OK I have done all that you suggested and am posting the logs.
There was one item missing when I ran the HJT part in SAFE MODE
O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\addins\basps.dll
But I was able to check and fix the second item.
Logfile of HijackThis v1.99.1
Scan saved at 7:47:50 PM, on 9/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\SOYO\HW Monitor\Itesmart.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\ULIRAID\ALiRaid.exe
C:\Program Files\ULIRAID\JMAPP.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MoodLogic\Service\Updater.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
C:\Program Files\eFax Messenger 4.0\J2GTray.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\system32\BhoCitUS.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\SOYO\HW Monitor\Itesmart.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ALiRaid] C:\Program Files\ULIRAID\ALiRaid.exe
O4 - HKLM\..\Run: [JMAPP] C:\Program Files\ULIRAID\JMAPP.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MoodLogic Updater] C:\Program Files\MoodLogic\Service\Updater.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O4 - Global Startup: eFax DllCmd 4.0.lnk = C:\Program Files\eFax Messenger 4.0\J2GDllCmd.exe
O4 - Global Startup: eFax Tray Menu 4.0.lnk = C:\Program Files\eFax Messenger 4.0\J2GTray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {5F05A225-0F66-43DE-89E4-6FFD589C4F01} (OC web Installer) -
http://www.aebn.net/...CubeInstall.cabO16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) -
http://www.kodakgall..._1/axofupld.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO16 - DPF: {BF18F2A7-8B30-11D3-A95C-00008639BD6E} (activePDF Toolkit) -
https://www.clientsp...d/aptoolkit.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.app.../ITDetector.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalci...illama/ampx.cabO20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: ExtremeSync Service (ExtremeSync_Service) - Unknown owner - C:\Program Files\SuperFlexible\ExtremeSyncService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
ACTIVE SCAN
Incident Status Location
Virus:Trj/Classloader.I Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-419d56eb.zip[b.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-419d56eb.zip[c.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-419d56eb.zip[a.class]
Virus:Trj/Downloader.DIS Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-419d56eb.zip[d.class]
Virus:Trj/Classloader.I Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-5651e119.zip[b.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-5651e119.zip[c.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-5651e119.zip[a.class]
Virus:Trj/Downloader.DIS Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-5651e119.zip[d.class]
Virus:Trj/Downloader.EGM Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\Counters.jar-333fe01c-4866329c.zip[web.exe]
Spyware:Spyware/Virtumonde No disinfected C:\Documents and Settings\david\Desktop\icons\backups\backup-20050609-110635-379.dll
Security Risk:HackTool/Gendel.ANo disinfected C:\games\Half-Life\valve\nwhldm-Uninstall\gendel32.ex_
Virus:Bck/Orifice2K.sfx Disinfected Personal Folders\sent\bo2k_1.0.exe\bo2k_1.0.exe
Virus:VBS/LoveLetter Disinfected Personal Folders\sent\ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:VBS/LoveLetter Disinfected Personal Folders\sent\FW: ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:X97M/Laroux.MV Disinfected Personal Folders\sent\FW: Estimates of Tasks and Costs\360Markets_Est.xls
Virus:W32/Hybris Disinfected Personal Folders\old mail\Snowhite and the Seven Dwarfs - The REAL story!\joke.exe
Hacktool:Nuker/Muerte No disinfected Personal Folders\NCH\Projects\log.bats\fwlogz.zip[muerte.zip][MUERTE.EXE]
Virus:BAT/Winuck.Trojan Disinfected Personal Folders\NCH\Projects\log.bats\fwlogz.zip[win[bleep].zip][win[bleep].bat]
Virus:VBS/LoveLetter Disinfected Personal Folders\NCH\360Markets\Vendors\ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:X97M/Laroux.MV Disinfected Personal Folders\NCH\360Markets\Vendors\Estimates of Tasks and Costs\360Markets_Est.xls
Virus:Bck/Orifice2K.sfx Disinfected Personal Folders\sent\bo2k_1.0.exe\bo2k_1.0.exe
Virus:VBS/LoveLetter Disinfected Personal Folders\sent\ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:VBS/LoveLetter Disinfected Personal Folders\sent\FW: ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:X97M/Laroux.MV Disinfected Personal Folders\sent\FW: Estimates of Tasks and Costs\360Markets_Est.xls
Adware:Adware/Surfbar No disinfected Personal Folders\Deleted Items\Hello
Adware:Adware/Surfbar No disinfected Personal Folders\Inbox\How you been?
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: That movie\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Approved\your_details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Approved\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Wicked screensaver\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: That movie\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Unresolvable mail address\Re: Wicked screensaver\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Re: My details\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Thank you!\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Wicked screensaver\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Wicked screensaver\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Your application\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Returned mail: see transcript for details\Thank you!\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Your application\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Thank you!\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: That movie\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Re: My details\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Approved\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Your application\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: That movie\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Your application\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\your_details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Approved\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Re: My details\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Approved\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Approved\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Details\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Details\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Thank you!\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Approved\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: That movie\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Thank you!\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Thank you!\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Details\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: Re: My details\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Old\Re: That movie\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Thank you!\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Re: Approved\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Re: Details\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Re: Approved\your_details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Inbox\Re: Thank you!\document_9446.pif
Adware:Adware/BrilliantDigitalNo disinfected C:\OLDPC\Program Files\Kazaa\bdcore.dll.updpnd
Virus:Trj/Multidropper.V No disinfected C:\OLDPC\psp.v8.00.rar[pspcrk.exe]
Possible Virus. No disinfected C:\Program Files\TrojanHunter 4.2\Tools\Process Viewer\ProcessViewer.exe
Spyware:Spyware/Virtumonde No disinfected C:\WINDOWS\addins\basps.dll
Virus:Trj/Downloader.EBG Disinfected C:\WINDOWS\system32\req.dat
VUNDOFIX:
Incident Status Location
Virus:Trj/Classloader.I Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-419d56eb.zip[b.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-419d56eb.zip[c.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-419d56eb.zip[a.class]
Virus:Trj/Downloader.DIS Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-419d56eb.zip[d.class]
Virus:Trj/Classloader.I Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-5651e119.zip[b.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-5651e119.zip[c.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-5651e119.zip[a.class]
Virus:Trj/Downloader.DIS Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-65695b65-5651e119.zip[d.class]
Virus:Trj/Downloader.EGM Disinfected C:\Documents and Settings\david\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\Counters.jar-333fe01c-4866329c.zip[web.exe]
Spyware:Spyware/Virtumonde No disinfected C:\Documents and Settings\david\Desktop\icons\backups\backup-20050609-110635-379.dll
Security Risk:HackTool/Gendel.ANo disinfected C:\games\Half-Life\valve\nwhldm-Uninstall\gendel32.ex_
Virus:Bck/Orifice2K.sfx Disinfected Personal Folders\sent\bo2k_1.0.exe\bo2k_1.0.exe
Virus:VBS/LoveLetter Disinfected Personal Folders\sent\ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:VBS/LoveLetter Disinfected Personal Folders\sent\FW: ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:X97M/Laroux.MV Disinfected Personal Folders\sent\FW: Estimates of Tasks and Costs\360Markets_Est.xls
Virus:W32/Hybris Disinfected Personal Folders\old mail\Snowhite and the Seven Dwarfs - The REAL story!\joke.exe
Hacktool:Nuker/Muerte No disinfected Personal Folders\NCH\Projects\log.bats\fwlogz.zip[muerte.zip][MUERTE.EXE]
Virus:BAT/Winuck.Trojan Disinfected Personal Folders\NCH\Projects\log.bats\fwlogz.zip[win[bleep].zip][win[bleep].bat]
Virus:VBS/LoveLetter Disinfected Personal Folders\NCH\360Markets\Vendors\ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:X97M/Laroux.MV Disinfected Personal Folders\NCH\360Markets\Vendors\Estimates of Tasks and Costs\360Markets_Est.xls
Virus:Bck/Orifice2K.sfx Disinfected Personal Folders\sent\bo2k_1.0.exe\bo2k_1.0.exe
Virus:VBS/LoveLetter Disinfected Personal Folders\sent\ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:VBS/LoveLetter Disinfected Personal Folders\sent\FW: ILOVEYOU\LOVE-LETTER-FOR-YOU.TXT.vbs
Virus:X97M/Laroux.MV Disinfected Personal Folders\sent\FW: Estimates of Tasks and Costs\360Markets_Est.xls
Adware:Adware/Surfbar No disinfected Personal Folders\Deleted Items\Hello
Adware:Adware/Surfbar No disinfected Personal Folders\Inbox\How you been?
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: That movie\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Approved\your_details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Approved\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Wicked screensaver\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: That movie\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Unresolvable mail address\Re: Wicked screensaver\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Re: My details\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Thank you!\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Wicked screensaver\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Wicked screensaver\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Your application\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Returned mail: see transcript for details\Thank you!\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Your application\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Thank you!\application.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: That movie\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Re: My details\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\movie0045.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Approved\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Your application\details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Details\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: That movie\thank_you.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Your application\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\your_details.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Re: Approved\document_all.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Your details\your_document.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!\document_9446.pif
Virus:W32/Sobig.F Disinfected Personal Folders\Deleted Items\Thank you!