Here are the logs, however, I don't know if I did the Dr Web thing right... Was I supposed to do something after it scanned? Such as curing things? Also, Sypbot asked if I wanted to block the CF log again after I enabled it after the Dr Web scan...
ComboFix 09-01-13.04 - Andrew 2009-01-14 11:36:52.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.725 [GMT -8:00]
Running from: c:\documents and settings\Andrew\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Andrew\Desktop\CFScript.txt.txt
AV: avast! antivirus 4.8.1296 [VPS 090114-0] *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-12-14 to 2009-01-14 )))))))))))))))))))))))))))))))
.
2009-01-10 12:12 . 2009-01-10 12:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avg7
2009-01-09 23:26 . 2009-01-09 23:26 <DIR> d-------- c:\windows\system32\scripting
2009-01-09 23:26 . 2009-01-09 23:26 <DIR> d-------- c:\windows\system32\en
2009-01-09 23:26 . 2009-01-09 23:26 <DIR> d-------- c:\windows\l2schemas
2009-01-09 22:55 . 2008-10-16 12:38 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-01-09 22:55 . 2007-04-17 01:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-01-09 22:55 . 2007-03-07 21:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-01-09 22:55 . 2008-10-16 12:38 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-01-09 22:55 . 2008-10-16 12:38 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-01-09 22:55 . 2008-10-16 12:38 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-01-09 22:55 . 2008-10-16 12:38 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-01-09 22:55 . 2008-10-16 12:38 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-01-09 22:55 . 2008-10-16 05:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-01-09 22:51 . 2007-08-13 18:54 33,792 --a--c--- c:\windows\system32\dllcache\custsat.dll
2009-01-09 19:53 . 2009-01-09 19:52 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-01-09 19:52 . 2009-01-09 19:52 <DIR> d-------- c:\program files\Java
2009-01-09 19:32 . 2009-01-09 19:45 <DIR> d-------- c:\documents and settings\Andrew\.SunDownloadManager
2009-01-08 17:47 . 2009-01-08 17:47 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-08 17:47 . 2009-01-08 17:47 <DIR> d-------- c:\documents and settings\Andrew\Application Data\Malwarebytes
2009-01-08 17:47 . 2009-01-08 17:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-08 17:47 . 2009-01-04 18:38 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-08 17:47 . 2009-01-04 18:38 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-08 14:48 . 2009-01-08 14:48 <DIR> d-------- c:\program files\Trend Micro
2009-01-08 09:34 . 2009-01-08 09:34 <DIR> d-------- c:\program files\XoftSpySE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-14 06:28 --------- d-----w c:\documents and settings\Andrew\Application Data\.purple
2009-01-10 21:29 --------- d-----w c:\documents and settings\Andrew\Application Data\gtk-2.0
.
((((((((((((((((((((((((((((( snapshot@2009-01-12_13.41.58.73 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-14 19:48:20 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_49c.dat
- 2009-01-12 20:13:10 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_710.dat
+ 2009-01-14 19:48:30 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_710.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\9afedb290d5fd574c253e2\admparse.dll
2007-08-13 18:39 71680 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146203.dll
c:\9afedb290d5fd574c253e2\advpack.dll
2007-08-13 18:39 123904 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146204.dll
c:\9afedb290d5fd574c253e2\browseui.dll
2006-09-23 13:12 1022976 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146205.dll
c:\9afedb290d5fd574c253e2\corpol.dll
2007-08-13 18:42 17408 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146206.dll
c:\9afedb290d5fd574c253e2\custsat.dll
2007-08-13 18:54 33792 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146207.dll
c:\9afedb290d5fd574c253e2\dxtmsft.dll
2007-08-13 18:35 346624 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146208.dll
c:\9afedb290d5fd574c253e2\dxtrans.dll
2007-08-13 18:35 214528 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146209.dll
c:\9afedb290d5fd574c253e2\extmgr.dll
2007-08-13 18:54 131584 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146210.dll
c:\9afedb290d5fd574c253e2\hmmapi.dll
2007-08-13 18:18 60416 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146211.dll
c:\9afedb290d5fd574c253e2\icardie.dll
2007-08-13 18:36 61952 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146212.dll
c:\9afedb290d5fd574c253e2\ie4uinit.exe
2007-08-13 18:39 54784 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146214.exe
c:\9afedb290d5fd574c253e2\ieakeng.dll
2007-08-13 18:39 152064 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146215.dll
c:\9afedb290d5fd574c253e2\ieaksie.dll
2007-08-13 18:39 229376 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146216.dll
c:\9afedb290d5fd574c253e2\ieakui.dll
2007-08-13 17:56 161792 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146217.dll
c:\9afedb290d5fd574c253e2\ieapfltr.dll
2007-07-11 12:27 383488 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146218.dll
c:\9afedb290d5fd574c253e2\iedkcs32.dll
2007-08-13 18:39 382976 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146219.dll
c:\9afedb290d5fd574c253e2\iedw.exe
2007-08-13 18:44 69120 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146220.exe
c:\9afedb290d5fd574c253e2\ieencode.dll
2007-08-13 18:45 78336 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146221.dll
c:\9afedb290d5fd574c253e2\ieframe.dll
2007-08-13 18:54 6049280 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146222.dll
c:\9afedb290d5fd574c253e2\iepeers.dll
2007-08-13 18:54 191488 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146223.dll
c:\9afedb290d5fd574c253e2\ieproxy.dll
2007-08-13 18:54 287744 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146224.dll
c:\9afedb290d5fd574c253e2\iernonce.dll
2007-08-13 18:39 43008 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146225.dll
c:\9afedb290d5fd574c253e2\iertutil.dll
2007-08-13 18:34 266752 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146226.dll
c:\9afedb290d5fd574c253e2\iesetup.dll
2007-08-13 18:39 55296 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146227.dll
c:\9afedb290d5fd574c253e2\ieudinit.exe
2007-08-13 18:39 13312 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146228.exe
c:\9afedb290d5fd574c253e2\ieui.dll
2007-08-13 18:54 180736 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146229.dll
c:\9afedb290d5fd574c253e2\iexplore.exe
2007-08-13 18:43 622080 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146231.exe
c:\9afedb290d5fd574c253e2\imgutil.dll
2007-08-13 18:36 36352 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146232.dll
c:\9afedb290d5fd574c253e2\inseng.dll
2007-08-13 18:39 92672 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146234.dll
c:\9afedb290d5fd574c253e2\jscript.dll
2007-08-13 18:38 491520 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146236.dll
c:\9afedb290d5fd574c253e2\jsproxy.dll
2007-08-13 18:54 27136 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146237.dll
c:\9afedb290d5fd574c253e2\licmgr10.dll
2007-08-13 18:44 40960 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146238.dll
c:\9afedb290d5fd574c253e2\msfeeds.dll
2007-08-13 18:54 458752 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146239.dll
c:\9afedb290d5fd574c253e2\msfeedsbs.dll
2007-08-13 18:54 50688 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146241.dll
c:\9afedb290d5fd574c253e2\msfeedssync.exe
2007-08-13 18:36 12288 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146243.exe
c:\9afedb290d5fd574c253e2\mshta.exe
2007-08-13 18:32 45568 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146244.exe
c:\9afedb290d5fd574c253e2\mshtml.dll
2007-08-13 18:54 3578368 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146245.dll
c:\9afedb290d5fd574c253e2\mshtmled.dll
2007-08-13 18:54 475648 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146247.dll
c:\9afedb290d5fd574c253e2\mshtmler.dll
2007-08-13 18:01 48128 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146248.dll
c:\9afedb290d5fd574c253e2\msls31.dll
2007-08-13 18:54 156160 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146249.dll
c:\9afedb290d5fd574c253e2\msrating.dll
2007-08-13 18:44 192000 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146250.dll
c:\9afedb290d5fd574c253e2\mstime.dll
2007-08-13 18:54 670720 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146251.dll
c:\9afedb290d5fd574c253e2\occache.dll
2007-08-13 18:44 101376 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146252.dll
c:\9afedb290d5fd574c253e2\pngfilt.dll
2007-08-13 18:36 44544 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146254.dll
c:\9afedb290d5fd574c253e2\shdocvw.dll
2006-09-23 13:12 1497088 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146255.dll
c:\9afedb290d5fd574c253e2\shlwapi.dll
2006-09-23 13:12 474112 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146256.dll
c:\9afedb290d5fd574c253e2\spmsg.dll
2006-09-06 17:43 14048 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146257.dll
c:\9afedb290d5fd574c253e2\spuninst.exe
2006-09-06 17:43 213216 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146258.exe
c:\9afedb290d5fd574c253e2\spupdsvc.exe
2006-09-06 17:43 22752 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146259.exe
c:\9afedb290d5fd574c253e2\update\idndl.exe
2006-09-06 17:42 589672 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146262.exe
c:\9afedb290d5fd574c253e2\update\iecustom.dll
2007-08-13 18:54 32960 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146264.dll
c:\9afedb290d5fd574c253e2\update\iereseticons.exe
2007-08-13 18:52 66048 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146265.exe
c:\9afedb290d5fd574c253e2\update\iesetup.exe
2007-08-13 18:54 1084096 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146266.exe
c:\9afedb290d5fd574c253e2\update\legitlibm.dll
2007-02-12 16:10 635696 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146267.dll
c:\9afedb290d5fd574c253e2\update\nlsdl.exe
2006-09-06 17:42 498016 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146268.exe
c:\9afedb290d5fd574c253e2\update\update.exe
2006-09-06 17:43 716000 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146269.exe
c:\9afedb290d5fd574c253e2\update\updspapi.dll
2006-09-06 17:43 371424 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146273.dll
c:\9afedb290d5fd574c253e2\update\xmllitesetup.exe
2006-09-06 17:43 536888 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146274.exe
c:\9afedb290d5fd574c253e2\url.dll
2007-08-13 18:44 105984 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146275.dll
c:\9afedb290d5fd574c253e2\urlmon.dll
2007-08-13 18:54 1162240 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146276.dll
c:\9afedb290d5fd574c253e2\vbscript.dll
2007-08-13 18:54 413696 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146277.dll
c:\9afedb290d5fd574c253e2\vgx.dll
2007-08-13 18:54 765952 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146278.dll
c:\9afedb290d5fd574c253e2\webcheck.dll
2007-08-13 18:54 231424 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146279.dll
c:\9afedb290d5fd574c253e2\winfxdocobj.exe
2007-08-13 18:45 206336 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146281.exe
c:\9afedb290d5fd574c253e2\wininet.dll
2007-08-13 18:54 818688 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146282.dll
2009-01-14 11:30 1458 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegBHO-Global.reg
2009-01-12 00:16 1458 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146067.reg
2009-01-13 00:17 1595 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148567.reg
2009-01-14 11:30 8424 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDPF-Global.reg
2009-01-12 00:16 8424 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146066.reg
2009-01-13 00:17 8424 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148605.reg
2009-01-14 11:30 60 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegDummy-Andrew.reg
2009-01-12 00:16 60 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146078.reg
2009-01-13 00:17 60 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148615.reg
2009-01-14 11:30 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtBat-Global.reg
2009-01-12 00:16 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146051.reg
2009-01-13 00:17 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148590.reg
2009-01-14 11:30 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtCmd-Global.reg
2009-01-12 00:16 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146045.reg
2009-01-13 00:17 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148584.reg
2009-01-14 11:30 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtCom-Global.reg
2009-01-12 00:16 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146050.reg
2009-01-13 00:17 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148589.reg
2009-01-14 11:30 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtExe-Global.reg
2009-01-12 00:16 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146049.reg
2009-01-13 00:17 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148588.reg
2009-01-14 11:30 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtPif-Global.reg
2009-01-12 00:16 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146048.reg
2009-01-13 00:17 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148587.reg
2009-01-14 11:30 86 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtReg-Global.reg
2009-01-12 00:16 86 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146046.reg
2009-01-13 00:17 86 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148585.reg
2009-01-14 11:30 77 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegExtScr-Global.reg
2009-01-12 00:16 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146047.reg
2009-01-13 00:17 77 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148586.reg
2009-01-14 11:30 81 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBME-Global.reg
2009-01-12 00:16 81 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146062.reg
2009-01-13 00:17 81 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148601.reg
2009-01-14 11:30 116 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP1-Global.reg
2009-01-12 00:16 116 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146056.reg
2009-01-13 00:17 116 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148595.reg
2009-01-14 11:30 352 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP2a-Global.reg
2009-01-12 00:16 329 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146055.reg
2009-01-13 00:17 352 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148594.reg
2009-01-14 11:30 441 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP2b-Global.reg
2009-01-12 00:16 461 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146054.reg
2009-01-13 00:17 441 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148593.reg
2009-01-14 11:30 277 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP3-Global.reg
2009-01-12 00:16 277 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146053.reg
2009-01-13 00:17 277 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148592.reg
2009-01-14 11:30 116 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBP4-Global.reg
2009-01-12 00:16 116 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146052.reg
2009-01-13 00:17 116 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148591.reg
2009-01-14 11:30 179 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBTB1-Global.reg
2009-01-12 00:16 179 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146068.reg
2009-01-13 00:17 179 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148606.reg
2009-01-14 11:30 240 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGBTB2-Global.reg
2009-01-12 00:16 240 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146064.reg
2009-01-13 00:17 240 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148603.reg
2009-01-14 11:30 114 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGCP-Global.reg
2009-01-12 00:16 114 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146043.reg
2009-01-13 00:17 114 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148582.reg
2009-01-14 11:30 88 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGIESH-Global.reg
2009-01-12 00:16 88 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146031.reg
2009-01-13 00:17 88 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148570.reg
2009-01-14 11:30 244 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGNTCVW-Global.reg
2009-01-12 00:16 244 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146041.reg
2009-01-13 00:17 244 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148580.reg
2009-01-14 11:30 337 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGNTCVWL-Global.reg
2009-01-12 00:16 337 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146039.reg
2009-01-13 00:17 337 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148578.reg
2009-01-14 11:30 957 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS1-Global.reg
2009-01-12 00:16 957 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146073.reg
2009-01-13 00:17 957 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148611.reg
2009-01-14 11:30 205 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS1SM-Global.reg
2009-01-12 00:16 205 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146036.reg
2009-01-13 00:17 205 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148575.reg
2009-01-14 11:30 86 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS2-Global.reg
2009-01-12 13:08 86 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146072.reg
2009-01-13 00:17 86 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148610.reg
2009-01-14 11:30 205 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS2SM-Global.reg
2009-01-12 00:16 205 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146035.reg
2009-01-13 00:17 205 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148574.reg
2009-01-14 11:30 90 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS3-Global.reg
2009-01-12 00:16 90 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146071.reg
2009-01-13 00:17 90 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148609.reg
2009-01-14 11:30 180 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS3SM-Global.reg
2009-01-12 00:16 180 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146034.reg
2009-01-13 00:17 180 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148573.reg
2009-01-14 11:30 94 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS4-Global.reg
2009-01-12 00:16 94 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146070.reg
2009-01-13 00:17 94 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148608.reg
2009-01-14 11:30 14017 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGSS-Global.reg
2009-01-12 00:16 14017 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146027.reg
2009-01-13 00:17 14017 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148568.reg
2009-01-14 11:30 323 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGSSODL-Global.reg
2009-01-12 00:16 323 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146037.reg
2009-01-13 00:17 323 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148576.reg
2009-01-14 11:30 3765 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGWLN-Global.reg
2009-01-12 00:16 3879 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146030.reg
2009-01-13 00:17 3765 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148569.reg
2009-01-14 11:30 717 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBME-Andrew.reg
2009-01-12 00:16 717 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146063.reg
2009-01-13 00:17 717 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148602.reg
2009-01-14 11:30 115 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP1-Andrew.reg
2009-01-12 00:16 115 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146061.reg
2009-01-13 00:17 115 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148600.reg
2009-01-14 11:30 290 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP2a-Andrew.reg
2009-01-12 00:16 260 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146060.reg
2009-01-13 00:17 290 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148599.reg
2009-01-14 11:30 406 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP2b-Andrew.reg
2009-01-12 00:16 406 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146059.reg
2009-01-13 00:17 406 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148598.reg
2009-01-14 11:30 177 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP3-Andrew.reg
2009-01-12 00:16 177 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146058.reg
2009-01-13 00:17 177 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148597.reg
2009-01-14 11:30 160 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBP4-Andrew.reg
2009-01-12 00:16 160 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146057.reg
2009-01-13 00:17 160 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148596.reg
2009-01-14 11:30 5912 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBTB1-Andrew.reg
2009-01-12 00:16 5912 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146069.reg
2009-01-13 00:17 5912 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148607.reg
2009-01-14 11:30 671 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUBTB2-Andrew.reg
2009-01-12 00:16 671 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146065.reg
2009-01-13 00:17 671 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148604.reg
2009-01-14 11:30 113 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUCP-Andrew.reg
2009-01-12 00:16 113 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146044.reg
2009-01-13 00:17 113 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148583.reg
2009-01-14 11:30 136 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUDesk-Andrew.reg
2009-01-12 00:16 136 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146033.reg
2009-01-13 00:17 136 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148572.reg
2009-01-14 11:30 222 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUIESH-Andrew.reg
2009-01-12 00:16 222 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146032.reg
2009-01-13 00:17 222 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148571.reg
2009-01-14 11:30 235 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUNTCVW-Andrew.reg
2009-01-12 00:16 235 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146042.reg
2009-01-13 00:17 235 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148581.reg
2009-01-14 11:30 390 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUNTCVWL-Andrew.reg
2009-01-12 00:16 390 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146040.reg
2009-01-13 00:17 390 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148579.reg
2009-01-14 11:30 380 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS1-Andrew.reg
2009-01-12 12:13 462 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146077.reg
2009-01-13 19:15 462 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148559.reg
2009-01-14 11:30 85 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS2-Andrew.reg
2009-01-12 00:16 85 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146076.reg
2009-01-13 00:17 85 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148614.reg
2009-01-14 11:30 89 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS3-Andrew.reg
2009-01-12 00:16 89 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146075.reg
2009-01-13 00:17 89 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148613.reg
2009-01-14 11:30 93 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUS4-Andrew.reg
2009-01-12 00:16 93 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146074.reg
2009-01-13 00:17 93 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148612.reg
2009-01-14 11:30 105 c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegUSSODL-Andrew.reg
2009-01-12 00:16 105 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146038.reg
2009-01-13 00:17 105 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901\A0148577.reg
c:\documents and settings\Andrew\Desktop\avg75free_516a1225.exe
2008-02-11 14:11 31768752 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897\A0146023.exe
2009-01-14 11:48 245800 c:\program files\Alwil Software\Avast4\DATA\aswar0.dll
2009-01-12 12:12 237560 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146289.dll
2009-01-14 11:24 245800 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902\A0148665.dll
2009-01-14 11:48 391216 c:\program files\Alwil Software\Avast4\DATA\clnr0.dll
2009-01-12 12:12 391216 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146290.dll
2009-01-14 11:24 391216 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902\A0148666.dll
2009-01-14 11:48 9080 c:\program files\Alwil Software\Avast4\DATA\exts0.dll
2009-01-12 12:12 9080 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899\A0146291.dll
2009-01-14 11:24 9080 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902\A0148667.dll
2008-11-26 09:15 97480 c:\windows\system32\AvastSS.scr
2008-11-26 09:15 97480 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898\A0146192.scr
2008-11-26 09:15 97480 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902\A0148680.scr
c:\windows\system32\cbXRjGVl.dll
2009-01-10 15:03 52224 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898\A0146085.dll
c:\windows\system32\ohfajk.dll
2009-01-12 02:25 124928 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898\A0146086.dll
c:\windows\system32\taoyvsfp.dll
2009-01-12 02:25 124928 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898\A0146087.dll
c:\windows\system32\xxyawwVN.dll
2009-01-10 15:09 46592 {4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898\A0146088.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"NetZero_uoltray"="c:\program files\NetZero\exec.exe" [2007-10-15 1636864]
"Aim6"="c:\program files\AIM6\aim6.exe" [2006-11-07 50736]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-01 4670968]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-04-27 7573504]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2006-04-27 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-09 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"nwiz"="nwiz.exe" [2006-04-27 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2007-06-23 303104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Pidgin\\pidgin.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-10 111184]
R3 pnicII;Linksys Fast Ethernet PCI Card;c:\windows\system32\drivers\LNE100.SYS [2000-02-10 20573]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-10 20560]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-01-25 42000]
S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
.
Contents of the 'Scheduled Tasks' folder
2009-01-14 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-01-07 07:47]
.
- - - - ORPHANS REMOVED - - - -
BHO-{12A56145-AF5E-450D-BD00-9EF8AED62324} - (no file)
BHO-{7C7F0A88-E7D3-4D1B-BDD0-D98F6499CD82} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.google.com
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
TCP: {A16447C3-1E1E-462E-9A78-AE0FFB4A023B} = 4.2.2.2,4.2.2.1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-14 11:49:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\rundll32.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\devldr32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-14 11:51:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-14 19:51:14
ComboFix2.txt 2009-01-13 02:42:26
ComboFix3.txt 2009-01-12 21:43:03
ComboFix4.txt 2009-01-10 01:02:12
Pre-Run: 61,919,154,176 bytes free
Post-Run: 62,123,466,752 bytes free
442 --- E O F --- 2009-01-12 19:53:20
Here is the next log:
36594438.FIL;C:\$VAULT$.AVG;Probably Trojan.Packed.196;;
inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.3;Probably BACKDOOR.Trojan;;
ocpinst.exe\data529;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.3\ocpinst.exe;Probably BACKDOOR.Trojan;;
ocpinst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.3;Archive contains infected objects;Moved.;
RegUBP2b-Andrew.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.;
aolsetup.exe;C:\Program Files\AIM6\services\softwareUpdate\ver2_13_13_7;Probably BACKDOOR.Trojan;;
cbXRjGVl.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1596;Deleted.;
ohfajk.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Probably Trojan.Packed.213;;
taoyvsfp.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Probably Trojan.Packed.213;;
xxyawwVN.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Probably Trojan.Packed.213;;
A0146059.reg;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP897;Trojan.StartPage.1505;Deleted.;
A0146085.dll;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898;Trojan.Virtumod.1596;Deleted.;
A0146086.dll;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898;Probably Trojan.Packed.213;;
A0146087.dll;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898;Probably Trojan.Packed.213;;
A0146088.dll;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898;Probably Trojan.Packed.213;;
A0146091.bat;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898;Probably BATCH.Virus;;
A0146162.reg;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP898;Trojan.StartPage.1505;Deleted.;
A0146299.bat;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP899;Probably BATCH.Virus;;
A0147353.EXE;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP900;Program.PsExec.170;;
A0147368.bat;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP900;Probably BATCH.Virus;;
A0147377.EXE;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP900;Program.PsExec.170;;
A0147469.reg;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP900;Trojan.StartPage.1505;Deleted.;
A0148598.reg;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901;Trojan.StartPage.1505;Deleted.;
A0148621.bat;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP901;Probably BATCH.Virus;;
A0148675.bat;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902;Probably BATCH.Virus;;
A0148684.EXE;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902;Program.PsExec.170;;
A0148722.exe\data529;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902\A0148722.exe;Probably BACKDOOR.Trojan;;
A0148722.exe;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902;Archive contains infected objects;Moved.;
A0148723.reg;C:\System Volume Information\_restore{4733C595-D74F-4A8C-B2C1-B89BAE2468BE}\RP902;Trojan.StartPage.1505;Deleted.;