstallKB920670_0$ -> [Folder | Modified Date = 23/07/2007 16:25:58 | Attr = H ] $NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Modified Date = 30/07/2007 22:31:52 | Attr = H ] $NtUninstallKB920683_0$ -> %SystemRoot%\$NtUninstallKB920683_0$ -> [Folder | Modified Date = 23/07/2007 16:14:36 | Attr = H ] $NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Modified Date = 30/07/2007 22:32:10 | Attr = H ] $NtUninstallKB920685_0$ -> %SystemRoot%\$NtUninstallKB920685_0$ -> [Folder | Modified Date = 27/07/2007 20:17:56 | Attr = H ] $NtUninstallKB921398$ -> %SystemRoot%\$NtUninstallKB921398$ -> [Folder | Modified Date = 30/07/2007 23:12:10 | Attr = H ] $NtUninstallKB921883$ -> %SystemRoot%\$NtUninstallKB921883$ -> [Folder | Modified Date = 30/07/2007 22:32:28 | Attr = H ] $NtUninstallKB921883_0$ -> %SystemRoot%\$NtUninstallKB921883_0$ -> [Folder | Modified Date = 27/07/2007 20:18:40 | Attr = H ] $NtUninstallKB922616$ -> %SystemRoot%\$NtUninstallKB922616$ -> [Folder | Modified Date = 30/07/2007 22:32:44 | Attr = H ] $NtUninstallKB922616_0$ -> %SystemRoot%\$NtUninstallKB922616_0$ -> [Folder | Modified Date = 24/07/2007 10:12:46 | Attr = H ] $NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Modified Date = 30/07/2007 22:33:04 | Attr = H ] $NtUninstallKB922819_0$ -> %SystemRoot%\$NtUninstallKB922819_0$ -> [Folder | Modified Date = 24/07/2007 10:14:18 | Attr = H ] $NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Modified Date = 30/07/2007 22:33:22 | Attr = H ] $NtUninstallKB923191_0$ -> %SystemRoot%\$NtUninstallKB923191_0$ -> [Folder | Modified Date = 23/07/2007 16:20:18 | Attr = H ] $NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Modified Date = 30/07/2007 22:33:38 | Attr = H ] $NtUninstallKB923414_0$ -> %SystemRoot%\$NtUninstallKB923414_0$ -> [Folder | Modified Date = 24/07/2007 10:13:22 | Attr = H ] $NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Modified Date = 30/07/2007 22:33:52 | Attr = H ] $NtUninstallKB924191_0$ -> %SystemRoot%\$NtUninstallKB924191_0$ -> [Folder | Modified Date = 27/07/2007 20:20:20 | Attr = H ] $NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Modified Date = 30/07/2007 22:34:08 | Attr = H ] $NtUninstallKB924496_0$ -> %SystemRoot%\$NtUninstallKB924496_0$ -> [Folder | Modified Date = 27/07/2007 20:17:02 | Attr = H ] $NtUninstallKB925486-IE6SP1-20060918.120000$ -> %SystemRoot%\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> [Folder | Modified Date = 24/07/2007 10:10:34 | Attr = H ] $NtUninstallQ327979$ -> %SystemRoot%\$NtUninstallQ327979$ -> [Folder | Modified Date = 14/07/2007 19:11:52 | Attr = H ] $NtUninstallq330512$ -> %SystemRoot%\$NtUninstallq330512$ -> [Folder | Modified Date = 14/07/2007 19:12:02 | Attr = H ] $NtUninstallQ330909$ -> %SystemRoot%\$NtUninstallQ330909$ -> [Folder | Modified Date = 14/07/2007 19:12:10 | Attr = H ] $NtUninstallQ331060$ -> %SystemRoot%\$NtUninstallQ331060$ -> [Folder | Modified Date = 14/07/2007 19:12:16 | Attr = H ] $NtUninstallQ331816$ -> %SystemRoot%\$NtUninstallQ331816$ -> [Folder | Modified Date = 14/07/2007 19:12:24 | Attr = H ] $NtUninstallQ810020$ -> %SystemRoot%\$NtUninstallQ810020$ -> [Folder | Modified Date = 14/07/2007 19:12:30 | Attr = H ] $NtUninstallQ815411$ -> %SystemRoot%\$NtUninstallQ815411$ -> [Folder | Modified Date = 14/07/2007 19:12:36 | Attr = H ] AcrobatSetupStatus.ini -> %SystemRoot%\AcrobatSetupStatus.ini -> [Ver = | Size = 72 bytes | Modified Date = 14/07/2007 19:23:18 | Attr = ] AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 30/07/2007 22:46:02 | Attr = ] bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 01/08/2007 20:04:54 | Attr = S] catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Modified Date = 20/07/2007 00:47:24 | Attr = ] CDE CX6600FGD.ini -> %SystemRoot%\CDE CX6600FGD.ini -> [Ver = | Size = 25 bytes | Modified Date = 14/07/2007 23:12:48 | Attr = ] Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 30/07/2007 22:48:44 | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 23/07/2007 16:25:26 | Attr = S] Drivers -> %SystemRoot%\Drivers -> [Folder | Modified Date = 14/07/2007 19:15:48 | Attr = ] EHome -> %SystemRoot%\EHome -> [Folder | Modified Date = 30/07/2007 21:45:12 | Attr = ] erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 27/07/2007 22:18:36 | Attr = ] ERUNT -> %SystemRoot%\ERUNT -> [Folder | Modified Date = 29/07/2007 01:35:32 | Attr = ] Favoris -> %SystemRoot%\Favoris -> [Folder | Modified Date = 01/08/2007 14:20:44 | Attr = R ] Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 31/07/2007 15:59:20 | Attr = R S] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 30/07/2007 22:05:28 | Attr = ] ime -> %SystemRoot%\ime -> [Folder | Modified Date = 30/07/2007 22:05:10 | Attr = ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 30/07/2007 23:11:48 | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 01/08/2007 11:23:56 | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 01/08/2007 19:52:08 | Attr = HS] Media -> %SystemRoot%\Media -> [Folder | Modified Date = 30/07/2007 22:04:14 | Attr = ] Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 31/07/2007 22:51:30 | Attr = ] Modio -> %SystemRoot%\Modio -> [Folder | Modified Date = 14/07/2007 19:13:00 | Attr = ] msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 30/07/2007 22:46:02 | Attr = ] ODBC.INI -> %SystemRoot%\ODBC.INI -> [Ver = | Size = 385 bytes | Modified Date = 31/07/2007 15:53:02 | Attr = ] peernet -> %SystemRoot%\peernet -> [Folder | Modified Date = 30/07/2007 22:04:16 | Attr = ] Profiles -> %SystemRoot%\Profiles -> [Folder | Modified Date = 14/07/2007 19:23:12 | Attr = ] provisioning -> %SystemRoot%\provisioning -> [Folder | Modified Date = 30/07/2007 22:04:14 | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Modified Date = 24/07/2007 11:09:06 | Attr = ] RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Modified Date = 14/07/2007 19:15:34 | Attr = ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 14/07/2007 19:42:14 | Attr = ] REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Modified Date = 14/07/2007 19:29:02 | Attr = ] RESTORE.INS -> %SystemRoot%\RESTORE.INS -> [Ver = | Size = 1501198 bytes | Modified Date = 14/07/2007 19:26:26 | Attr = ] security -> %SystemRoot%\security -> [Folder | Modified Date = 31/07/2007 23:10:50 | Attr = ] ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [Folder | Modified Date = 30/07/2007 21:57:30 | Attr = ] setupapi.log.0.old -> %SystemRoot%\setupapi.log.0.old -> [Ver = | Size = 1595275 bytes | Modified Date = 16/07/2007 22:55:14 | Attr = ] ShellNew -> %SystemRoot%\ShellNew -> [Folder | Modified Date = 31/07/2007 15:51:36 | Attr = ] smscfg.ini -> %SystemRoot%\smscfg.ini -> [Ver = | Size = 61 bytes | Modified Date = 14/07/2007 19:26:50 | Attr = ] SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 17/07/2007 09:12:30 | Attr = ] srchasst -> %SystemRoot%\srchasst -> [Folder | Modified Date = 30/07/2007 21:56:38 | Attr = ] system -> %SystemRoot%\system -> [Folder | Modified Date = 31/07/2007 15:47:46 | Attr = ] system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 231 bytes | Modified Date = 14/07/2007 19:29:10 | Attr = ] system32 -> %System32% -> [Folder | Modified Date = 01/08/2007 20:07:18 | Attr = ] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 01/08/2007 21:06:58 | Attr = ] twain_32 -> %SystemRoot%\twain_32 -> [Folder | Modified Date = 14/07/2007 23:13:24 | Attr = ] Web -> %SystemRoot%\Web -> [Folder | Modified Date = 30/07/2007 21:52:18 | Attr = R ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 635 bytes | Modified Date = 01/08/2007 11:23:30 | Attr = ] WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 30/07/2007 22:06:04 | Attr = ] WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Modified Date = 30/07/2007 22:48:02 | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 26/07/2007 17:49:30 | Attr = H ] $ncsp$.inf -> %System32%\$ncsp$.inf -> [Ver = | Size = 333 bytes | Modified Date = 14/07/2007 19:26:46 | Attr = ] $winnt$.inf -> %System32%\$winnt$.inf -> [Ver = | Size = 497 bytes | Modified Date = 14/07/2007 19:43:10 | Attr = ] bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Modified Date = 01/08/2007 21:06:38 | Attr = ] bits -> %System32%\bits -> [Folder | Modified Date = 24/07/2007 10:10:56 | Attr = ] CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 30/07/2007 23:12:02 | Attr = ] CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 01/08/2007 11:22:36 | Attr = ] Com -> %System32%\Com -> [Folder | Modified Date = 30/07/2007 22:25:50 | Attr = ] config -> %System32%\config -> [Folder | Modified Date = 27/07/2007 22:18:42 | Attr = ] dllcache -> %System32%\dllcache -> [Folder | Modified Date = 30/07/2007 23:12:14 | Attr = RHS] drivers -> %System32%\drivers -> [Folder | Modified Date = 30/07/2007 22:45:58 | Attr = ] EPPRTDRV.CAB -> %System32%\EPPRTDRV.CAB -> [Ver = | Size = 288201 bytes | Modified Date = 14/07/2007 23:14:06 | Attr = ] EPSETUP.CAB -> %System32%\EPSETUP.CAB -> [Ver = | Size = 443573 bytes | Modified Date = 14/07/2007 23:14:04 | Attr = ] EPSTP32U.CAB -> %System32%\EPSTP32U.CAB -> [Ver = | Size = 591071 bytes | Modified Date = 14/07/2007 23:14:02 | Attr = ] eps_icon.avi -> %System32%\eps_icon.avi -> [Ver = | Size = 8284 bytes | Modified Date = 14/07/2007 23:14:04 | Attr = ] FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 112584 bytes | Modified Date = 31/07/2007 22:51:22 | Attr = ] Macromed -> %System32%\Macromed -> [Folder | Modified Date = 14/07/2007 19:24:36 | Attr = ] mui -> %System32%\mui -> [Folder | Modified Date = 30/07/2007 22:05:10 | Attr = ] npp -> %System32%\npp -> [Folder | Modified Date = 30/07/2007 21:56:42 | Attr = ] oobe -> %System32%\oobe -> [Folder | Modified Date = 30/07/2007 22:05:22 | Attr = ] perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 39992 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ] perfc00C.dat -> %System32%\perfc00C.dat -> [Ver = | Size = 48616 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ] perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 311604 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ] perfh00C.dat -> %System32%\perfh00C.dat -> [Ver = | Size = 367658 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ] PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 775034 bytes | Modified Date = 30/07/2007 23:08:52 | Attr = ] PreInstall -> %System32%\PreInstall -> [Folder | Modified Date = 23/07/2007 16:19:58 | Attr = ] QuickTime -> %System32%\QuickTime -> [Folder | Modified Date = 14/07/2007 19:24:06 | Attr = ] ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 30/07/2007 21:50:50 | Attr = ] Restore -> %System32%\Restore -> [Folder | Modified Date = 30/07/2007 21:56:42 | Attr = ] Setup -> %System32%\Setup -> [Folder | Modified Date = 30/07/2007 22:05:12 | Attr = ] SoftwareDistribution -> %System32%\SoftwareDistribution -> [Folder | Modified Date = 17/07/2007 09:12:22 | Attr = ] swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 22/07/2007 18:39:28 | Attr = ] usmt -> %System32%\usmt -> [Folder | Modified Date = 30/07/2007 21:55:04 | Attr = ] wbem -> %System32%\wbem -> [Folder | Modified Date = 30/07/2007 22:46:42 | Attr = ] wmpscheme.xml -> %System32%\wmpscheme.xml -> [Ver = | Size = 25065 bytes | Modified Date = 14/07/2007 19:43:30 | Attr = ] wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1170 bytes | Modified Date = 30/07/2007 22:47:46 | Attr = ] etc -> %System32%\drivers\etc -> [Folder | Modified Date = 01/08/2007 19:59:38 | Attr = ] [File String Scan - Non-Microsoft Only] PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41131 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ] UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 22/07/2007 18:39:28 | Attr = ] winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ] PTech , -> %System32%\drivers\mtlstrm.sys -> [Ver = 3.00.01 | Size = 1805544 bytes | Modified Date = 18/04/2002 09:58:02 | Attr = ] < End of report > je lance panda et je reposte, @+
  19. Merci Jok voilà donc le dernier résultat.txt. DiagHelp version v1.1.2 - http://www.malekal.com excute le 31/07/2007 à 22:49:10,48 Liste des derniers fichies modifies/crees dans windir\system32 C:\WINDOWS\System32/drivers\ssmdrv.sys -->01/03/2007 10:34:36 C:\WINDOWS\System32/drivers\tcpip6.sys -->16/08/2006 11:37:30 C:\WINDOWS\System32/drivers\srv.sys -->14/08/2006 12:34:41 C:\WINDOWS\System32/drivers\rmcast.sys -->13/07/2006 10:48:58 C:\WINDOWS\System32/drivers\rdbss.sys -->05/05/2006 11:47:57 C:\WINDOWS\System32/drivers\mrxsmb.sys -->05/05/2006 11:41:45 C:\WINDOWS\System32/drivers\tcpip.sys -->20/04/2006 13:51:50 C:\WINDOWS\System32\bdod.bin -->31/07/2007 22:45:06 C:\WINDOWS\System32\bdss.log -->31/07/2007 20:40:47 C:\WINDOWS\System32\PerfStringBackup.INI -->30/07/2007 23:08:50 C:\WINDOWS\System32\perfh00C.dat -->30/07/2007 23:08:50 C:\WINDOWS\System32\perfh009.dat -->30/07/2007 23:08:50 C:\WINDOWS\System32\perfc00C.dat -->30/07/2007 23:08:50 C:\WINDOWS\System32\perfc009.dat -->30/07/2007 23:08:50 C:\WINDOWS\System32\wpa.dbl -->30/07/2007 22:47:44 C:\WINDOWS\System32\spupdwxp.log -->30/07/2007 22:46:37 C:\WINDOWS\System32\FNTCACHE.DAT -->30/07/2007 22:46:03 C:\WINDOWS\System32\x -->24/07/2007 18:49:32 C:\WINDOWS\System32\swreg.exe -->22/07/2007 18:39:27 C:\WINDOWS\System32\EPPRTDRV.CAB -->14/07/2007 23:14:05 C:\WINDOWS\System32\eps_icon.avi -->14/07/2007 23:14:03 C:\WINDOWS\System32\EPSETUP.CAB -->14/07/2007 23:14:03 C:\WINDOWS\System32\EPSTP32U.CAB -->14/07/2007 23:14:00 C:\WINDOWS\System32\wmpscheme.xml -->14/07/2007 19:43:28 C:\WINDOWS\System32\$winnt$.inf -->14/07/2007 19:43:09 C:\WINDOWS\System32\$ncsp$.inf -->14/07/2007 19:26:44 C:\WINDOWS\System32\qtplugin.log -->14/07/2007 19:24:13 C:\WINDOWS\System32\MRT.exe -->28/06/2007 00:57:28 C:\WINDOWS\System32\wups.dll -->16/04/2007 22:47:36 C:\WINDOWS\System32\wuaucpl.cpl.mui -->16/04/2007 22:47:26 C:\WINDOWS\System32\wuapi.dll.mui -->16/04/2007 22:46:54 C:\WINDOWS\System32\wuaueng.dll -->16/04/2007 22:45:54 C:\WINDOWS\wiadebug.log -->31/07/2007 21:54:51 C:\WINDOWS\WindowsUpdate.log -->31/07/2007 19:41:01 C:\WINDOWS\ODBC.INI -->31/07/2007 15:53:00 C:\WINDOWS\win.ini -->31/07/2007 15:12:16 C:\WINDOWS.log -->31/07/2007 14:57:30 C:\WINDOWS\wiaservc.log -->31/07/2007 14:57:06 C:\WINDOWS\spupdsvc.log -->31/07/2007 14:57:04 C:\WINDOWS\bootstat.dat -->31/07/2007 14:56:49 C:\WINDOWS\ntdtcsetup.log -->30/07/2007 23:12:20 C:\WINDOWS\iis6.log -->30/07/2007 23:12:20 C:\WINDOWS\comsetup.log -->30/07/2007 23:12:20 C:\WINDOWS\tsoc.log -->30/07/2007 23:12:19 C:\WINDOWS\ocmsn.log -->30/07/2007 23:12:19 C:\WINDOWS\ocgen.log -->30/07/2007 23:12:19 C:\WINDOWS\msgsocm.log -->30/07/2007 23:12:19 Le volume dans le lecteur C s'appelle HDD Le numéro de série du volume est 6C2E-CFA4 Répertoire de C:\WINDOWS\system32 20/08/2004 01:09 6 144 csrss.exe 1 fichier(s) 6 144 octets 0 Rép(s) 31 694 012 416 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C s'appelle HDD Le numéro de série du volume est 6C2E-CFA4 Répertoire de C:\WINDOWS\Downloaded Program Files 23/07/2007 16:25 <REP> . 23/07/2007 16:25 <REP> .. 30/09/2002 13:03 65 desktop.ini 14/10/1997 18:52 697 DirectAnimation Java Classes.osd 20/01/2000 15:25 1 162 Microsoft XML Parser for Java.osd 11/06/2007 12:21 5 021 swflash.inf 4 fichier(s) 6 945 octets Total des fichiers listés : 4 fichier(s) 6 945 octets 2 Rép(s) 31 694 012 416 octets libres Recherche de rootkit! (Merci S!Ri) Recherche d'infections connues Export des clefs sensibles.. Liste des fichiers en exception sur le pare-feu XP SP2 "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Export de la clef SharedTaskScheduler [sharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" Rechercher adresses sensibles dans le fichier HOSTS... Suis-je débarrassée des virus ?? Merci encore pour votre aide à tous, vous rendez l'informatique plus douce (pour des boulets comme moi, bien sûr..)
  20. salut charles, je dois être vraiment nouille mais j'ai encore un rapport diaghelp incomplet. Pourtant, j'appuie bien sur entrée (le panneau est rouge avec le nombre de fichiers cachés à la fin), ça reboote, et après j'ouvre mon rapport catchme incomplet. Je loupe une étape ?? Merci pour la ram je vais voir si je trouve des barettes compatibles. Comment on fait pour le rapport diaghelp ??
  21. hello, Charles, plus de port ouvert tt est ok. Voici le dernier Diaghelp : catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-30 23:01:46 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch] "Epoch"=dword:00002d01 scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden files: 0 j'ai bien désinstallé mIRC ? Est ce que tu avais ce problème en arrivant sur le forum ? as tu fait des modifications au niveau du fichier d'échange ? J'avais bien ce pbl de mémoire, c'est récurrent. Je n'ai fait aucune modif sur le fichier d'échange. Je dois ?? Est-ce que tu peux m'expliquer comment marche secunia ??
  22. hello, Est ce que tu as pû expédier le fichier demandé ? > sohbet.exe Si tu n'a pas pû le faire, expédie stp la copie que tu trouveras dans le dossier sur ton bureau > WinPFind3u\MovedFiles\WINDOWS\sohbet.exe (envoie aussi Sohbet-Script ) envoie les à la même adresse stp. C'est fait mais sohbet-script non c'est un répertoire, pas de fichier à ce nom. J'aimerai stp que tu fasses ce scan rapide des ports de ton pc pour voir si celui ci est bien protégé par BitDefender > voila le rapport : Attention ! Il existe un ou plusieurs ports ouverts ainsi que un ou plusieurs ports détectés comme fermés ! Un ou plusieurs ports ont répondu aux test, cela signifie qu'ils sont ouvert. Un port ouvert permet aux pirates potentiels d'accéder facilement à votre machine. De plus, un ou plusieurs ports fermés ont également été détecté. Bien qu'il soit protégé, un port fermé reste visible, un pirate potentiel peut donc tenter d'attaquer votre machine. Il est vivement conseillé de masquer (ou à défaut fermer) ces ports ou de modifier la configuration de votre firewall. Ports TCP ouverts 135 N/A Utilisé pour les applications client/server basées sur des systèmes d'exploitation Microsoft Trojans possibles : W32.Blaster.Worm, W32/Lovsan.worm 139 netbios-ssn Utilisé pour le partage de fichiers dans un réseau local Trojans possibles : Chode, God Message worm, Msinit, Netlog, Network, Qaz, Sadmind, SMB Relay Ports TCP fermés 21 ftp Utilisé pour le transfert de fichier entre ordinateurs Trojans possibles : Back Construction, Blade Runner, Cattivik FTP Server, CC Invader, Dark FTP, Doly Trojan, Fore, FreddyK, Invisible FTP, Juggernaut 42, Larva, MotIv FTP, Net Administrator, Ramen, RTB 666, Senna Spy FTP server, The Flu, Traitor 21, WebEx, WinCrash 22 ssh Le shell SSH permet de se connecter à un serveur de façon sécurisée Trojans possibles : Adore sshd, Shaft 23 telnet Utilisé pour obtenir un shell distant Trojans possibles : ADM worm, Fire HacKer, My Very Own trojan, RTB 666, Telnet Pro, Tiny Telnet Server - TTS, Truva Atl 25 smtp Utilisé pour le transfert de courrier électronique entre deux hôtes. Si vous n'utilisez pas de serveur de messagerie, il est conseillé de fermer ce port. Trojans possibles : Ajan, Antigen, Barok, BSE, Email Password Sender - EPS, EPS II, Gip, Gris, Happy99, Hpteam mail, Hybris, I love you, Kuang2, Magic Horse, MBT (Mail Bombing Trojan), Moscow Email trojan, Naebi, NewApt worm, ProMail trojan, Shtirlitz, Stealth, Stukach, Tapiras, Terminator, WinPC, WinSpy 79 finger Permet de connaître diverses informations relatives à votre profil Trojans possibles : CDK, Firehotcker 80 http Utilisé pour les services Web. Si vous n'utilisez pas de serveur web, il est conseillé de fermer ce port Trojans possibles : 711 trojan (Seven Eleven), AckCmd, Back End, Back Orifice 2000 Plug-Ins, Cafeini, CGI Backdoor, Code Red, Executor, God Message, God Message 4 Creator, Hooker, IISworm, MTX, NCX, Nimda, Noob, Ramen, Reverse WWW Tunnel Backdoor, RingZero, RTB 666, Seeker, WAN Remote, Web Server CT, WebDownloader 110 pop3 Utilisé par les serveurs de messagerie Internet. Si vous n'utilisez pas de serveur de messagerie, il est conseillé de fermer ce port. Trojans possibles : ProMail trojan 113 auth Utilisé par certains serveurs de messagerie ou de newsgroups (MiRC - Virc...). Des problèmes de performances peuvent survenir si ce port est masqué Trojans possibles : Invisible Identd Deamon, Kazimas 119 nntp Utilisé par les serveurs de news pour la distribution d'articles Usenet Trojans possibles : Happy99 143 imap Utilisé par les serveurs de messagerie Internet pour l'envoi de messages électroniques. Si vous n'utilisez pas de serveur IMAP, il est conseillé de fermer ce port. Trojans possibles : N/A 389 ldap LDAP (Lightweight Directory Access Protocol) : utilisé pour accéder automatiquement à des services d'annuaires en ligne Trojans possibles : N/A 443 https Utilisé pour sécuriser les communications HTTP. Si vous n'utilisez pas de serveur web, il est conseillé de fermer ce port. Ce port est également utilisé par AOL Instant Messenger Trojans possibles : N/A 445 microsoft-ds Utilisé pour le partage des protocoles SMB. Son exploitation peut permettre d'obtenir vos mots de passe Trojans possibles : Lioten, Randon, WORM_DELODER.A, W32/Deloder.A, W32.HLLW.Deloder 1002 N/A Port non standard Trojans possibles : N/A 1024 N/A Port réservé Trojans possibles : Jade, Latinus, NetSpy, Remote Administration Tool - RAT [no 2] 1025 N/A Port non standard Trojans possibles : Fraggle Rock, md5 Backdoor, NetSpy, Remote Storm 1026 N/A Port non standard Trojans possibles : N/A 1027 N/A Port non standard Trojans possibles : ICKiller 1028 N/A Port non standard Trojans possibles : N/A 1029 N/A Port non standard Trojans possibles : InCommand Access, ICQ Nuke 98 1030 N/A Port non standard Trojans possibles : N/A 1720 h323hostcall Port non standard. Peut être utilisé par NetMeeting Trojans possibles : N/A 5000 N/A Utilisé pour communiquer avec tous les périphériques UpnP reliés à votre réseau Trojans possibles : Back Door Setup, BioNet Lite, Blazer5, Bubbel, ICKiller, Ra1d, Sockets des Troie Ports TCP masqués Aucun port détecté Poste stp un dernier rapport DiagHelp pour vérification. voilà le rapport, mais incomplet il me reboote tjs qd je valide. J'ai tjs un message de mémoire virtuelle minimale insuffisante, qu'est-ce qu'il faut faire ? cela ne vient pas encore d'un virus ?? Zonk m'avait conseillé Secunia, mais comment ça marche ? qd je fait scan now, rien ne se passe ?? Merci à +
  23. hello, voici les rapports : report.txt : SDFix: Version 1.94 Run by romestan on 29/07/2007 at 01:36 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Name: Seagate Communication ImagePath: "C:\WINDOWS\System32\dllcache\seagatecom.exe" Seagate Communication - Deleted Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting... Normal Mode: Checking Files: Trojan Files Found: C:\WINDOWS\system32\i - Deleted C:\WINDOWS\system32\o - Deleted Removing Temp Files... ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] Remaining Files: --------------- Backups Folder: - C:\SDFix\backups\backups.zip Files with Hidden Attributes: C:\Documents and Settings\romestan\Bureau\WinPFind3u\MovedFiles\WINDOWS\2pack.exe C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0004.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0284.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL0292.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL1758.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3125.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3375.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Chris\Organisation\~WRL3690.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\Peyrolles\~WRL0796.tmp C:\Documents and Settings\romestan\Mes documents\Mes fichiers\tsouin tsouin\~WRL3039.tmp C:\WINDOWS\system32\config\DEFAULT.tmp.LOG C:\WINDOWS\system32\config\SAM.tmp.LOG C:\WINDOWS\system32\config\SECURITY.tmp.LOG C:\WINDOWS\system32\config\SOFTWARE.tmp.LOG C:\WINDOWS\system32\config\SYSTEM.tmp.LOG Finished win : [Processes - Non-Microsoft Only] Unable to kill process 2pack.exe . C:\WINDOWS\2pack.exe moved successfully. Unable to kill process 2pack.exe . File C:\WINDOWS\2pack.exe not found. [Win32 Services - Non-Microsoft Only] Service ChanSirv stopped successfully. Service ChanSirv deleted successfully. File C:\WINDOWS\2pack.exe not found. [Registry - Additional Scans - Non-Microsoft Only] Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\2pack.exe deleted successfully. File C:\WINDOWS\2pack.exe:*:Enabled:Chan Services For Win32 not found. [Files/Folders - Created Within 30 days] C:\Sohbet Chat.lnk moved successfully. C:\Sohbet-Script\sounds moved successfully. C:\Sohbet-Script\logs moved successfully. C:\Sohbet-Script\download moved successfully. C:\Sohbet-Script\DLL moved successfully. C:\Sohbet-Script\Code\text moved successfully. C:\Sohbet-Script\Code\ses moved successfully. C:\Sohbet-Script\Code\resim moved successfully. C:\Sohbet-Script\Code\korumalar moved successfully. C:\Sohbet-Script\Code\ini moved successfully. C:\Sohbet-Script\Code\icon moved successfully. C:\Sohbet-Script\Code\html moved successfully. C:\Sohbet-Script\Code\addon moved successfully. C:\Sohbet-Script\Code moved successfully. C:\Sohbet-Script\channels moved successfully. C:\Sohbet-Script moved successfully. C:\sohbet.exe moved successfully. [Files/Folders - Modified Within 30 days] File C:\Sohbet Chat.lnk not found! File C:\Sohbet-Script not found! File C:\sohbet.exe not found! < End of log > Created on 07/29/2007 01:29:51 et hijackthis : Logfile of HijackThis v1.99.1 Scan saved at 02:03:55, on 29/07/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\WINDOWS\System32\devldr32.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\romestan\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing) O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) non je n'utilise pas mIRC, je sais meme pas ce que c'est. comment c'est arrivé dans ma pacoule ?? Est-ce que mon cauchemar est terminé ??
  24. [salut zonk, j'ai pas bien compris comment marchait Secunia. Qd je clique sur Start now, il ne se passe rien ??
  25. j'ai aussi envoyé sur bleeping un fichier qui apparemment ouvre un serveur croate ou turc : sohbet.exe Tu pourras me donner le résultat ? merci
×
×
  • Créer...