Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

please check this out going crazy

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

please check this out going crazy

Unread postby wcdjs » February 11th, 2006, 1:09 am

Logfile of HijackThis v1.99.1
Scan saved at 11:01:58 PM, on 2/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\TGF2ZWxsIEhhbXB0b24\command.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AirLink101\WLAN Monitor\WLANmon.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\wmplayer\wmplayer.exe
C:\windows\winsysban7.exe
C:\WINDOWS\system32\hpsw.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\webHancer\Programs\whagent.exe
C:\Program Files\ATI Multimedia\main\LaunchPd.exe
C:\PROGRA~1\COMMON~1\zufw\zufwm.exe
C:\Program Files\Common Files\VCClient\VCClient.exe
C:\Program Files\Common Files\VCClient\VCMain.exe
C:\WINDOWS\system32\wgse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Windows\services32.exe
C:\PROGRA~1\COMMON~1\zufw\zufwa.exe
C:\Documents and Settings\Lavell\a.exe
C:\Program Files\outlook\outlook.exe
C:\PROGRA~1\COMMON~1\zufw\zufwl.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://yahoo.sbc.com/dsl"); (C:\Documents and Settings\Lavell\Application Data\Mozilla\Profiles\default\36z17xne.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lavell\Application Data\Mozilla\Profiles\default\36z17xne.slt\prefs.js)
O2 - BHO: Trecker Class - {39C78B50-7E98-4aa0-B007-D83114EA6E0F} - C:\PROGRA~1\Jalmp\jalmp.dll
O2 - BHO: XBTB04715 - {A8B0BDED-64A5-495b-97DA-42C0301E229B} - C:\PROGRA~1\TOOLBA~1\TOOLBA~1.DLL
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Toolbar888 - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Toolbar888\ToolBar888.dll
O4 - HKLM\..\Run: [CellVision WLAN Monitor] C:\Program Files\AirLink101\WLAN Monitor\WLANmon.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [wmplayer] C:\Program Files\wmplayer\wmplayer.exe /auto
O4 - HKLM\..\Run: [] p2pnetworking.exe
O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd7.exe
O4 - HKLM\..\Run: [0go40948.dll] RUNDLL32.EXE 0go40948.dll,b 112828
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\caopoi.exe reg_run
O4 - HKLM\..\Run: [winsysban] C:\windows\winsysban7.exe
O4 - HKLM\..\Run: [susse] "C:\WINDOWS\system32\hpsw.exe"
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program Files\webHancer\Programs\whsurvey.exe
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunServices: [] p2pnetworking.exe
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - HKCU\..\Run: [zufw] C:\PROGRA~1\COMMON~1\zufw\zufwm.exe
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: 2WireSetup.lnk = C:\Program Files\2Wire\WebWorks.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by WebHancer
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/activex/L ... ontrol.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 1590254545
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/S ... anager.ocx
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Filter: text/html - {2F6E85DC-8D2D-4896-8A4F-7DF8A7B1749D} - C:\PROGRA~1\Jalmp\jalmp.dll
O20 - AppInit_DLLs: repairs302972994.dll
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\system32\fpjo0313e.dll
O20 - Winlogon Notify: winccf32 - C:\WINDOWS\SYSTEM32\winccf32.dll
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
wcdjs
Regular Member
 
Posts: 15
Joined: February 10th, 2006, 7:47 am
Advertisement
Register to Remove

Unread postby Kimberly » February 11th, 2006, 1:55 am

Hello wcdjs and welcome,

That's quite a collection of malware you have on the PC, SurfSideKick, Look2Me, probably Elitebar - EliteMedia, some trojans but I highly suspect an trojan of the SBOT/RBOT family and maybe a keylogging Trojan relating to certain banking websites.

O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto

This doesn't look as the usual path to Office applications and that's why I suspect the following SBOT/RBOT
W32/Sdbot-RU is a network worm from the Sdbot family which attempts to spread to remote network shares protected by weak passwords and computers vulnerable to common exploits. W32/Sdbot-RU also contains backdoor Trojan functionality, allowing unauthorised remote access to the infected computer via IRC channels while running in the background as a service process.

A remote attacker can use the backdoor to send commands to the Trojan. These commands include instructions to delete network shares, steal registration keys for computer games, redirect internet traffic, participate in DDoS attacks, scan other computers and spread to network shares.


O4 - HKLM\..\Run: [wmplayer] C:\Program Files\wmplayer\wmplayer.exe /auto

Unusual, suspicous entry, prolly a keylogger.

C:\Documents and Settings\Lavell\a.exe in the running processes, another SBOT/RBOT


Untill we know more about those files, You are strongly advised to do the following immediately:

1. Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned.

2. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

3. From a clean computer, change *all* your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.

and what ever else seems appropriate.

We can likely clean the infected files off computer but we cannot be sure that the files involved didn't do anything to your system to reduce overall system security. You could be vulnerable to another attack as soon as you connect to net again. I personally would reinstall if this happend on my computer. Please let me know your intentions if those files turn out to be what I think they are.

Please perform the following in order to gather more info:

Make sure that you can see hidden files.
  1. Click Start.
  2. Click My Computer.
  3. Select the Tools menu and click Folder Options.
  4. Select the View Tab.
  5. Under the Hidden files and folders heading select Show hidden files and folders.
  6. Uncheck the Hide protected operating system files (recommended) option.
  7. Click Yes to confirm.
  8. Uncheck the Hide file extensions for known file types.
  9. Click OK.
______________________________

Submit the file C:\Program Files\outlook\outlook.exe to Jotti's scanner at:
http://virusscan.jotti.org/
Post the results here in the next reply.

Submit the file C:\Program Files\wmplayer\wmplayer.exe to Jotti's scanner at:
http://virusscan.jotti.org/
Post the results here in the next reply.

Submit the file C:\Documents and Settings\Lavell\a.exe to Jotti's scanner at:
http://virusscan.jotti.org/
Post the results here in the next reply.
______________________________

You did disable entries with MSconfig, I would like to see what else is lurking.

Copy/paste the following quote box into a new notepad (not wordpad) document.

regedit /e %systemdrive%\regkey.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig"
notepad %systemdrive%\regkey.txt
del /q %systemdrive%\regkey.txt

Save it to your Desktop as mslook.bat. Save it as:
File Type: All Files (not as a text document or it wont work).
Name: mslook.bat

Locate mslook.bat on your Desktop and double-click it. When notepad opens, copy/paste the content in your reply. When you close Notepad the CMD window will close automatically and the text file will be deleted.
______________________________

Run HijackThis, click on Open the Misc Tools Section, click on Open Uninstall Manager. Click on Save List and save uninstall_list.txt to your Desktop. Open this file in Notepad and copy/paste the content in your reply.
Click back (the one located at the right side of the save list button)
Put a checkmark in List also minor sections and List empty sections. Click on Generate StartupList log, anwser Yes and copy/paste the content in your reply.
Click Back and Click on Scan. When the scan is finished, click Save Log and paste the content in your reply.
______________________________

Please post
  1. Jotti's scanner results
  2. content of mslook.bat
  3. HijackThis startup list & uninstall_list.txt
  4. a new HijackThis log
You might need several replies to post the requested logs, otherwise they might get cut off.

Kim
User avatar
Kimberly
MRU Teacher Emeritus
 
Posts: 3505
Joined: June 15th, 2005, 12:57 am

help

Unread postby wcdjs » February 12th, 2006, 6:45 pm

OK thats fine but how do I send the files to that location, when I took that computer of the internet connection... And saying all that when I hooked back in I can not connect to anything ,, Just to let you know I sinced purchased pc-cillin internet security and ran a scan and it is as follows,, but before that my browser is so far gone it want let me do anything.

Logfile of HijackThis v1.99.1
Scan saved at 4:40:22 PM, on 2/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hpsw.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\wgse.exe
C:\Program Files\ATI Multimedia\main\LaunchPd.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://yahoo.sbc.com/dsl"); (C:\Documents and Settings\Lavell\Application Data\Mozilla\Profiles\default\36z17xne.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lavell\Application Data\Mozilla\Profiles\default\36z17xne.slt\prefs.js)
O2 - BHO: Trecker Class - {39C78B50-7E98-4aa0-B007-D83114EA6E0F} - C:\PROGRA~1\Jalmp\jalmp.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Toolbar888 - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Toolbar888\ToolBar888.dll
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [susse] "C:\WINDOWS\system32\hpsw.exe"
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\RunServices: [] p2pnetworking.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by WebHancer
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/activex/L ... ontrol.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 1590254545
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/S ... anager.ocx
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Filter: text/html - {2F6E85DC-8D2D-4896-8A4F-7DF8A7B1749D} - C:\PROGRA~1\Jalmp\jalmp.dll
O20 - AppInit_DLLs: repairs302972994.dll
O20 - Winlogon Notify: Detect - C:\WINDOWS\system32\q0ps0a77ed.dll
O20 - Winlogon Notify: winccf32 - C:\WINDOWS\SYSTEM32\winccf32.dll
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
wcdjs
Regular Member
 
Posts: 15
Joined: February 10th, 2006, 7:47 am

Unread postby Kimberly » February 13th, 2006, 1:37 am

Hello wcdjs,

OK thats fine but how do I send the files to that location, when I took that computer of the internet connection... And saying all that when I hooked back in I can not connect to anything ,, Just to let you know I sinced purchased pc-cillin internet security and ran a scan and it is as follows,, but before that my browser is so far gone it want let me do anything.


You can quickly connect to Internet, I did mean that you shouldn't leave it running all day. There is still a lot wrong on your PC and we will have to use special removal tools because pc-cillin wont get rid of all the stuff that needs to be removed.
I'm not surprised at all that you can't access internet since you did remove 3 essential startup entries for your wireless network.

O4 - HKLM\..\Run: [CellVision WLAN Monitor] C:\Program Files\AirLink101\WLAN Monitor\WLANmon.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - Startup: 2WireSetup.lnk = C:\Program Files\2Wire\WebWorks.exe

Can you access internet from another PC and transfer files to the infected PC ? (usb pen drive or cd ... )

I still need to see the results of the mslook.bat, the startup list and the uninstall list please. In meanwhile I'll start to put together a fix.

Kim
User avatar
Kimberly
MRU Teacher Emeritus
 
Posts: 3505
Joined: June 15th, 2005, 12:57 am

help again

Unread postby wcdjs » February 13th, 2006, 11:41 pm

Service load:
0% 100%
File: outlook.exe
Status:
INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 b420a430d733a3a1d8b27e71f78590e1
Packers detected:
UPX
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found Worm/Generic.IQ
BitDefender
Found Trojan.Dropper.G
ClamAV
Found nothing
Dr.Web
Found Trojan.MulDrop.3290
F-Prot Antivirus
Found nothing
Fortinet
Found W32/VB.DW!p2p
Kaspersky Anti-Virus
Found P2P-Worm.Win32.VB.dw
NOD32
Found a variant of Win32/TrojanDropper.VB.NAI
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found P2P-Worm.Win32.VB.dw

Service load:
0% 100%
File: wmplayer.exe
Status:
INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 c087b5d1361a254e523dcaf6c457dfab
Packers detected:
SDPROTECTOR
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found Win32:Wurmark-I
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found Win32.HLLW.MyBot
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found nothing
wcdjs
Regular Member
 
Posts: 15
Joined: February 10th, 2006, 7:47 am

Unread postby Kimberly » February 14th, 2006, 1:08 pm

Hello wcdjs,

Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Make sure to perform them all and save the logs !

Please download LSP-Fix from the following link and save it to a location you can find later if necessary.
______________________________

Download Fixssk.reg to your Desktop
http://www.bleepingcomputer.com/files/s ... fixssk.reg
______________________________

Download CWShredder to your Desktop or to your usual Download Folder.
http://www.trendmicro.com/ftp/products/ ... redder.exe
Run CWShredder.exe and Check for updates.
______________________________

Please download the trial version of Ewido from here:
http://www.ewido.net/en/download/
  • Install Ewido.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
  • When you run Ewido for the first time, you could get a warning "Database could not be found!". Click Ok.
  • The program will prompt you to update. Click the Ok button.
  • The program will now go to the main screen.
You will need to update Ewido to the latest definition files.
  • On the left-hand side of the main screen click the Update Button.
  • Click on Start.
The update will start and a progress bar will show the updates being installed.
Once finished updating, close Ewido.

If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates. Make sure to close Ewido before installing the update.
______________________________

Look2Me infection.
______________________________

Print these directions or copy/paste them into a Notepad document and save it to your desktop. Close any programs you have open since this step requires a reboot.
  • Open the l2mfix folder on your desktop.
  • Double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing the Enter key.
  • Press any key to reboot your computer.
After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, Notepad will open with a log. Post that log along with any additional information as directed below.

IMPORTANT: Do NOT run any other files in the l2mfix folder until you are asked to do so!

If after the reboot the desktop icons don't dissappear or the log does not pop up, then in the l2mfix folder double click the second.bat file to continue with the fix.

If you receive, while running the fix an error similar like below
''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications.
Choose close to terminate the application.."

...then please use option #5 and press Enter or use the web page link in the l2mfix folder to solve this error condition. You will be taken to a website that has C:windows\system32\autoexec.nt Fix in large letters. A little bit lower are choices of Operating Systems with links to replace the files needed. Choose the correct version of Windows for your computer and run it. Do not attempt to continue without fixing this first.
______________________________

Download and unzip BFU.zip from here.
Run the program and click the Web button as shown by the blue arrow below:
Image

Use this URL to copy into the address bar of the Download script window:
http://metallica.geekstogo.com/p2pnetwork.bfu

Execute the script by clicking the Execute button.

If you have any questions about the use of BFU please read here:
http://metallica.geekstogo.com/BFUinstructions.html
______________________________

Run CWShredder.exe. Close ALL windows except CWShredder and click on the Fix button, then click Next.
______________________________

To remove New.net please follow these steps
  1. Click on Start, Control Panel, click on Add/Remove Programs
  2. Look through the installed programs for an entry called New.Net or NewDotNet.
  3. If there is no uninstall program listed then do the following:
Reboot your computer.

To remove Webhancer please follow these steps
  1. Click on Start, Control Panel, click on Add/Remove Programs
  2. Choose webHancer Survey Companion from the list of installed applications. If you have a later version of Customer Companion, Survery Companion will not be in the list.
  3. Click Add/Remove. Survery Companion will be removed immediately.
  4. Choose webHancer Customer Companion from the list of installed applications.
  5. Click Add/Remove. A dialog box will be displayed, confirming that webHancer Customer Companion was successfully removed.
  6. Click OK.
Reboot your computer.
______________________________

Click on Start, Control Panel, click on Add/Remove Programs
Look through the installed programs for the following items and remove them if present:

Surf Sidekick
Surf Sidekick 2
Surf Sidekick 3


During the uninstall process, you might be presented with several prompts to guide you through uninstalling the product. Read these carefully to make sure you are actually choosing to uninstall rather than keep the software.

If there is no Add/Remove Programs entry for this programs, click on Start, then Run and type the followin in the Open: field:

C:\Program Files\SurfSideKick 3\Ssk.exe /u

and press the OK button. A code will be displayed that it will ask you to enter. Enter this code and reboot. Once back to your desktop continue with the rest of the fix.

Locate fixssk.reg and double-click on it and say Yes when it asks if you would like to merge the data.
______________________________

Reboot your computer in Safe Mode. Log in under YOUR ACCOUNT
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
______________________________

Run HijackThis, click on None of the above, just start the program, click on Scan. Put a check in the box on the left side of the following items if still present:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O2 - BHO: Trecker Class - {39C78B50-7E98-4aa0-B007-D83114EA6E0F} - C:\PROGRA~1\Jalmp\jalmp.dll
O3 - Toolbar: Toolbar888 - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Toolbar888\ToolBar888.dll
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [susse] "C:\WINDOWS\system32\hpsw.exe"
O4 - HKLM\..\RunServices: [] p2pnetworking.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) -
O18 - Filter: text/html - {2F6E85DC-8D2D-4896-8A4F-7DF8A7B1749D} - C:\PROGRA~1\Jalmp\jalmp.dll
O20 - AppInit_DLLs: repairs302972994.dll
O20 - Winlogon Notify: Detect - C:\WINDOWS\system32\q0ps0a77ed.dll
O20 - Winlogon Notify: winccf32 - C:\WINDOWS\SYSTEM32\winccf32.dll

Close ALL windows and browsers except HijackThis and click Fix Checked
______________________________

Click Start > Run > type CMD and hit enter

In the dos box, type the following lines followed by enter

sc stop Network Monitor and hit Enter
sc delete Network Monitor and hit Enter
______________________________

Using Windows Explorer, Search and Delete these Folders if listed:

C:\WINDOWS\TGF2ZWxsIEhhbXB0b24
C:\program files\Network Monitor
C:\Program Files\SurfSideKick 3
C:\PROGRAM FILES\SurfSideKick
C:\Program Files\Jalmp
C:\Program Files\Toolbar888
C:\Program Files\wmplayer
C:\Program Files\NewDotNet
C:\Program Files\webHancer
C:\Program Files\outlook
C:\Program Files\Common Files\zufw
C:\Program Files\Common Files\VCClient
C:\Program Files\Common Files\Windows

Using Windows Explorer, Search and Delete these Files if listed:

C:\WINDOWS\system32\wgse.exe
C:\windows\winsysupd7.exe
C:\WINDOWS\system32\caopoi.exe
C:\windows\winsysban7.exe
C:\WINDOWS\system32\hpsw.exe
C:\WINDOWS\system32\fpjo0313e.dll
C:\WINDOWS\SYSTEM32\winccf32.dll
C:\WINDOWS\system32\q0ps0a77ed.dll
C:\Documents and Settings\Lavell\a.exe

Use the Start > Search function to find the following Files and Delete them if listed. Make sure that Local Disk (C) is listed in the dropdrown box - if not, click the arrow and select it.
Click All files and folders, and then click More advanced options.
  • Click to select the Search system folders and Search hidden files and folders check boxes.
  • Make sure that the Subfolders are checked too.
Type the name of the file in the search box and click the Search button. Delete the file if found.

p2pnetworking.exe
Sskknwrd.dll
Ssk.log
SskUpdater.exe
Ssk.exe
repairs.dll
repairs302972994.dll
repairs<a random number>.dll
sporder.dll
webhdll.dll
whagent.inf
whInstaller.exe
whInstaller.ini


If you get an error when deleting a file, right click on the file and check to see if the read only attribute is checked. If it is uncheck it and try again.
______________________________

Navigate to C:\Windows\Prefetch
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Clean out your Temporary Internet files. Procede like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido Security Suite, and run a full scan.
  • Click on Scanner
  • Click on Settings
    • Under How to scan all boxes should be checked
    • Under Unwanted Software all boxes should be checked
    • Under What to scan select Scan every file
    • Click on Ok
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections, then choose clean and click Ok.

Once the scan has completed, there will be a button located on the bottom of the screen named Save Report.
  • Click Save Report button
  • Save the report to your Desktop
Close Ewido and reboot in Normal Mode.
______________________________

If you can not connect to the Internet after removing New.net, please run the LSP-Fix program I had you download earlier.
  • Close all windows except LSPfix.
  • Put a check mark in the box I know what I am doing
  • Select webhdll.dll if present, press on the >> button, to move the LSP into the Remove section.
  • Click on the Finish button.
  • Reboot and you should be able to get back on.
______________________________

Download WinPFind.zip to your Desktop or to your usual Download Folder.
http://www.bleepingcomputer.com/files/winpfind.php
Extract it to your C:\ folder. This will create a folder called WinPFind in the C:\ folder.

Open the C:\WinPFind folder and double-click on WinPFind.exe.
Click on the Start Scan button and wait for it to finish.

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log file named C:\WinPFind\WinPFind.txt. Please copy that log into your next reply.
______________________________

Please do an online scan with Kaspersky Online Scanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
______________________________

Copy/paste the following quote box into a new notepad (not wordpad) document.

regedit /e %systemdrive%\regkey.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig"
notepad %systemdrive%\regkey.txt
del /q %systemdrive%\regkey.txt

Save it to your Desktop as mslook.bat. Save it as:
File Type: All Files (not as a text document or it wont work).
Name: mslook.bat

Locate mslook.bat on your Desktop and double-click it. When notepad opens, copy/paste the content in your reply. When you close Notepad the CMD window will close automatically and the text file will be deleted.
______________________________

Run HijackThis, click on Open the Misc Tools Section, put a checkmark in List also minor sections and List empty sections. Click on Generate StartupList log, anwser Yes and copy/paste the content in your reply.
Click Back and Click on Scan. When the scan is finished, click Save Log and paste the content in your reply.
______________________________

Please post
  1. L2M log
  2. Ewido log
  3. C:\WinPFind\WinPFind.txt
  4. Kaspersky Scan
  5. mslook.bat content
  6. HijackThis startup list and a new Hijackthis log
You may need several replies to post the logs, otherwise they might get cut off. Please post those logs, they are essential for the health of your PC.

Kim
User avatar
Kimberly
MRU Teacher Emeritus
 
Posts: 3505
Joined: June 15th, 2005, 12:57 am

im back

Unread postby wcdjs » February 15th, 2006, 1:05 am

Ok here we go, I did what u said but this the results I did not see any webhancer anything in my add/remove software section. could not remove webhancer from windows explorer (access denied) could not winccf32 (access denied) it also want let me delete temp files in your instructions to do ( the first time u said do it. below is the logs so far I stop for the moment until further direction from you I left off at the part of running ewido scanner.
this hijackthis log is in safe mode
Logfile of HijackThis v1.99.1
Scan saved at 10:52:04 PM, on 2/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://yahoo.sbc.com/dsl"); (C:\Documents and Settings\Lavell\Application Data\Mozilla\Profiles\default\36z17xne.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lavell\Application Data\Mozilla\Profiles\default\36z17xne.slt\prefs.js)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\RunOnce: [cleanup] cmd /c IF NOT EXIST "C:\Program Files\Jalmp\qlink32.dll" (IF EXIST "C:\Program Files\Jalmp\uninstall.exe" rmdir /s /q "C:\Program Files\Jalmp\")
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} (LightSurfUploadCtl Class) - http://pictures.sprintpcs.com/activex/L ... ontrol.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 1590254545
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/S ... anager.ocx
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\hr6205joe.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
L2mfix 010406
Creating Account.
The command completed successfully.

Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful

Running From:
C:\WINDOWS\system32

Killing Processes!

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 516 'smss.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 600 'winlogon.exe'
Killing PID 600 'winlogon.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1324 'explorer.exe'
Killing PID 1324 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 564 'rundll32.exe'
Killing PID 1968 'rundll32.exe'
Restoring Sedebugprivilege:
Granting SeDebugPrivilege to Administrators ... successful

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
0 file(s) copied.
0 file(s) copied.
0 file(s) copied.
0 file(s) copied.
0 file(s) copied.
0 file(s) copied.
0 file(s) copied.
0 file(s) copied.
0 file(s) copied.
0 file(s) copied.
Deleting: C:\WINDOWS\system32\agi2edxx.dll
Successfully Deleted: C:\WINDOWS\system32\agi2edxx.dll
Deleting: C:\WINDOWS\system32\cdpbk32.dll
Successfully Deleted: C:\WINDOWS\system32\cdpbk32.dll
Deleting: C:\WINDOWS\system32\enl4l13q1.dll
Successfully Deleted: C:\WINDOWS\system32\enl4l13q1.dll
Deleting: C:\WINDOWS\system32\hr6205joe.dll
Successfully Deleted: C:\WINDOWS\system32\hr6205joe.dll
Deleting: C:\WINDOWS\system32\jt2q07f5e.dll
Successfully Deleted: C:\WINDOWS\system32\jt2q07f5e.dll
Deleting: C:\WINDOWS\system32\kt2sl7f71.dll
Successfully Deleted: C:\WINDOWS\system32\kt2sl7f71.dll
Deleting: C:\WINDOWS\system32\LMTWN11N.DLL
Successfully Deleted: C:\WINDOWS\system32\LMTWN11N.DLL
Deleting: C:\WINDOWS\system32\m8lsli3718.dll
Successfully Deleted: C:\WINDOWS\system32\m8lsli3718.dll
Deleting: C:\WINDOWS\system32\murle32.dll
Successfully Deleted: C:\WINDOWS\system32\murle32.dll
Deleting: C:\WINDOWS\system32\tTpiui.dll
Successfully Deleted: C:\WINDOWS\system32\tTpiui.dll

msg11?.dll
0 file(s) copied.



Restoring Windows Update Certificates.:

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\hr6205joe.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winccf32]
"Asynchronous"=dword:00000001
"DllName"="winccf32.dll"
"Impersonate"=dword:00000000
"Startup"="EvtStartup"
"Shutdown"="EvtShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\agi2edxx.dll
C:\WINDOWS\system32\cdpbk32.dll
C:\WINDOWS\system32\enl4l13q1.dll
C:\WINDOWS\system32\hr6205joe.dll
C:\WINDOWS\system32\jt2q07f5e.dll
C:\WINDOWS\system32\kt2sl7f71.dll
C:\WINDOWS\system32\LMTWN11N.DLL
C:\WINDOWS\system32\m8lsli3718.dll
C:\WINDOWS\system32\murle32.dll
C:\WINDOWS\system32\tTpiui.dll

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8F529610-C027-43DC-9350-458E2FF26EF2}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F529610-C027-43DC-9350-458E2FF26EF2}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F529610-C027-43DC-9350-458E2FF26EF2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F529610-C027-43DC-9350-458E2FF26EF2}\InprocServer32]
@="C:\\WINDOWS\\system32\\tTpiui.dll"
"ThreadingModel"="Apartment"

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{8F529610-C027-43DC-9350-458E2FF26EF2}"=-
[-HKEY_CLASSES_ROOT\CLSID\{8F529610-C027-43DC-9350-458E2FF26EF2}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************

****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
zip warning: name not matched: dlls\*.*

zip error: Nothing to do! (backup.zip)
adding: backregs/8F529610-C027-43DC-9350-458E2FF26EF2.reg (212 bytes security) (deflated 70%)
adding: backregs/notibac.reg (140 bytes security) (deflated 88%)
wcdjs
Regular Member
 
Posts: 15
Joined: February 10th, 2006, 7:47 am

Unread postby Kimberly » February 15th, 2006, 1:51 pm

Hello wcdjs,

Ok here we go, I did what u said but this the results I did not see any webhancer anything in my add/remove software section. could not remove webhancer from windows explorer (access denied) could not winccf32 (access denied) it also want let me delete temp files in your instructions to do ( the first time u said do it. below is the logs so far I stop for the moment until further direction from you I left off at the part of running ewido scanner.

Thanks for letting me know what went wrong and where you did leave off. Let's try a different removal method for Webhancer since the entries are not present in Add/Remove. It prolly has been installed with another program and the suggestion from the Webhancer website is to install it and then remove it (ughh)

At first sight, we got rid of Lookme, which would be very nice. Just one line to fix in HijackThis for that. I prefer to see HijackThis logs from Normal mode, it gives a better overview of what has been loaded. :)

Run HijackThis, click on None of the above, just start the program, click on Scan. Put a check in the box on the left side of the following items if still present:

O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\hr6205joe.dll (file missing)

Close ALL windows and browsers except HijackThis and click Fix Checked
______________________________

If you already have the latest Ad-Aware SE 1.06 version, skip to Run Ad-Aware. Otherwise download Ad-Aware SE 1.06 from here and install it. Uncheck all the options before leaving the Install Wizard.

Run Ad-Aware and Click on the World Icon. Click the Connect button on the webupdate screen. If an update is available download it and install it. Click the Finish button to go back to the main screen.

Click on the Gear Icon (second from the left at the top of the window) to access the Configuration Window.

Click on the General Button on the left and select in green
  • Under Safety
    • Automatically save log-file
    • Automatically quarantine objects prior to removal
    • Safe Mode (always request confirmation)
  • Under Definitions
    • Prompt to udate outdated definitions - set to 7 days
Click on the Scanning Button of the left and select in green
  • Under Driver, Folders & Files
    • Scan Within Archives
  • Under Select drives & folders to scan
    • choose all hard drives
  • Under Memory & Registry
    • Scan Active Processes
    • Scan Registry
    • Deep Scan Registry
    • Scan my IE favorites for banned URL’s
    • Scan my Hosts file
Click on the Advanced Button on the left and select in green
  • Under Shell Integration
    • Move deleted files to Recycle Bin
  • Under Logfile Detail Level
    • Include addtional object information
    • DESELECT - Include negligible objects information (make it show a red X)
    • Include environment information
  • Under Alternate Data Streams
    • Don't log streams smaller than 0 bytes
    • Don't log ADS with the following names: CA_INOCULATEIT
Click the Tweak Button and select in green
  • Under the Scanning Engine (Click on the + sign to expand)
    • DESELECT Unload recognized processes & modules during scan (make it show a red X)
    • Scan registry for all users instead of current user only
  • Under the Cleaning Engine (Click on the + sign to expand)
    • Always try to unload modules before deletion
    • During Removal, unload Explorer and IE if necessary
    • Let Windows remove files in use at next reboot
  • Under the Log Files (Click on the + sign to expand)
    • Include basic Ad-aware SE settings in logfile
    • Include additional Ad-aware SE settings in logfile
    • Include reference summarry in log file
    • Include alternate data stream details in log file
Click on Proceed to save the settings and close the program.
______________________________

Download http://securityresponse.symantec.com/av ... Hancer.exe
Don't use it yet.
______________________________

Download the Killbox by Option^Explicit to your Desktop or to your usual Download Folder.
http://www.downloads.subratam.org/KillBox.zip
Unzip it to your desktop or a convenient folder.
______________________________

Reboot your computer in Safe Mode. Log in under YOUR ACCOUNT
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
______________________________

Doubleclick FixWebHancer.exe, let the tool run. If a reboot is needed allow it to reboot but reboot in Safe Mode.
______________________________

Use the Start > Search function to find the following Files and Delete them if listed. Make sure that Local Disk (C) is listed in the dropdrown box - if not, click the arrow and select it.
Click All files and folders, and then click More advanced options.
  • Click to select the Search system folders and Search hidden files and folders check boxes.
  • Make sure that the Subfolders are checked too.
Type the name of the file in the search box and click the Search button. Write down the paths of those files, you will need that in Killbox.

sporder.dll
webhdll.dll
whagent.inf
whInstaller.exe
whInstaller.ini


Double-click Killbox.exe to run it. Click on Tools > Delete Temp Files

A box will open with a list of all user profiles.

Check the following boxes at a minimum for each profile by clicking on the drop down and checking the boxes that are enabled. Some will not apply and those boxes will not be available to check. Make sure you do this for all the profiles listed.

Temporary Internet Files
Temp Files


If you want to clean your cookies, history, and list of recent files run you may check those boxes as well.

Then click on the Button titled "Delete Selected Temp Files"

Do the next profile until you have cleaned all the profiles in the list.

Exit by clicking the Button titled "Exit(Save Settings)"

Once back into the main killbox program, you will be entering items into Pocket KillBox. Please select the “Delete on Rebootâ€
Last edited by Kimberly on February 17th, 2006, 12:05 pm, edited 1 time in total.
User avatar
Kimberly
MRU Teacher Emeritus
 
Posts: 3505
Joined: June 15th, 2005, 12:57 am

im back

Unread postby wcdjs » February 16th, 2006, 10:05 pm

Ok sorry it took so long but im at a stand still with the kampersky i guess i spelled it right but my ie browser wont let it run the install say my security wont let it ie6.0 try to change the setting but still not working please help here is some of the logs so far

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 5:34:43 AM, 2/16/2006
+ Report-Checksum: 6254A2AE

+ Scan result:

HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2296428D-C133-4928-B76A-A200FF409572} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup
[268] C:\WINDOWS\system32\winccf32.dll -> Downloader.Agent.aej : Cleaned with backup
C:\cygwid.exe -> Downloader.Small.bmx : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\About CNET Networks.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\All Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET Channel.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET Download.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET News.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET Reviews.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET Shopper.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Computer Shopper.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D - Diabetic Software 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D Programming Language 0.131.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D&D Attack Roller 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D&MA Hancock SuDoku Solver 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Drums Player 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Easy Tuner 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Guitar Chord Dictionary 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Keyboard Chord Dictionary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Mobile Chords 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Personal Guitarist 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-Bug 1.51.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-Day, 1944 Invasion of Europe v1.3 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-Lock 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-SoundPro 3.5.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-Zone 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D.L. Manager 5.0.1003.808.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D.o.D-lete 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D2 Simply Typing 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D2 Tools for FrontPage 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D3DChess 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D3DGear 1.5.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D4Modelizer 0.1.27.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D4Soft Code Editor Control for .NET 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D4Soft HTML Editor Control For .NET 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DA Launcher 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Da Vinci Code Generator 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dABC 0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DAC for MySQL 2.3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dacris Benchmarks 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dad The Chef Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daddy's Triangle Game 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaddyCall 3.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dads Day Off Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\daED 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daedalus 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daemon Tools 4.0.3 X86.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\daER 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DAFFAF Assistant 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DAFFAF Assistant for Windows 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Base map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Skyline 4 map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Slipgate Central map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Stairs map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Zeus' Quest map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana deathmatch demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana singlemultiplayer demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Alarm Clock 1.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Backup 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Bible and Prayer 1.2a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Bible Passage Volume (NIV) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Bible Passage Volume 1a (NIV) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Bread 5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Calls to Doctors for One Year 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Index Update Service 2.5.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Number Cruncher 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Planner Journal 4.0a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Planner Plus 4.8a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Shifts and Tasks for Your Employees with Excel 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DailyDiary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DailyInventory 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dailymotion Dashboard Widget 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DailyPIM 3.80.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daimonin 0.966.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daimyo - Beat the Shogun 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daisy Reversi 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaisyWords 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaisyWords 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dale Earnhardt Theme 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dali Professional Edition 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dalmaker XE 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DAM (Digital Assets Manager) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Damage ID 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dan Elwell's Broadband Speed Test 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dan Gordon's NFL Handicapping Companion 1.0.48.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dana 1.2b.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DanceForce 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dancing Leaves 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dancing Olympic Mascot Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dancing Skeleton Demox 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dancing Skeleton Demox 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dangerous Activity 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dangerous Activity 3D 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dangerous Mines 1.0 OSX.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DangleDate 1.0.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Danica Patrick Sexy Screensaver 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DanielaScript for mIRC 2.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Danny Phantom Ghost Sweep 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dantz Retrospect Desktop 6.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dapix Legal Series 8.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darik's Boot and Nuke SE.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Age of Camelot 1.54.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Age of Camelot Shrouded Isles New Frontiers beta expansion .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Age of Camelot Trials of Atlantis Gongdi User Interface .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Age of Camelot Trials of Atlantis New Frontiers beta expan .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Ages 5.51.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Ages II Engel 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Angael demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Archon 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Archon Invasion 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Colony demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Corona Pegasus (PowerPC) 1.0.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Files 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Forces demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Forest II 1.32.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Haven The Arena 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Horizons Lore demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Horizons Lore demo 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Horizons Lore patch 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Mailer 1.13.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Orbit 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Passage 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Planet Battle for Natrolis Demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Prince 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Prince WP 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 ambush movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 Battle movie (big) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 Battle movie (small) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 CTP movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 Desert Storm movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 gameplay movie 2 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 gameply movie 1 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 into sprawl movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Vengeance 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Vengeance Updater 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Water Trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DarkBASIC 1.13.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darklight Conflict demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DarkSpace 1.481.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darling Violetta Desktop Theme 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaRO Registry Fixer 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaRO Uninstaller 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dart Board 1.0.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DART CD-Recorder 4.1.27p.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DART Karaoke Studio CD+G 1.4.9cd.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dart Marker 3 - Cricket Scoreboard 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dArt Tropical Islands vol.1 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dart XP Pro 1.1.6p.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dartscore 2005 1.1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dartz 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darwinia demo 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darwinia demo 2 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dash Pop Up Control 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DashBlog 0.12b.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dashboard (Pocket PC) 1.1.001a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DashCook 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dasher 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dashfly Minutes for Nokia 365076506600 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dashLicious 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DashPopUpKiller 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dashr 0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Agent 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Application Builder 1.0.67.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data ASAP 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Base Scripting Pages 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Cleaner+ 4.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Converter Systems 1.0.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Crow 1.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Destroyer 6.57.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Eraser 07122005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Extractor 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Globe 9.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Loader 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Loader 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Management Toolkit 2005 1.0.61.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Map Pins 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Master 2003 11.7.0.226.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Miner 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Navigator 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data On The Run 4.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Processing Suite 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Protection Module 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Quik 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Recall 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Rescue 10.4.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Scrambler 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Security Crawler 1.8.38.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Transfer Utility 4.17.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Wiz 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data's Anonymous Mailer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data-Reports.NET 1.2.0.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data-Reports.NET 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data-XRay 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data2Quick 2.00405.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Databake Software 1.05.19.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database and XML Toolkit (DbTkXml) 1.4c.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Applet 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Architect 1.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Design Studio Lite 2.10.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Design Studio Professional 2.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Designer Enterprise Edition 9.83L.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Doctor SQL Repair Tool 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Fishing Tool 1.3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database For Microsoft Excel 8.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Genius 1.0.1a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Plus for Microsoft Excel 8.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Tour Pro 5.0.5.629.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Viewer 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Workshop 4.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatabaseBridge 1.002.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataBasix 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataBee 1.3.3.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Databound Schedule Controls 1.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Databrid 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataCAD 11.08.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataCaddy 1.0.1651.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datacation Flashcard Maker 3.0.0.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datacation Kids Math Flashcards 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datacation Math Flashcards 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataChart 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataClipper 3.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataCollector 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataConverse Server 1.1.3.197.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datacryp 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataDrafter Personal Edition 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataEase-To-Access Table Migration Utility 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataExecuter 2004.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataFit 8.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataForms.Net 2.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataFort Offsite Backup 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datagram SyslogAgent 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datagram SyslogServer Suite 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataGrid 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataGridColumns .NET assembly 1.8.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataGridView Columns .NET 2.0 assembly 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataHound 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataHouse 4.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataHouse Contact Manager 4.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataKeeper 1.09.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataKeeper32 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataLocker Desktop Agent Service 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataMatrix ActiveX 2.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datameter 1.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataMorph 1.61.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datanation Shutdown Utility 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataNow 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataObjects.NET Express 3.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataPilot 3.13.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataPipe 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataPoint 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataPro 1.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataQuest Systems Privacy Protector ZX 2.1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSafe (32-bit) 4.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSafe 2.0.5.052.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSafePro 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSaver Pro 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datascape 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSlave Professional 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTierHelper 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataToMail 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTrack System 2.0.6479.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTrakConverter 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTrakPOS 4.2.1.443.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTrakScheduler 1.0.0.24.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datatrieve Online Backup System 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTron 6.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataView 0.22.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataVision 2005 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataWeb Builder 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataXplorer 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Calculator 2.68.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Calculator 5.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Converter for P3E 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Time Counter Home Edition 1.02 build 20051116#03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Time Counter Personal Edition 1.01 build 20051116#03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Viewer 1.0.1.35.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Wheel 2.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date2Memo 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateApp 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateBk5 5.4a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateBook On Clock 2.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateCalc 1.1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateCalc 3.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateInTray 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateLens (ARM) 1.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatePal Pro 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatePicker 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatePicker 3.3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateTray 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dathorc's Kids 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dating Pro JAN.2006.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatingClub 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datiris Profiler Professional 1.1 build 171.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaToInfo 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datsun's Paddle Game 1.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daub Ages 1.31.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daumenkino 0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dava Image Viewer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dave (OS X) 5.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dave 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dave Mirra Freestyle BMX demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dave's Quick Search Deskbar 3.1.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\David's Backgammon 5.2.3(Carbon)-ysg.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\David's Backgammon 5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaVince Tools 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Davor's PHP Editor 1.0.3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dawn and Dusk Jigsaw Puzzle 40pc.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dawn Performance Manager 1.0A.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dawn Wallpaper 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daxaif (fat) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Day and Night Wallpaper 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Day at the Beach 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Day Trader 2 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DayCare 2005 5.7 01-2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daycare Management Professional 3.0.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daycare Manager 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daydreamer 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DayLogR 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DayNotez 2.8.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Days Away 1.4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Days Counter 1.5.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Days To Enjoy Christmas Screensaver 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaySmart 5.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daytona USA Deluxe demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dazzling Daytona Sun Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dazzling Events 1.7.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dazzling Reflections 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Anywhere 3.08n.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Architect 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Audit 2.7.58.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB CD Burner & Ripper 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Commander 2000 Pro 6.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Companion 2.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Cruiser 4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Mail 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Maker 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Manual 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Mapper 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Navigator 2 build 21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dB Organizer Deluxe 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Solo 1.2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB SynchroComp 3.4 build 216.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB to HTML Express 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Tools for Oracle 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB-Tool 2.0.1.122.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB2ASP 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB2ASP Creator 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Db4o for .NET 4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Db4o for Java 4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBA Manufacturing Next-Generation 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBA OnLine 1.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbaBar 1.2 build 225.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBabble Chat Server 2.7z.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBACentral for MySQL 1.6.1 build 166.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBAConnect 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBAny 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBase viewer 1.73 build 5.36.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBBlobEditor 2.5 release 1 build 13.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBCleaner (CE handheld, MIPS) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBCleaner (CE handheld, SH-3) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbCOPY 3.1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dbdesc 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBDiff 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBDiff for Oracle 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBExpress Driver for MS SQL Server 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Comparer 1.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Doctor 1.10 build 1021.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Manager 1.25 build 63.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Recovery 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to CSV 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to DBF 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to HTML 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to MDB (Access) 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to SQL 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to XLS (Excel) 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to XML 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF View 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Viewer 2000 2.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Viewer and Editor 2.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Viewer Pro 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbfUtils 2.1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBI Staff-Scheduler 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBISAM viewer 1.73 build 5.36.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbLockdown Standard 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBlogger 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBMachine 1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBMaestro Freeware Edition 3.1.3152.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBManager Professional 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBMonitor (DBPlus) 1.3.0 build 40.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBPix 2.0.0.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBPlus With Unattended Web Publishing 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBpowerAmp Audio Player 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBpowerAMP CD Writer Release 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBpowerAmp Music Converter 11.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBPowerTools II .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBPut Pro 2.2 build 210.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbQwikEdit Pro 3.0.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbQwikReport Pro 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbQwikSite 4.0.0.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBS 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbSaint 2.1.0.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbSchema 2.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbShow 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbSketch 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBSmart 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbSuite Admin Tool for MySQL 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbToXml 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBUptime 1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBVault 6.1.56.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbVisualizer 4.3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBWinXW 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBX Triever 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBX2mail 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbXpert for Oracle 6.0.2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBxq 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ 0.668.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ Acceleration Patch 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ FasterDownloads 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ Manager 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ MP3 Finder 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ Ultra Speed 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC-Art Millennium 4.83.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC-Sakura Boyish-Downloader 2.52.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dcat Screen Saver 1.61 build 821.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dcat Screensaver 1.41.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCC Workshop 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCF Analyst Pro 4.24.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dci Organzier 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCL&Lisp Generator 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCM Collection Agency Management System 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCM Professional Edition 4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCPro Studio 6.4.2r9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dCut 0.95.1 beta.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DD Magic Gallery 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DD Poker 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDBPlayer 3.9.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDBQ 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDCDes 2.0.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDD Pool 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDFileCatcher 2.145.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDNSServ 10.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dead Disc Doctor 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dead Disk Doctor 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dead Man's Hand 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dead Man's Hand Retail patch 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadhunt 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeadLine 2.26 build 962.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadlock demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadlock II demo (small) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadlock II larger demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 1.00 to 1.03 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 1.01 to 1.03 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 1.02 to 1.03 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 2 Pacific Theater gampley movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen Pacific Theater 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Games demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeafSpot Google Toolbar 4.5.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealAlert Shopping Assistant 3.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealerSim BJ 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealerSim Poker 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealHound 0.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dealio Comparison Shopping ToolBar 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealOngo Lite 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dean's Law Dictionary 5.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DearDiary 2.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death From Above 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death Rally demo 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death To Smoochy Screensaver (PC) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death Trap 2001 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeathDrome demo 1.55.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeBabelizer Pro 5.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debit McCredit Personal Finance 3.35.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debit McCredit Personal Finance Software Lite 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeBoard II PC Video Display System 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Accelerator 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Analyzer 3.5.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Collection Management 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Elimination Planner 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Hammer 2004 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Killer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Minder 1.8.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Minder 1.9.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Paydown Calculator 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DebugBar 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debugger Engine Package 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debugger Selector 1.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DebugMode Wax 2.0e.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DebugPackager 1.9.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DebugView 4.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deccan Encryptor Decryptor 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Decifra .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DecisionViewer OCX 4.07.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deck 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deck The Halls 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Chinese Dictionary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Chinese FlashCards 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's French FlashCards 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's German FlashCards 1.0.101.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Japanese Dictionary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Japanese FlashCards 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Korean Dictionary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Comple
wcdjs
Regular Member
 
Posts: 15
Joined: February 10th, 2006, 7:47 am

Unread postby Kimberly » February 17th, 2006, 12:32 am

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
UPX! 12/11/2002 3:13:36 PM 44032 C:\WINDOWS\unwash.exe

Checking %System% folder...
UPX! 2/11/2006 3:29:04 PM 45568 C:\WINDOWS\SYSTEM32\0go4efoy.dll
UPX! 7/9/2005 3:03:06 AM 433152 C:\WINDOWS\SYSTEM32\aswBoot.exe
PEC2 12/3/2003 7:12:08 AM 832276 C:\WINDOWS\SYSTEM32\ATIVTPXX.AX
PEC2 8/23/2001 6:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
FSG! 11/11/2003 3:00:22 PM 236544 C:\WINDOWS\SYSTEM32\DivXdec.ax
UPX! 1/4/2003 6:42:32 PM 67072 C:\WINDOWS\SYSTEM32\dtssource.ax
aspack 10/26/2004 3:39:42 PM 683008 C:\WINDOWS\SYSTEM32\Incinerator.dll
PTech 7/12/2005 5:04:22 PM 520456 C:\WINDOWS\SYSTEM32\LegitCheckControl.dll
PECompact2 1/4/2006 9:41:02 PM 2827616 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 1/4/2006 9:41:02 PM 2827616 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 8/4/2004 1:56:36 AM 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
PEC2 5/21/2002 10:31:08 AM R 217192 C:\WINDOWS\SYSTEM32\Packet.dll
Umonitor 8/4/2004 1:56:44 AM 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
UPX! 7/13/2005 2:19:10 AM 30208 C:\WINDOWS\SYSTEM32\usb496.dat
winsync 8/23/2001 6:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...
UPX! 10/21/2005 9:52:04 PM 726016 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
FSG! 10/21/2005 9:52:04 PM 726016 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
PEC2 10/21/2005 9:52:04 PM 726016 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
aspack 10/21/2005 9:52:04 PM 726016 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
PTech 8/3/2004 11:41:38 PM 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts

qoologic 2/14/2006 7:41:46 PM 1654 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.bak
urllogic 2/14/2006 7:41:46 PM 1654 C:\WINDOWS\SYSTEM32\drivers\etc\hosts.bak

Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
2/16/2006 7:07:54 PM S 2048 C:\WINDOWS\bootstat.dat
1/2/2006 5:09:36 PM S 11223 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB912919.cat
2/16/2006 7:12:52 PM H 1024 C:\WINDOWS\system32\config\default.LOG
2/16/2006 7:08:16 PM H 1024 C:\WINDOWS\system32\config\SAM.LOG
2/16/2006 7:20:12 PM H 1024 C:\WINDOWS\system32\config\SECURITY.LOG
2/16/2006 7:33:30 PM H 1024 C:\WINDOWS\system32\config\software.LOG
2/16/2006 7:15:42 PM H 1024 C:\WINDOWS\system32\config\system.LOG
1/20/2006 12:03:44 AM H 1024 C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
1/27/2006 4:22:48 PM S 1047 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\7C8A03C4580C6B04FDF34357F3474EDC
1/27/2006 4:22:44 PM S 1370 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\B82262A5D5DA4DDACE9EDA7F787D0DEB
1/27/2006 4:22:48 PM S 126 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\7C8A03C4580C6B04FDF34357F3474EDC
1/27/2006 4:22:44 PM S 194 C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\B82262A5D5DA4DDACE9EDA7F787D0DEB
2/16/2006 7:08:02 PM H 6 C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 8/4/2004 1:56:58 AM 68608 C:\WINDOWS\SYSTEM32\access.cpl
Avance Logic, Inc. 9/15/2002 7:52:06 PM 1256448 C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL
Microsoft Corporation 8/4/2004 1:56:58 AM 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl
11/12/1999 5:11:00 AM 183808 C:\WINDOWS\SYSTEM32\bdeadmin.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 135168 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 80384 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 129536 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 380416 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 68608 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems, Inc. 6/3/2005 2:52:54 AM 49265 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 8/23/2001 6:00:00 AM 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 8/23/2001 6:00:00 AM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
8/4/2004 1:56:58 AM 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 8/23/2001 6:00:00 AM 36864 C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Sun Microsystems 5/17/2002 5:04:56 PM 45154 C:\WINDOWS\SYSTEM32\plugincpl131_04.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 8/23/2001 6:00:00 AM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 94208 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 8/4/2004 1:56:58 AM 148480 C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation 5/26/2005 3:16:30 AM 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
The Weather Channel Interactive8/4/2005 8:33:42 AM 3010560 C:\WINDOWS\SYSTEM32\wxfw.cpl
Microsoft Corporation 8/23/2001 6:00:00 AM 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 8/23/2001 6:00:00 AM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 8/23/2001 6:00:00 AM 36864 C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation 8/23/2001 6:00:00 AM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 5/26/2005 3:16:30 AM 174360 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
11/25/2004 5:17:38 PM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini

Checking files in %ALLUSERSPROFILE%\Application Data folder...
11/25/2004 10:38:00 AM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
12/5/2005 8:50:16 PM 6 C:\Documents and Settings\All Users\Application Data\DragToDiscUserNameF.txt

Checking files in %USERPROFILE%\Startup folder...
11/25/2004 5:17:38 PM HS 84 C:\Documents and Settings\Lavell\Start Menu\Programs\Startup\desktop.ini

Checking files in %USERPROFILE%\Application Data folder...
1/31/2005 12:38:04 AM 1558 C:\Documents and Settings\Lavell\Application Data\AdobeDLM.log
11/25/2004 10:38:00 AM HS 62 C:\Documents and Settings\Lavell\Application Data\desktop.ini
1/31/2005 12:38:04 AM 0 C:\Documents and Settings\Lavell\Application Data\dm.ini
2/13/2006 9:39:08 PM 30 C:\Documents and Settings\Lavell\Application Data\Sskcwrd.dll

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
SV1 =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Evidence Eliminator
{B1816445-A3ED-11D3-B2B3-00104B4C6B08} = C:\WINDOWS\system32\Eeshellx.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Evidence Eliminator
{B1816445-A3ED-11D3-B2B3-00104B4C6B08} = C:\WINDOWS\system32\Eeshellx.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Library
{54F51408-DD44-4a12-82EF-519AD2A80DE9} = C:\Program Files\ATI Multimedia\mlibrary\MLShell.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinRAR
{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{F9DB5320-233E-11D1-9F84-707F02C10627}
= C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = blank
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = Yahoo! Toolbar : C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{44226DFF-747E-4edc-B30C-78752E50CD0C}
ButtonText = ATI TV :

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
=
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = blank
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{40D41A8B-D79B-43D7-99A7-9EE0F344C385} = AIM Search :
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = Yahoo! Toolbar : C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ATI Launchpad "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\bhoreg

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services
YPCService 3
x10nets 3
vsmon 2
ose 3
KodakCCS 3
iPodService 3
IDriverT 3
ewido security suite control 2
Avg7UpdSvc 2
Avg7Alrt 2
ATI Smart 2
Ati HotKey Poller 2
Network Monitor 2
cmdService 2


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk
backup C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE
item Adobe Gamma Loader.exe
backup C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE
item Adobe Gamma Loader.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk
backup C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE
item Adobe Reader Speed Launch
backup C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE
item Adobe Reader Speed Launch

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AllTracksGone 2005.lnk
backup C:\WINDOWS\pss\AllTracksGone 2005.lnkCommon Startup
location Common Startup
item AllTracksGone 2005
backup C:\WINDOWS\pss\AllTracksGone 2005.lnkCommon Startup
location Common Startup
item AllTracksGone 2005

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HPAiODevice(hp officejet d series) - 1.lnk
backup C:\WINDOWS\pss\HPAiODevice(hp officejet d series) - 1.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\HEWLET~1\AiO\HPOFFI~1\Bin\hpoojd07.exe -DeviceID 1102044946
item HPAiODevice(hp officejet d series) - 1
backup C:\WINDOWS\pss\HPAiODevice(hp officejet d series) - 1.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\HEWLET~1\AiO\HPOFFI~1\Bin\hpoojd07.exe -DeviceID 1102044946
item HPAiODevice(hp officejet d series) - 1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk
backup C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\Kodak\KODAKE~1\bin\EASYSH~1.EXE -hx
item Kodak EasyShare software
backup C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\Kodak\KODAKE~1\bin\EASYSH~1.EXE -hx
item Kodak EasyShare software

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk
backup C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\Kodak\KODAKS~1\7288971\Program\KODAKS~1.EXE
item KODAK Software Updater
backup C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\Kodak\KODAKS~1\7288971\Program\KODAKS~1.EXE
item KODAK Software Updater

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk
backup C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\MICROS~2\Office10\OSA.EXE -b -l
item Microsoft Office
backup C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\MICROS~2\Office10\OSA.EXE -b -l
item Microsoft Office

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk
backup C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\wkcalrem.exe
item Microsoft Works Calendar Reminders
backup C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
location Common Startup
command C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\wkcalrem.exe
item Microsoft Works Calendar Reminders

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Lavell^Start Menu^Programs^Startup^2WireSetup.lnk
path C:\Documents and Settings\Lavell\Start Menu\Programs\Startup\2WireSetup.lnk
backup C:\WINDOWS\pss\2WireSetup.lnkStartup
location Startup
command C:\PROGRA~1\2Wire\WebWorks.exe
item 2WireSetup
path C:\Documents and Settings\Lavell\Start Menu\Programs\Startup\2WireSetup.lnk
backup C:\WINDOWS\pss\2WireSetup.lnkStartup
location Startup
command C:\PROGRA~1\2Wire\WebWorks.exe
item 2WireSetup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Lavell^Start Menu^Programs^Startup^LimeWire On Startup.lnk
backup C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
location Startup
item LimeWire On Startup
backup C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
location Startup
item LimeWire On Startup

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item p2pnetworking
hkey HKLM
command p2pnetworking.exe
inimapping 0


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\0go40948.dll
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RUNDLL32
hkey HKLM
command RUNDLL32.EXE 0go40948.dll,b 112828
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RUNDLL32
hkey HKLM
command RUNDLL32.EXE 0go40948.dll,b 112828
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AllTracksGone
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item alltracksgone
hkey HKCU
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item alltracksgone
hkey HKCU
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ANIWZCS2Service
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item WZCSLDR2
hkey HKLM
command C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item WZCSLDR2
hkey HKLM
command C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ATI Launchpad
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item LaunchPd
hkey HKCU
command "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item LaunchPd
hkey HKCU
command "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ATI Remote Control
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ATIRW
hkey HKCU
command C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ATIRW
hkey HKCU
command C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ATI Scheduler
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ATISched
hkey HKCU
command C:\Program Files\ATI Multimedia\MAIN\ATISched.EXE
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ATISched
hkey HKCU
command C:\Program Files\ATI Multimedia\MAIN\ATISched.EXE
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ATIPTA
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item atiptaxx
hkey HKLM
command C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item atiptaxx
hkey HKLM
command C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AVG7_CC
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item avgcc
hkey HKLM
command C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item avgcc
hkey HKLM
command C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AVG7_EMC
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item avgemc
hkey HKLM
command C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item avgemc
hkey HKLM
command C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BJCFD
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CFD
hkey HKLM
command C:\Program Files\BroadJump\Client Foundation\CFD.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CFD
hkey HKLM
command C:\Program Files\BroadJump\Client Foundation\CFD.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CaAvTray
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CAVTray
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CAVTray
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CAVRID
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CAVRID
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CAVRID
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CellVision WLAN Monitor
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item WLANmon
hkey HKLM
command C:\Program Files\AirLink101\WLAN Monitor\WLANmon.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item WLANmon
hkey HKLM
command C:\Program Files\AirLink101\WLAN Monitor\WLANmon.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Cleanup
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item 20051010192212_mcappins
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item 20051010192212_mcappins
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Complete Security
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item PrivateSurfNT
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item PrivateSurfNT
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CompleteSecurityUpdate
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AutomaticUpdate
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AutomaticUpdate
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CU1
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item VCClient
hkey HKCU
command C:\Program Files\Common Files\VCClient\VCClient.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item VCClient
hkey HKCU
command C:\Program Files\Common Files\VCClient\VCClient.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CU2
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item VCMain
hkey HKCU
command C:\Program Files\Common Files\VCClient\VCMain.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item VCMain
hkey HKCU
command C:\Program Files\Common Files\VCClient\VCMain.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\dvd43
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item dvd43_tray
hkey HKLM
command C:\Program Files\dvd43\dvd43_tray.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item dvd43_tray
hkey HKLM
command C:\Program Files\dvd43\dvd43_tray.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DW4
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item
hkey HKCU
command
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item
hkey HKCU
command
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Evidence Eliminator
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ee
hkey HKCU
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ee
hkey HKCU
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HostManager
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AOLHostManager
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item AOLHostManager
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IPInSightLAN 02
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item IPClient
hkey HKLM
command "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item IPClient
hkey HKLM
command "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\IPInSightMonitor 02
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item IPMon32
hkey HKLM
command "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item IPMon32
hkey HKLM
command "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ISM
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Intelligent Stick Manager 2
hkey HKLM
command c:\program files\intelligent stick manager 2\ism2.exe sys_auto_run C:\Program Files\Intelligent Stick Manager 2
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Intelligent Stick Manager 2
hkey HKLM
command c:\program files\intelligent stick manager 2\ism2.exe sys_auto_run C:\Program Files\Intelligent Stick Manager 2
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item iTunesHelper
hkey HKLM
command "C:\Program Files\iTunes\iTunesHelper.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item iTunesHelper
hkey HKLM
command "C:\Program Files\iTunes\iTunesHelper.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KernelFaultCheck
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item dumprep 0 -k
hkey HKLM
command %systemroot%\system32\dumprep 0 -k
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item dumprep 0 -k
hkey HKLM
command %systemroot%\system32\dumprep 0 -k
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\McAfee Guardian
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CMGrdian
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item CMGrdian
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MCAgentExe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mcagent
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mcagent
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MCUpdateExe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item McUpdate
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item McUpdate
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MPFExe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MpfTray
hkey HKLM
command C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MpfTray
hkey HKLM
command C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSKAGENTEXE
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MskAgent
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MskAgent
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSKDetectorExe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MSKDetct
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item MSKDetct
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MyApplicationProfile
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item interface
hkey HKLM
command C:\WINDOWS\system32\interface.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item interface
hkey HKLM
command C:\WINDOWS\system32\interface.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroFilterCheck
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NeroCheck
hkey HKLM
command C:\WINDOWS\system32\NeroCheck.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NeroCheck
hkey HKLM
command C:\WINDOWS\system32\NeroCheck.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\New.net Startup
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NEWDOT~2
hkey HKLM
command rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item NEWDOT~2
hkey HKLM
command rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\outlook
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item outlook
hkey HKLM
command C:\Program Files\outlook\outlook.exe /auto
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item outlook
hkey HKLM
command C:\Program Files\outlook\outlook.exe /auto
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Booster
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item pcbooster
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item pcbooster
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\pccguide.exe
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item pccguide
hkey HKLM
command "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item pccguide
hkey HKLM
command "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PinnacleDriverCheck
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item PSDrvCheck
hkey HKLM
command C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item PSDrvCheck
hkey HKLM
command C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item qttask
hkey HKLM
command "C:\Program Files\QuickTime\qttask.exe" -atboottime
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item qttask
hkey HKLM
command "C:\Program Files\QuickTime\qttask.exe" -atboottime
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Realtime Audio Engine
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mmrtkrnl
hkey HKLM
command mmrtkrnl.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item mmrtkrnl
hkey HKLM
command mmrtkrnl.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RecoverFromReboot
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RecoverFromReboot
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RecoverFromReboot
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Registry Cleaner Scheduler
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RCScheduler
hkey HKCU
command "C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe" /startup
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item RCScheduler
hkey HKCU
command "C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe" /startup
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RoxioDragToDisc
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item DrgToDsc
hkey HKLM
command "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item DrgToDsc
hkey HKLM
command "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Share-to-Web Namespace Daemon
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hpgs2wnd
hkey HKLM
command C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hpgs2wnd
hkey HKLM
command C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SM1BG
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item SM1BG
hkey HKLM
command C:\WINDOWS\SM1BG.EXE
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item SM1BG
hkey HKLM
command C:\WINDOWS\SM1BG.EXE
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SoundMan
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item SOUNDMAN
hkey HKLM
command SOUNDMAN.EXE
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item SOUNDMAN
hkey HKLM
command SOUNDMAN.EXE
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SunJavaUpdateSched
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item jusched
hkey HKLM
command C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item jusched
hkey HKLM
command C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SurfBuddy
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item sbuddy
hkey HKCU
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item sbuddy
hkey HKCU
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SurfSideKick 3
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Ssk
hkey HKLM
command C:\Program Files\SurfSideKick 3\Ssk.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item Ssk
hkey HKLM
command C:\Program Files\SurfSideKick 3\Ssk.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\susse
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hpsw
hkey HKLM
command "C:\WINDOWS\system32\hpsw.exe"
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item hpsw
hkey HKLM
command "C:\WINDOWS\system32\hpsw.exe"
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TimeSink Ad Client
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item TsAdBot
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item TsAdBot
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ViewMgr
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ViewMgr
hkey HKLM
command C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ViewMgr
hkey HKLM
command C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Washer
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item washer
hkey HKCU
command C:\Program Files\Washer\washer.exe /0
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item washer
hkey HKCU
command C:\Program Files\Washer\washer.exe /0
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\webHancer Agent
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item whagent
hkey HKLM
command C:\Program Files\webHancer\Programs\whagent.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item whagent
hkey HKLM
command C:\Program Files\webHancer\Programs\whagent.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\webHancer Survey Companion
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item whsurvey
hkey HKLM
command C:\Program Files\webHancer\Programs\whsurvey.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item whsurvey
hkey HKLM
command C:\Program Files\webHancer\Programs\whsurvey.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WebSpecials
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item webspec
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item webspec
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\winsync
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item caopoi
hkey HKLM
command C:\WINDOWS\system32\caopoi.exe reg_run
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item caopoi
hkey HKLM
command C:\WINDOWS\system32\caopoi.exe reg_run
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\winsysban
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item winsysban7
hkey HKLM
command C:\windows\winsysban7.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item winsysban7
hkey HKLM
command C:\windows\winsysban7.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\winsysupd
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item winsysupd7
hkey HKLM
command C:\windows\winsysupd7.exe
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item winsysupd7
hkey HKLM
command C:\windows\winsysupd7.exe
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\wmplayer
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item wmplayer
hkey HKLM
command C:\Program Files\wmplayer\wmplayer.exe /auto
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item wmplayer
hkey HKLM
command C:\Program Files\wmplayer\wmplayer.exe /auto
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Yahoo! Pager
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ypager
hkey HKCU
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ypager
hkey HKCU
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\YBrowser
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ybrwicon
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ybrwicon
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ymetray
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ymetray
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item ymetray
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\YOP
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item yop
hkey HKLM
inimapping 0
key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
item yop
hkey HKLM
inimapping 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
system.ini 0
win.ini 0
bootini 0
services 2
startup 1


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 0
NoLowDiskSpaceChecks 1
NoBandCustomize 0
NoMovingBands 0
NoCloseDragDropBands 0
NoSetTaskbar 0
NoToolbarsOnTaskbar 0
NoSaveSettings 0
NoActiveDesktop 0
ClassicShell 0
NoToolbarCustomize 0
NoTrayItemsDisplay 0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent
= Ati2evxx.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winccf32
= winccf32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 2/16/2006 7:33:45 PM
User avatar
Kimberly
MRU Teacher Emeritus
 
Posts: 3505
Joined: June 15th, 2005, 12:57 am

Unread postby Kimberly » February 17th, 2006, 12:44 am

I still need to look up the logs, but the Ewido report got cut off and I would like to see the end of the report. There may be hunderds (if not more) entries that are starting with C:\Documents and Settings\Lavell\Complete\...... go to the last one in the Ewido log and post the rest please.

Let's check your IE settings and see if we can get an online scan going, they did update the control recently and we did notice a few glitches in the install.
  1. From within Internet Explorer click on the Tools menu and then click on Options.
  2. Click on the Security tab
  3. Click the Internet icon so it becomes highlighted.
  4. Click on Default Level and click Ok
  5. Click on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Prompt
    • Check that Script ActiveX controls marked safe for scripting is set to Enabled or Prompt
    • Check that Run ActiveX controls and plugins is Enabled
    • Change the Initialise and script ActiveX controls not marked as safe to Prompt
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • Check that Active Scripting is set to Enabled
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  6. Next press the Apply button and then the OK to exit the Internet Properties page.
Open a new IE window and try to run the Kaspersky online scan.

Also, since you have sp2 installed...are you clicking on the yellow "info bar" that is blocking active x install?
If not, click it > install active x.

Once the scan done, change the 2 following items back to disabled :
  • Change the Download unsigned ActiveX controls to Disabled
  • Change the Initialise and script ActiveX controls not marked as safe to Disabled
Kim
User avatar
Kimberly
MRU Teacher Emeritus
 
Posts: 3505
Joined: June 15th, 2005, 12:57 am

Unread postby Kimberly » February 17th, 2006, 12:17 pm

When the above is done, perform this please :

Start > Run > type CMD and hit enter

Type the following lines followed by enter

sc stop cmdService and hit enter

sc delete cmdService and hit enter


Double-click Killbox.exe to run it. You will be entering items into Pocket KillBox. Please select the “Delete on Rebootâ€
User avatar
Kimberly
MRU Teacher Emeritus
 
Posts: 3505
Joined: June 15th, 2005, 12:57 am

im back

Unread postby wcdjs » February 17th, 2006, 10:37 pm

all those changes still will not let me run kaspersky online scanner it tells me that it must be admin. aproved and i am the admin. please help must i try to get another ie browser getting tired now and very pleased with your help........ :cry:
wcdjs
Regular Member
 
Posts: 15
Joined: February 10th, 2006, 7:47 am

Unread postby Kimberly » February 18th, 2006, 1:25 am

Hi wcdjs,

Let's put the Kaspersky scan aside then. I came accross the admin error a few times and I don't have a solution for that problem although I know that the user is really an admin (I can see that when I ask you to run other programs). Unfortunatly KAV will only run in IE and not in other browsers.

Just post Ewido report that got cut off because I would like to see the end of the report. There may be hunderds (if not more) entries that are starting with C:\Documents and Settings\Lavell\Complete\...... go to the last one in the Ewido log and post the rest please. We'll decide from there.

Also, please post a new Hijackthis log for review.

Kim
User avatar
Kimberly
MRU Teacher Emeritus
 
Posts: 3505
Joined: June 15th, 2005, 12:57 am

Unread postby wcdjs » February 18th, 2006, 11:01 am

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 5:34:43 AM, 2/16/2006
+ Report-Checksum: 6254A2AE

+ Scan result:

HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2296428D-C133-4928-B76A-A200FF409572} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39C78B50-7E98-4AA0-B007-D83114EA6E0F} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup
HKU\S-1-5-21-1177238915-220523388-725345543-1003\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup
[268] C:\WINDOWS\system32\winccf32.dll -> Downloader.Agent.aej : Cleaned with backup
C:\cygwid.exe -> Downloader.Small.bmx : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Lavell\Application Data\Netscape\NSB\Profiles\w595u7mt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\About CNET Networks.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\All Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET Channel.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET Download.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET News.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET Reviews.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\CNET Shopper.com.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Computer Shopper.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D - Diabetic Software 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D Programming Language 0.131.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D&D Attack Roller 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D&MA Hancock SuDoku Solver 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Drums Player 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Easy Tuner 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Guitar Chord Dictionary 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Keyboard Chord Dictionary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Mobile Chords 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D'Accord Personal Guitarist 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-Bug 1.51.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-Day, 1944 Invasion of Europe v1.3 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-Lock 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-SoundPro 3.5.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D-Zone 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D.L. Manager 5.0.1003.808.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D.o.D-lete 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D2 Simply Typing 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D2 Tools for FrontPage 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D3DChess 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D3DGear 1.5.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D4Modelizer 0.1.27.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D4Soft Code Editor Control for .NET 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\D4Soft HTML Editor Control For .NET 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DA Launcher 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Da Vinci Code Generator 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dABC 0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DAC for MySQL 2.3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dacris Benchmarks 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dad The Chef Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daddy's Triangle Game 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaddyCall 3.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dads Day Off Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\daED 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daedalus 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daemon Tools 4.0.3 X86.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\daER 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DAFFAF Assistant 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DAFFAF Assistant for Windows 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Base map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Skyline 4 map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Slipgate Central map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Stairs map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana - Zeus' Quest map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana deathmatch demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana singlemultiplayer demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daikatana trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Alarm Clock 1.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Backup 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Bible and Prayer 1.2a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Bible Passage Volume (NIV) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Bible Passage Volume 1a (NIV) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Bread 5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Calls to Doctors for One Year 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Index Update Service 2.5.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Number Cruncher 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Planner Journal 4.0a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Planner Plus 4.8a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daily Shifts and Tasks for Your Employees with Excel 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DailyDiary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DailyInventory 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dailymotion Dashboard Widget 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DailyPIM 3.80.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daimonin 0.966.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daimyo - Beat the Shogun 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daisy Reversi 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaisyWords 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaisyWords 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dale Earnhardt Theme 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dali Professional Edition 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dalmaker XE 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DAM (Digital Assets Manager) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Damage ID 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dan Elwell's Broadband Speed Test 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dan Gordon's NFL Handicapping Companion 1.0.48.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dana 1.2b.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DanceForce 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dancing Leaves 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dancing Olympic Mascot Screensaver .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dancing Skeleton Demox 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dancing Skeleton Demox 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dangerous Activity 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dangerous Activity 3D 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dangerous Mines 1.0 OSX.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DangleDate 1.0.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Danica Patrick Sexy Screensaver 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DanielaScript for mIRC 2.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Danny Phantom Ghost Sweep 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dantz Retrospect Desktop 6.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dapix Legal Series 8.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darik's Boot and Nuke SE.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Age of Camelot 1.54.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Age of Camelot Shrouded Isles New Frontiers beta expansion .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Age of Camelot Trials of Atlantis Gongdi User Interface .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Age of Camelot Trials of Atlantis New Frontiers beta expan .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Ages 5.51.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Ages II Engel 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Angael demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Archon 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Archon Invasion 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Colony demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Corona Pegasus (PowerPC) 1.0.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Files 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Forces demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Forest II 1.32.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Haven The Arena 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Horizons Lore demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Horizons Lore demo 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Horizons Lore patch 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Mailer 1.13.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Orbit 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Passage 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Planet Battle for Natrolis Demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Prince 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Prince WP 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 ambush movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 Battle movie (big) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 Battle movie (small) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 CTP movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 Desert Storm movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 gameplay movie 2 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 gameply movie 1 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Reign 2 into sprawl movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Vengeance 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Vengeance Updater 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dark Water Trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DarkBASIC 1.13.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darklight Conflict demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DarkSpace 1.481.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darling Violetta Desktop Theme 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaRO Registry Fixer 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaRO Uninstaller 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dart Board 1.0.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DART CD-Recorder 4.1.27p.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DART Karaoke Studio CD+G 1.4.9cd.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dart Marker 3 - Cricket Scoreboard 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dArt Tropical Islands vol.1 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dart XP Pro 1.1.6p.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dartscore 2005 1.1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dartz 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darwinia demo 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Darwinia demo 2 .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dash Pop Up Control 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DashBlog 0.12b.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dashboard (Pocket PC) 1.1.001a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DashCook 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dasher 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dashfly Minutes for Nokia 365076506600 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dashLicious 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DashPopUpKiller 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dashr 0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Agent 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Application Builder 1.0.67.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data ASAP 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Base Scripting Pages 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Cleaner+ 4.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Converter Systems 1.0.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Crow 1.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Destroyer 6.57.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Eraser 07122005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Extractor 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Globe 9.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Loader 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Loader 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Management Toolkit 2005 1.0.61.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Map Pins 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Master 2003 11.7.0.226.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Miner 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Navigator 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data On The Run 4.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Processing Suite 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Protection Module 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Quik 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Recall 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Rescue 10.4.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Scrambler 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Security Crawler 1.8.38.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Transfer Utility 4.17.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data Wiz 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data's Anonymous Mailer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data-Reports.NET 1.2.0.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data-Reports.NET 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data-XRay 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Data2Quick 2.00405.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Databake Software 1.05.19.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database and XML Toolkit (DbTkXml) 1.4c.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Applet 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Architect 1.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Design Studio Lite 2.10.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Design Studio Professional 2.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Designer Enterprise Edition 9.83L.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Doctor SQL Repair Tool 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Fishing Tool 1.3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database For Microsoft Excel 8.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Genius 1.0.1a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Plus for Microsoft Excel 8.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Tour Pro 5.0.5.629.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Viewer 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Database Workshop 4.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatabaseBridge 1.002.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataBasix 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataBee 1.3.3.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Databound Schedule Controls 1.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Databrid 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataCAD 11.08.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataCaddy 1.0.1651.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datacation Flashcard Maker 3.0.0.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datacation Kids Math Flashcards 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datacation Math Flashcards 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataChart 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataClipper 3.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataCollector 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataConverse Server 1.1.3.197.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datacryp 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataDrafter Personal Edition 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataEase-To-Access Table Migration Utility 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataExecuter 2004.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataFit 8.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataForms.Net 2.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataFort Offsite Backup 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datagram SyslogAgent 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datagram SyslogServer Suite 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataGrid 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataGridColumns .NET assembly 1.8.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataGridView Columns .NET 2.0 assembly 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataHound 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataHouse 4.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataHouse Contact Manager 4.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataKeeper 1.09.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataKeeper32 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataLocker Desktop Agent Service 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataMatrix ActiveX 2.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datameter 1.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataMorph 1.61.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datanation Shutdown Utility 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataNow 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataObjects.NET Express 3.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataPilot 3.13.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataPipe 3.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataPoint 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataPro 1.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataQuest Systems Privacy Protector ZX 2.1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSafe (32-bit) 4.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSafe 2.0.5.052.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSafePro 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSaver Pro 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datascape 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataSlave Professional 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTierHelper 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataToMail 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTrack System 2.0.6479.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTrakConverter 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTrakPOS 4.2.1.443.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTrakScheduler 1.0.0.24.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datatrieve Online Backup System 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataTron 6.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataView 0.22.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataVision 2005 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataWeb Builder 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DataXplorer 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Calculator 2.68.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Calculator 5.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Converter for P3E 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Time Counter Home Edition 1.02 build 20051116#03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Time Counter Personal Edition 1.01 build 20051116#03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Viewer 1.0.1.35.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date Wheel 2.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Date2Memo 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateApp 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateBk5 5.4a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateBook On Clock 2.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateCalc 1.1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateCalc 3.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateInTray 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateLens (ARM) 1.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatePal Pro 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatePicker 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatePicker 3.3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DateTray 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dathorc's Kids 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dating Pro JAN.2006.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DatingClub 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datiris Profiler Professional 1.1 build 171.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaToInfo 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Datsun's Paddle Game 1.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daub Ages 1.31.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daumenkino 0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dava Image Viewer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dave (OS X) 5.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dave 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dave Mirra Freestyle BMX demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dave's Quick Search Deskbar 3.1.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\David's Backgammon 5.2.3(Carbon)-ysg.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\David's Backgammon 5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaVince Tools 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Davor's PHP Editor 1.0.3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dawn and Dusk Jigsaw Puzzle 40pc.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dawn Performance Manager 1.0A.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dawn Wallpaper 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daxaif (fat) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Day and Night Wallpaper 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Day at the Beach 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Day Trader 2 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DayCare 2005 5.7 01-2005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daycare Management Professional 3.0.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daycare Manager 1.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daydreamer 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DayLogR 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DayNotez 2.8.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Days Away 1.4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Days Counter 1.5.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Days To Enjoy Christmas Screensaver 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DaySmart 5.0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Daytona USA Deluxe demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dazzling Daytona Sun Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dazzling Events 1.7.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dazzling Reflections 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Anywhere 3.08n.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Architect 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Audit 2.7.58.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB CD Burner & Ripper 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Commander 2000 Pro 6.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Companion 2.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Cruiser 4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Mail 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Maker 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Manual 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Mapper 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Navigator 2 build 21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dB Organizer Deluxe 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Solo 1.2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB SynchroComp 3.4 build 216.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB to HTML Express 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB Tools for Oracle 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB-Tool 2.0.1.122.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB2ASP 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DB2ASP Creator 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Db4o for .NET 4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Db4o for Java 4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBA Manufacturing Next-Generation 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBA OnLine 1.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbaBar 1.2 build 225.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBabble Chat Server 2.7z.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBACentral for MySQL 1.6.1 build 166.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBAConnect 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBAny 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBase viewer 1.73 build 5.36.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBBlobEditor 2.5 release 1 build 13.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBCleaner (CE handheld, MIPS) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBCleaner (CE handheld, SH-3) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbCOPY 3.1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dbdesc 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBDiff 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBDiff for Oracle 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBExpress Driver for MS SQL Server 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Comparer 1.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Doctor 1.10 build 1021.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Manager 1.25 build 63.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Recovery 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to CSV 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to DBF 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to HTML 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to MDB (Access) 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to SQL 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to XLS (Excel) 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF to XML 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF View 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Viewer 2000 2.02.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Viewer and Editor 2.03.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBF Viewer Pro 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbfUtils 2.1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBI Staff-Scheduler 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBISAM viewer 1.73 build 5.36.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbLockdown Standard 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBlogger 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBMachine 1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBMaestro Freeware Edition 3.1.3152.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBManager Professional 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBMonitor (DBPlus) 1.3.0 build 40.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBPix 2.0.0.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBPlus With Unattended Web Publishing 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBpowerAmp Audio Player 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBpowerAMP CD Writer Release 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dBpowerAmp Music Converter 11.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBPowerTools II .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBPut Pro 2.2 build 210.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbQwikEdit Pro 3.0.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbQwikReport Pro 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbQwikSite 4.0.0.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBS 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbSaint 2.1.0.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbSchema 2.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbShow 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbSketch 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBSmart 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dbSuite Admin Tool for MySQL 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbToXml 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBUptime 1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBVault 6.1.56.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbVisualizer 4.3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBWinXW 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBX Triever 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBX2mail 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DbXpert for Oracle 6.0.2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DBxq 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ 0.668.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ Acceleration Patch 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ FasterDownloads 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ Manager 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ MP3 Finder 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC++ Ultra Speed 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC-Art Millennium 4.83.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DC-Sakura Boyish-Downloader 2.52.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dcat Screen Saver 1.61 build 821.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dcat Screensaver 1.41.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCC Workshop 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCF Analyst Pro 4.24.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dci Organzier 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCL&Lisp Generator 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCM Collection Agency Management System 6.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCM Professional Edition 4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DCPro Studio 6.4.2r9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\dCut 0.95.1 beta.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DD Magic Gallery 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DD Poker 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDBPlayer 3.9.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDBQ 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDCDes 2.0.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDD Pool 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDFileCatcher 2.145.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DDNSServ 10.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dead Disc Doctor 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dead Disk Doctor 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dead Man's Hand 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dead Man's Hand Retail patch 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadhunt 1.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeadLine 2.26 build 962.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadlock demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadlock II demo (small) .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadlock II larger demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 1.00 to 1.03 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 1.01 to 1.03 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 1.02 to 1.03 patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen 2 Pacific Theater gampley movie .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Dozen Pacific Theater 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deadly Games demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeafSpot Google Toolbar 4.5.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealAlert Shopping Assistant 3.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealerSim BJ 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealerSim Poker 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealHound 0.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dealio Comparison Shopping ToolBar 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DealOngo Lite 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Dean's Law Dictionary 5.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DearDiary 2.04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death From Above 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death Rally demo 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death To Smoochy Screensaver (PC) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Death Trap 2001 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeathDrome demo 1.55.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeBabelizer Pro 5.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debit McCredit Personal Finance 3.35.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debit McCredit Personal Finance Software Lite 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DeBoard II PC Video Display System 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Accelerator 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Analyzer 3.5.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Collection Management 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Elimination Planner 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Hammer 2004 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Killer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Minder 1.8.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Minder 1.9.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debt Paydown Calculator 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DebugBar 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debugger Engine Package 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Debugger Selector 1.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DebugMode Wax 2.0e.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DebugPackager 1.9.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DebugView 4.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deccan Encryptor Decryptor 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Decifra .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\DecisionViewer OCX 4.07.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deck 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Deck The Halls 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Chinese Dictionary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Chinese FlashCards 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's French FlashCards 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's German FlashCards 1.0.101.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Japanese Dictionary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Japanese FlashCards 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Korean Dictionary 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Korean FlashCards 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's Russian FlashCards 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup
C:\Documents and Settings\Lavell\Complete\Declan's S
wcdjs
Regular Member
 
Posts: 15
Joined: February 10th, 2006, 7:47 am
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: Vanilla-krypton and 45 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware