Firstly, I want to say thank you so very much...You see, I thought Windows Defender and all that was supposed to take care of viruses and all that nonsense...but it turns out to be a piece of junk...hasnt been useful for anything...So i downloaded the AVG antivirus and found a crap load of trojans and it deleted them all...One thing though, when I did the whole Safe Mode part of your instructions, I couldnt find the files hfwsaj.exe or Lajgbr.exe...I did the whole search and even manually searched through folders...couldn't find them...Also, I could not find the last 3 entries you told me to fix in the HijackThis scan (all of the O4's),but i found the first 2. So here is an updated HijackThis Report and my antivirus log...Thanks again...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:23:04 PM, on 7/29/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HiJackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.saramco.net:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2281244247-817284931-1731002456-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'IUSR_NMPR')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: iFinger.lnk = C:\Program Files\iFinger\iFinger.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Convert link target to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF -
res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: iFinger - {936E5D60-596C-11D3-BB96-00600816DF55} - C:\Windows\system32\SHDOCVW.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\Windows\system32\sfrem01.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 11810 bytes
<history>
<!-- 01c7d1fa7d842570 -->
<rec time="2007/07/29 16:06:58" user="SYSTEM" source="Update">
<value>@HL_UpdateOK</value>
<attr name="version">avi:1080-1048;iavi:934-875;</attr>
</rec>
<rec time="2007/07/29 16:07:39" user="Abdel Rahman Negm" source="General">
<value>@HL_TestStarted</value>
<attr name="testname">@TestName_02</attr>
</rec>
<rec time="2007/07/29 16:07:41" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\system32\shbrvt.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:27:36" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Users\Abdel Rahman Negm\Desktop\Negm\Ticket-Crack.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">VB.NJ</attr>
</rec>
<rec time="2007/07/29 16:27:36" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Users\Abdel Rahman Negm\Desktop\Negm\Ticket-Crack.rar</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">VB.NJ</attr>
</rec>
<rec time="2007/07/29 16:32:25" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\anuvmw.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:27" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\bcqlry.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:31" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\civpib.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:33" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\cyoynh.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:37" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\dghgwu.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:41" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\esfnco.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:42" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\evfdin.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:42" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\ewkxkl.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:42" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\fhvkoo.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:45" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\gvhdla.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:45" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\hfwsaj.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:46" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\hpppmx.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:46" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\hqqera.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:46" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\hznfob.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:49" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\iocfxr.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:50" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\isccew.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:51" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\itanpw.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:51" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\jjefdn.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:52" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\kjwxyx.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:53" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\lajgbr.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:53" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\ljycgl.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:54" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\llenpv.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:54" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\locgqk.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:57" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\mjyfaq.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:57" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\mkrlaq.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:32:57" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\mkueib.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:05" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\mtvvvj.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:35" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\ofuceb.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:36" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\oobtde.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:38" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\psggvc.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:39" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\pyifam.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:39" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\qsezmq.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:40" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\qyqvjf.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:42" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\rmbyli.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:42" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\scehyz.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:44" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\shbrvt.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:51" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\tqgahp.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:52" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\uijkxb.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:52" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\uqloje.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:52" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\urcfey.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:53" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\uuirqi.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:54" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\vfskut.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:54" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\vmwxlf.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:33:55" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\wbojeg.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:34:03" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\wxbkxi.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:34:03" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\xaakas.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:34:04" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\xxysfz.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:34:04" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\ymrmwh.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:34:04" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\ynkdji.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:34:04" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\zlosxw.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:34:05" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\System32\zxezkr.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:41:09" user="SYSTEM" source="Virus">
<value>@HL_ReportFindRS</value>
<attr name="filename">C:\Windows\System32\shbrvt.exe</attr>
<attr name="finding">@EID_Id_trj</attr>
<attr name="virusname">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:45:01" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ReportFind</value>
<attr name="where">C:\Windows\system32\shbrvt.exe</attr>
<attr name="type">@EID_Id_trj</attr>
<attr name="what">IRC/BackDoor.SdBot3.CLM</attr>
</rec>
<rec time="2007/07/29 16:45:01" user="Abdel Rahman Negm" source="General">
<value>@HL_TestEnded</value>
<attr name="testname">@TestName_02</attr>
<attr name="infectedfiles">55</attr>
</rec>
<rec time="2007/07/29 16:45:03" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\system32\shbrvt.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:03" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Users\Abdel Rahman Negm\Desktop\Negm\Ticket-Crack.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:03" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\anuvmw.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:03" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\bcqlry.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:03" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\civpib.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:03" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\cyoynh.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:04" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\dghgwu.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:04" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\esfnco.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:04" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\evfdin.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:05" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\ewkxkl.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:05" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\fhvkoo.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:05" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\gvhdla.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:05" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\hfwsaj.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:05" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\hpppmx.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:06" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\hqqera.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:06" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\hznfob.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:06" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\iocfxr.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:06" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\isccew.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:06" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\itanpw.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:07" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\jjefdn.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:07" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\kjwxyx.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:07" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\lajgbr.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:07" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\ljycgl.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:07" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\llenpv.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:07" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\locgqk.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:07" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\mjyfaq.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:08" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\mkrlaq.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:08" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\mkueib.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:08" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\mtvvvj.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:09" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\ofuceb.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:09" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\oobtde.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:09" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\psggvc.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:09" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\pyifam.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:09" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\qsezmq.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:09" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\qyqvjf.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:09" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\rmbyli.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:10" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\scehyz.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:10" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\shbrvt.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:10" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\tqgahp.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:10" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\uijkxb.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:10" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\uqloje.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:10" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\urcfey.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:10" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\uuirqi.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:11" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\vfskut.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:11" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\vmwxlf.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:11" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\wbojeg.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:11" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\wxbkxi.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:12" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\xaakas.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:12" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\xxysfz.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:12" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\ymrmwh.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:12" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\ynkdji.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:12" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\zlosxw.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:12" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\System32\zxezkr.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:45:12" user="Abdel Rahman Negm" source="Virus">
<value>@HL_ActionTaken</value>
<attr name="filename">C:\Windows\system32\shbrvt.exe</attr>
<attr name="action">@HL_ActCleaned</attr>
</rec>
<rec time="2007/07/29 16:50:18" user="Abdel Rahman Negm" source="General">
<value>@HL_TestStarted</value>
<attr name="testname">@TestName_02</attr>
</rec>
<rec time="2007/07/29 16:50:19" user="Abdel Rahman Negm" source="General">
<value>@HL_TestStopped</value>
<attr name="testname">@TestName_02</attr>
<attr name="infectedfiles">0</attr>
</rec>
<rec time="2007/07/29 16:50:42" user="Abdel Rahman Negm" source="General">
<value>@HL_TestStarted</value>
<attr name="testname">@TestName_13</attr>
</rec>
<rec time="2007/07/29 16:51:03" user="Abdel Rahman Negm" source="General">
<value>@HL_TestStopped</value>
<attr name="testname">@TestName_13</attr>
<attr name="infectedfiles">0</attr>
</rec>
</history>
Also, one more thing, I cant get my Windoes Security Center to frieking work...Everytime i click the Turn On button next to it it says that it failed to start, and I have all the necessary conditions it needs to run...automatic updates are on, so is windows firewall and User Account control and all of that...Any help would be great...Thanks alot