Page 1 of 2 12 LastLast
Results 1 to 10 of 15

Thread: Virtumonde i think is gone but still popups?

  1. #1
    Member
    Join Date
    Jul 2008
    Posts
    41

    Default Virtumonde i think is gone but still popups?

    I turned sys restore off then rebooted safe mode deleted virtumonde backup in C drive then well reboot then scanned again nothing found from system search and destroy except 2 cookies but no trace of virtumonde still shows it searching the directories where i guess it used to be but other than that im still getting popups even with my popup blocker on high help me? i think i might still have something left somewhere ty





    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:26:20 PM, on 7/16/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
    C:\program files\powerstrip\pstrip.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DNA\btdna.exe
    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Xfire\xfire.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    R3 - URLSearchHook: (no name) - {f592709f-ff4a-4862-b659-4afabda56312} - (no file)
    F1 - win.ini: run= C:\WESTWOOD\LOLG\ICONS95.EXE
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
    O2 - BHO: {8b3a20df-e8fa-8f38-9bd4-9855e8f873b3} - {3b378f8e-5589-4db9-83f8-af8efd02a3b8} - C:\WINDOWS\system32\cfyvya.dll
    O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
    O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
    O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
    O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [IMC] C:\Program Files\FriendFinder\FriendFinder Messenger 40\imc.exe
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
    O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Michael Gilbertson\Start Menu\Programs\IMVU\Run IMVU.lnk
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.2.100.cab
    O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/...nlineGames.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.co...s/MsnPUpld.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5...ws-i586-jc.cab
    O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://www.playwhat.com/solidPlugin/solidstateion.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

    --
    End of file - 10772 bytes

    Oh and i even scanned with malware bytes to

    Quote Originally Posted by Necrucifer View Post
    Oh and i even scanned with malware bytes to,
    and if you wanted to know where i got it lol ill say this much, do not EVER look at porn unless its on DVD so i hope someone can help ty

    its not gone and well its been on my pc for 5 days i managed to be keeping it fine but kinda wondering is anyone actually out there?


    Edit:
    kinda wondering is anyone actually out there?
    Please read the forum stickies and do not bump topic with extra posts, thanks.

    "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)
    The Waiting Room: Post here if waiting for help longer than four days
    Last edited by tashi; 2008-07-18 at 08:07. Reason: Mod: four posts merged, added link

  2. #2
    Member
    Join Date
    Jul 2008
    Posts
    41

    Default

    I read all that and sorry but well i dont know what bumping is and i know i have trojans on my pc and well i think its getting worst by the time someone reads that its gonna be 50x worst anyway

  3. #3
    Security Expert Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,470

    Default

    Hi

    Turn system restore back on if it still off. Even an infected restore point is better than nothing.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

    1. Download combofix from any of these links and save it to Desktop:
    Link 1
    Link 2
    Link 3

    **Note: It is important that it is saved directly to your desktop**

    2. Double click combofix.exe & follow the prompts.
    3. When finished, it shall produce a log for you (C:\ComboFix.txt). Post that log & a fresh hjt log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.

    If you have problems with Combofix usage, see here
    Microsoft MVP Consumer Security 2008 2009 2010 2011 2012
    ASAP & UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  4. #4
    Member
    Join Date
    Jul 2008
    Posts
    41

    Default

    ComboFix 08-07-21.2 - Michael Gilbertson 2008-07-22 22:06:19.2 - NTFSx86 MINIMAL
    Running from: C:\Documents and Settings\Michael Gilbertson\Desktop\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\system32\aorcrvrc.dll
    C:\WINDOWS\system32\hmowyjbj.dll
    C:\WINDOWS\system32\klugdkvw.ini
    C:\WINDOWS\system32\sysusqyp.dll
    C:\WINDOWS\system32\wlkuwu.dll
    .
    ---- Previous Run -------
    .
    C:\WINDOWS\system32\mcrh.tmp

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_NPF


    ((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))
    .

    2008-07-17 01:29 . 2008-07-17 01:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
    2008-07-17 00:26 . 2008-07-17 00:26 <DIR> d-------- C:\Screen Recordings
    2008-07-16 21:20 . 2008-07-22 15:42 <DIR> d--h----- C:\$AVG8.VAULT$
    2008-07-16 21:08 . 2008-07-22 08:05 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
    2008-07-16 21:08 . 2008-07-16 21:08 <DIR> d-------- C:\Program Files\AVG
    2008-07-16 21:08 . 2008-07-16 21:19 <DIR> d-------- C:\Documents and Settings\Michael Gilbertson\Application Data\AVGTOOLBAR
    2008-07-16 21:08 . 2008-07-16 21:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
    2008-07-16 21:08 . 2008-07-16 21:08 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
    2008-07-16 21:08 . 2008-07-16 21:08 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
    2008-07-16 21:08 . 2008-07-16 21:08 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
    2008-07-16 18:24 . 2008-07-16 18:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-07-16 18:24 . 2008-07-16 18:24 <DIR> d-------- C:\Documents and Settings\Michael Gilbertson\Application Data\Malwarebytes
    2008-07-16 18:24 . 2008-07-16 18:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-07-16 18:24 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
    2008-07-16 18:24 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-07-16 17:08 . 2008-07-16 17:08 <DIR> d-------- C:\Program Files\ZD Soft
    2008-07-16 16:51 . 2008-07-16 16:52 <DIR> d-------- C:\Program Files\BSR Screen Recorder 4
    2008-07-16 16:51 . 2008-07-16 16:51 585,728 --a------ C:\WINDOWS\system32\bsratswf.dll
    2008-07-16 16:51 . 2008-07-16 16:51 147,456 --a------ C:\WINDOWS\system32\bsratwmv.dll
    2008-07-16 16:51 . 2008-07-16 17:07 2,048 --a------ C:\WINDOWS\system32\Tr_sttool.dat
    2008-07-15 18:46 . 2008-07-15 18:46 <DIR> d-------- C:\Program Files\Bethesda Softwork
    2008-07-14 17:24 . 2008-07-22 22:14 <DIR> d-------- C:\Program Files\Trojan Remover
    2008-07-14 17:24 . 2008-07-14 17:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
    2008-07-14 16:56 . 2008-07-16 21:29 <DIR> d-------- C:\Program Files\SpyZooka
    2008-07-14 16:56 . 2008-07-14 17:35 <DIR> d-------- C:\Program Files\PowerStrip
    2008-07-14 16:55 . 2008-07-17 13:59 <DIR> d-------- C:\Program Files\Steam
    2008-07-14 12:57 . 2008-07-14 15:00 1,841,443 --a------ C:\WINDOWS\system32\fyctovdo.ini.ren
    2008-07-14 12:57 . 2008-07-14 12:57 81,168 --a------ C:\WINDOWS\system32\odvotcyf.dll.ren
    2008-07-14 12:56 . 2008-07-14 15:12 615,135 --a------ C:\WINDOWS\system32\KjRBJRqr.ini2.ren
    2008-07-14 12:56 . 2008-07-14 15:14 614,386 --ahs---- C:\WINDOWS\system32\KjRBJRqr.ini.ren
    2008-07-14 12:56 . 2008-07-14 12:56 314,672 --a------ C:\WINDOWS\system32\rqRJBRjK.dll.ren
    2008-07-14 12:28 . 2008-07-21 18:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-07-14 12:28 . 2008-07-14 12:28 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-07-14 09:47 . 2008-07-14 09:52 1,840,559 --a------ C:\WINDOWS\system32\bwybvtqa.ini.ren
    2008-07-14 09:47 . 2008-07-14 09:47 81,152 --a------ C:\WINDOWS\system32\aqtvbywb.dll.ren
    2008-07-14 09:41 . 2008-07-14 11:12 620,858 --a------ C:\WINDOWS\system32\jPonnnpo.ini2.ren
    2008-07-14 09:41 . 2008-07-14 11:13 620,858 --a------ C:\WINDOWS\system32\jPonnnpo.ini.ren
    2008-07-14 09:41 . 2008-07-14 09:41 314,752 --a------ C:\WINDOWS\system32\opnnnoPj.dll.ren
    2008-07-14 08:08 . 2008-07-14 16:56 <DIR> d-------- C:\Program Files\PowerStrip(2)
    2008-07-14 02:20 . 2008-07-14 02:20 1,878,176 --a------ C:\WINDOWS\system32\obkfpisy.ini.ren
    2008-07-14 02:17 . 2008-07-14 08:09 611,321 --a------ C:\WINDOWS\system32\kkkjlnnn.ini.ren
    2008-07-14 02:17 . 2008-07-14 08:07 610,648 --a------ C:\WINDOWS\system32\kkkjlnnn.ini2.ren
    2008-07-14 01:01 . 2008-07-14 01:09 607,906 --a------ C:\WINDOWS\system32\SttvDcdd.ini2.ren
    2008-07-14 01:01 . 2008-07-14 01:09 607,906 --a------ C:\WINDOWS\system32\SttvDcdd.ini.ren
    2008-07-14 01:01 . 2008-07-14 01:01 314,608 --a------ C:\WINDOWS\system32\ddcDvttS.dll.ren
    2008-07-14 00:24 . 2008-07-14 16:56 <DIR> d-------- C:\Program Files\Trojan Remover(2)
    2008-07-13 23:46 . 2008-07-13 23:46 <DIR> d-------- C:\Program Files\INAC
    2008-07-13 19:42 . 2008-07-13 19:42 <DIR> d-------- C:\Program Files\Common Files\Download Manager
    2008-07-13 18:20 . 2008-07-13 18:20 81,152 --a------ C:\WINDOWS\system32\omkefayu.dll.ren
    2008-07-13 17:00 . 2008-07-13 17:00 <DIR> d-------- C:\Program Files\Trend Micro
    2008-07-13 01:39 . 2008-07-13 01:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
    2008-07-13 01:38 . 2008-07-13 01:38 0 --a------ C:\WINDOWS\ativpsrm.bin
    2008-07-11 13:04 . 2008-07-13 16:47 <DIR> d-------- C:\Program Files\WHITE
    2008-07-11 12:21 . 2008-07-13 16:47 <DIR> d-------- C:\Program Files\NCH Swift Sound
    2008-07-11 12:21 . 2008-07-13 16:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
    2008-07-10 11:52 . 2008-07-15 22:06 626,742 --ahs---- C:\WINDOWS\system32\QrAGOXbc.ini2.ren
    2008-07-10 11:52 . 2008-07-15 22:07 626,742 --ahs---- C:\WINDOWS\system32\QrAGOXbc.ini.ren
    2008-07-10 11:51 . 2008-07-10 11:52 314,608 --a------ C:\WINDOWS\system32\cbXOGArQ.dll.ren
    2008-07-10 01:40 . 2008-07-10 01:40 <DIR> d-------- C:\Program Files\cheapestsoft
    2008-07-10 01:22 . 2008-07-10 01:22 <DIR> d-------- C:\temp
    2008-07-10 01:22 . 2008-07-10 01:41 <DIR> d-------- C:\Program Files\PMPro Flash To iPod-PSP-3gp-Mp4 Converter
    2008-07-10 01:22 . 2008-07-10 01:22 <DIR> d-------- C:\MediaOut
    2008-07-09 21:22 . 2008-07-09 21:22 <DIR> d-------- C:\Program Files\Red Kawa
    2008-07-08 17:17 . 2008-07-08 17:17 <DIR> d-------- C:\Program Files\Mediafour
    2008-07-06 21:03 . 2008-07-06 21:21 <DIR> d-------- C:\illusion
    2008-07-06 20:39 . 2008-07-06 20:35 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
    2008-07-06 02:50 . 2008-07-06 02:50 <DIR> d-------- C:\Program Files\Paradox Interactive
    2008-07-05 16:21 . 2008-07-05 16:21 <DIR> d-------- C:\Program Files\OpenAL
    2008-07-05 03:54 . 2008-07-05 03:54 <DIR> d-------- C:\Program Files\Vuze
    2008-07-03 01:56 . 2008-07-03 02:01 <DIR> d-------- C:\Documents and Settings\Michael Gilbertson\Application Data\Hamachi
    2008-07-03 01:55 . 2008-07-03 01:56 <DIR> d-------- C:\Program Files\Hamachi
    2008-07-03 01:55 . 2008-07-03 01:55 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
    2008-06-29 12:38 . 2008-07-06 01:10 <DIR> d-------- C:\Program Files\Frets on Firez
    2008-06-29 12:38 . 2008-06-29 12:39 <DIR> d-------- C:\Documents and Settings\Michael Gilbertson\Application Data\fretsonfire
    2008-06-26 16:10 . 2008-06-26 16:10 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
    2008-06-26 16:09 . 2008-06-29 12:28 <DIR> d-------- C:\Program Files\Frets on Fire
    2008-06-23 23:54 . 2008-06-23 23:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
    2008-06-23 23:54 . 2004-08-09 05:04 73,728 --a------ C:\WINDOWS\system32\ISUSPM.cpl
    2008-06-23 20:17 . 2008-06-26 19:04 96 --ah----- C:\WINDOWS\system32\HsInfo.dat
    2008-06-23 18:22 . 2008-06-23 18:22 <DIR> d-------- C:\Program Files\Gravity
    2008-06-23 04:58 . 2008-06-23 05:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Outspark
    2008-06-23 04:51 . 2008-06-23 04:58 <DIR> d-------- C:\Program Files\Outspark

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-07-23 02:02 --------- d-----w C:\Documents and Settings\Michael Gilbertson\Application Data\DNA
    2008-07-22 07:44 --------- d-----w C:\Program Files\AIM6
    2008-07-22 07:43 --------- d-----w C:\Program Files\Viewpoint
    2008-07-22 07:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
    2008-07-22 07:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
    2008-07-22 05:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
    2008-07-21 21:42 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\Xfire
    2008-07-21 01:13 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2008-07-21 01:13 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
    2008-07-20 16:54 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\Azureus
    2008-07-17 19:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-07-17 19:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-07-17 01:20 --------- d-----w C:\Program Files\InternetProgram
    2008-07-16 21:51 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-07-16 17:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-07-16 17:42 --------- d-----w C:\Program Files\Voyage Century Online
    2008-07-16 17:37 --------- d-----w C:\Program Files\1503 AD
    2008-07-14 21:40 --------- d-s---w C:\Program Files\Xfire
    2008-07-14 12:32 --------- d-----w C:\Program Files\CyberLink
    2008-07-13 20:46 --------- d-----w C:\Program Files\VR Mixer ActiveX
    2008-07-13 05:34 --------- d-----w C:\Program Files\ATI Technologies
    2008-07-11 17:14 2,079 ----a-w C:\WINDOWS\wininit.tmp
    2008-07-11 06:11 --------- d-----w C:\Program Files\Bethesda Softworks
    2008-07-10 05:15 --------- d-----w C:\Program Files\AliveMedia
    2008-07-07 00:34 6,656 ----a-w C:\WINDOWS\system32\kbdlk41a.dll
    2008-07-07 00:33 838,144 ----a-w C:\WINDOWS\system32\chtbrkr.dll
    2008-07-07 00:31 1,677,824 ----a-w C:\WINDOWS\system32\chsbrkr.dll
    2008-07-07 00:25 70,656 ----a-w C:\WINDOWS\system32\korwbrkr.dll
    2008-07-07 00:24 7,168 ----a-w C:\WINDOWS\system32\kbdnec95.dll
    2008-07-07 00:23 9,216 ----a-w C:\WINDOWS\system32\kbdnecAT.dll
    2008-07-07 00:22 98,304 ----a-w C:\WINDOWS\system32\msir3jp.dll
    2008-07-06 22:37 7,168 ----a-w C:\WINDOWS\system32\kbdibm02.dll
    2008-07-06 22:37 6,144 ----a-w C:\WINDOWS\system32\kbd101a.dll
    2008-07-06 22:37 218,112 ----a-w C:\WINDOWS\system32\c_g18030.dll
    2008-07-06 22:34 6,144 ----a-w C:\WINDOWS\system32\kbd106n.dll
    2008-07-06 22:30 6,144 ----a-w C:\WINDOWS\system32\kbdax2.dll
    2008-07-06 22:29 6,656 ----a-w C:\WINDOWS\system32\c_is2022.dll
    2008-07-06 22:28 6,144 ----a-w C:\WINDOWS\system32\kbd101.dll
    2008-07-06 22:27 7,680 ----a-w C:\WINDOWS\system32\kbdnecNT.dll
    2008-07-06 22:27 7,168 ----a-w C:\WINDOWS\system32\f3ahvoas.dll
    2008-07-06 22:27 6,144 ----a-w C:\WINDOWS\system32\kbdlk41j.dll
    2008-07-06 07:28 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
    2008-07-05 20:21 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
    2008-07-05 20:21 114,688 ----a-w C:\WINDOWS\system32\OpenAL32.dll
    2008-07-03 20:22 --------- d-----w C:\Program Files\Azureus
    2008-07-03 20:03 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\Ventrilo
    2008-06-30 00:40 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\teamspeak2
    2008-06-29 11:55 --------- d-----w C:\Program Files\LimeWire
    2008-06-24 09:54 --------- d-----w C:\Program Files\CAPCOM
    2008-06-23 22:22 --------- d-----w C:\Program Files\Common Files\InstallShield
    2008-06-21 09:16 --------- d-----w C:\Documents and Settings\Michael Gilbertson\Application Data\acccore
    2008-06-21 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\acccore
    2008-06-21 09:14 --------- d-----w C:\Program Files\Common Files\AOL
    2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    2008-06-19 00:41 --------- d-----w C:\Program Files\Gpotato
    2008-06-17 23:57 --------- d-----w C:\Program Files\Electronic Arts
    2008-06-17 23:57 --------- d-----w C:\Documents and Settings\Michael Gilbertson\Application Data\SPORE Creature Creator
    2008-06-17 22:00 --------- d-----w C:\Program Files\Lionhead Studios
    2008-06-17 21:17 --------- d-----w C:\Documents and Settings\Michael Gilbertson\Application Data\Nexon
    2008-06-14 12:48 --------- d-----w C:\Program Files\RogueRemover FREE
    2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-11 08:49 --------- d-----w C:\Program Files\Maxis
    2008-06-10 23:19 --------- d-----w C:\Program Files\EA GAMES
    2008-06-06 07:52 --------- d-----w C:\Program Files\Microsoft Games
    2008-06-06 07:51 --------- d-----w C:\Program Files\MythWar
    2008-06-06 07:44 --------- d-----w C:\Program Files\Deer Hunter 5
    2008-06-03 17:12 --------- d-----w C:\Program Files\CCleaner
    2008-06-03 03:21 306,688 ----a-w C:\WINDOWS\system32\SET4A.tmp
    2008-06-03 03:21 306,688 ----a-w C:\WINDOWS\system32\SET11.tmp
    2008-06-03 03:11 43,520 ----a-w C:\WINDOWS\system32\SET56.tmp
    2008-06-03 03:11 43,520 ----a-w C:\WINDOWS\system32\SET37.tmp
    2008-06-03 03:11 180,224 ----a-w C:\WINDOWS\system32\SET54.tmp
    2008-06-03 03:11 180,224 ----a-w C:\WINDOWS\system32\SET31.tmp
    2008-06-03 03:09 552,960 ----a-w C:\WINDOWS\system32\SET52.tmp
    2008-06-03 03:09 552,960 ----a-w C:\WINDOWS\system32\SET2B.tmp
    2008-06-03 02:59 3,500,352 ----a-w C:\WINDOWS\system32\SET4E.tmp
    2008-06-03 02:59 3,500,352 ----a-w C:\WINDOWS\system32\SET1A.tmp
    2008-06-03 02:48 2,120,832 ----a-w C:\WINDOWS\system32\SET50.tmp
    2008-06-03 02:48 2,120,832 ----a-w C:\WINDOWS\system32\SET1D.tmp
    2008-06-03 02:29 348,160 ----a-w C:\WINDOWS\system32\SET58.tmp
    2008-06-03 02:29 348,160 ----a-w C:\WINDOWS\system32\SET3A.tmp
    2008-06-03 02:21 557,056 ----a-w C:\WINDOWS\system32\SET4C.tmp
    2008-06-03 02:21 557,056 ----a-w C:\WINDOWS\system32\SET14.tmp
    2008-05-28 08:22 --------- d-----w C:\Program Files\Activision
    2008-05-28 08:19 --------- d-----w C:\Program Files\Atari
    2008-05-28 08:18 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\Atari
    2008-05-28 08:16 --------- d-----w C:\Program Files\Firefly Studios
    2008-05-28 08:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Firefly Studios
    2008-05-26 23:46 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
    2008-05-26 23:46 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
    2008-05-26 23:46 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
    2008-05-26 08:50 --------- d-----w C:\Program Files\Microsoft Silverlight
    2008-05-16 13:21 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
    2008-05-16 01:19 22,328 ----a-w C:\Documents and Settings\Michael Gilbertson\Application Data\PnkBstrK.sys
    2008-05-15 02:18 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
    2008-05-13 14:48 674,600 ----a-w C:\WINDOWS\system32\pbsvc[1].exe
    2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{0A94B116-4504-4e26-AB05-E61E474AA38B}"= "C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL" [2007-09-14 08:47 61440]

    [HKEY_CLASSES_ROOT\clsid\{0a94b116-4504-4e26-ab05-e61e474aa38b}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}"= "C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL" [2008-03-15 05:11 266240]

    [HKEY_CLASSES_ROOT\clsid\{e3ea4fd9-cade-4ae5-84f7-086eee888be4}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{E3EA4FD9-CADE-4AE5-84F7-086EEE888BE4}"= "C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL" [2008-03-15 05:11 266240]

    [HKEY_CLASSES_ROOT\clsid\{e3ea4fd9-cade-4ae5-84f7-086eee888be4}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 06:48 157592]
    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
    "BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-12 02:23 289088]
    "Power2GoExpress"="C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" [2005-01-07 18:51 1380445]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
    "Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-19 13:51 50528]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2004-04-06 18:14 504080]
    "D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-03-18 05:34 1228800]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
    "XboxStat"="c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 18:05 734264]
    "PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-02-16 19:09 802552]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 22:32 208952]
    "IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2008-07-06 20:30 44032]
    "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 22:31 59392]
    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 22:32 455168]
    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 22:32 455168]
    "TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2007-06-10 17:38 431696]
    "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-16 21:08 1232152]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.iv31"= C:\WINDOWS\system32\ir32_32.dll
    "vidc.iv32"= C:\WINDOWS\system32\ir32_32.dll
    "msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
    "VIDC.XFR1"= xfcodec.dll
    "VIDC.ZDSV"= scrvid.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
    backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Michael Gilbertson^Start Menu^Programs^Startup^OpenOffice.org 2.1.lnk]
    path=C:\Documents and Settings\Michael Gilbertson\Start Menu\Programs\Startup\OpenOffice.org 2.1.lnk
    backup=C:\WINDOWS\pss\OpenOffice.org 2.1.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
    C:\WINDOWS\system32\dumprep 0 -u [X]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
    --a------ 2004-12-16 18:49 49152 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a------ 2004-08-04 00:56 15360 C:\WINDOWS\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    --a------ 2007-08-16 14:35 1838592 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a--c--- 2007-06-01 16:51 257088 C:\Program Files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
    --------- 2005-01-07 18:51 1380445 C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    --a--c--- 2003-10-31 20:42 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    --a--c--- 2006-11-09 16:07 49263 C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-07-24 23:36 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
    --a------ 2007-03-14 17:03 24104 C:\Program Files\Zune\ZuneLauncher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    -ra------ 2005-10-04 18:12 90112 C:\WINDOWS\SOUNDMAN.EXE

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\CA\\eTrust Antivirus\\InocIT.exe"=
    "C:\\StubInstaller.exe"=
    "C:\\Program Files\\CA\\eTrust Antivirus\\Realmon.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\CA\\eTrust Antivirus\\Shellscn.exe"=
    "C:\\Program Files\\BYOND\\bin\\byond.exe"=
    "C:\\Program Files\\Xfire\\xfire.exe"=
    "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\michael_e_g\\half-life 2 deathmatch\\hl2.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=
    "C:\\Program Files\\DNA\\btdna.exe"=
    "C:\\Program Files\\1964\\099\\1964.exe"=
    "C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe"=
    "C:\\WINDOWS\\system32\\PnkBstrA.exe"=
    "C:\\WINDOWS\\system32\\PnkBstrB.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\EA GAMES\\American McGee's Alice\\alice.exe"=
    "C:\\GAMES\\NeoSteam\\NSStarter.exe"=
    "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
    "C:\\GAMES\\Paintball2\\paintball2.exe"=
    "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
    "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "C:\\Program Files\\AIM6\\aim6.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "17533:TCP"= 17533:TCP:BitComet 17533 TCP
    "17533:UDP"= 17533:UDP:BitComet 17533 UDP
    "56820:TCP"= 56820:TCP:Pando P2P TCP Listening Port
    "56820:UDP"= 56820:UDP:Pando P2P UDP Listening Port
    "42823:TCP"= 42823:TCP:SolidNetworkManager
    "42823:UDP"= 42823:UDP:SolidNetworkManager
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
    "13500:TCP"= 13500:TCP:Azureus Vuze
    "13500:UDP"= 13500:UDP:Azureus Vuze

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-16 21:08]
    R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-16 21:08]
    R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-16 21:08]
    R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-16 21:08]
    R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:56]
    R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys [2007-07-14 22:37]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
    R3 scrcap;scrcap;C:\WINDOWS\system32\DRIVERS\scrcap.sys [2006-12-27 10:47]
    S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2005-03-22 20:17]
    .
    Contents of the 'Scheduled Tasks' folder
    "2008-07-07 12:19:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-07-22 02:59:41 C:\WINDOWS\Tasks\User_Feed_Synchronization-{E4FB928C-E500-41EB-9001-155F8E007BBA}.job"
    - C:\WINDOWS\system32\msfeedssync.exe
    .
    - - - - ORPHANS REMOVED - - - -

    URLSearchHooks-{f592709f-ff4a-4862-b659-4afabda56312} - (no file)
    BHO-{3b378f8e-5589-4db9-83f8-af8efd02a3b8} - C:\WINDOWS\system32\cfyvya.dll
    WebBrowser-{F592709F-FF4A-4862-B659-4AFABDA56312} - (no file)
    HKCU-Run-IMC - C:\Program Files\FriendFinder\FriendFinder Messenger 40\imc.exe
    HKCU-Run-SweetIM - C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
    MSConfigStartUp-ares - C:\Program Files\Ares\Ares.exe
    MSConfigStartUp-DW4 - C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
    MSConfigStartUp-My Web Search Bar Search Scope Monitor - C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
    MSConfigStartUp-MyWebSearch Email Plugin - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    MSConfigStartUp-StartCCC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe


    .
    ------- Supplementary Scan -------
    .
    R0 -: HKCU-Main,Start Page = hxxp://www.youtube.com/
    O9 -: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O9 -: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Michael Gilbertson\Start Menu\Programs\IMVU\Run IMVU.lnk

    O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd


    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-22 22:14:03
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\system32\ati2evxx.exe
    C:\WINDOWS\system32\ati2evxx.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    C:\Program Files\AVG\AVG8\avgrsx.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\Program Files\Zune\ZuneNss.exe
    C:\Program Files\AIM6\aolsoftware.exe
    .
    **************************************************************************
    .
    Completion time: 2008-07-22 22:21:38 - machine was rebooted [Michael Gilbertson]
    ComboFix-quarantined-files.txt 2008-07-23 02:21:33

    Pre-Run: 41,093,136,384 bytes free
    Post-Run: 42,450,636,800 bytes free

    382 --- E O F --- 2008-07-10 01:05:00

  5. #5
    Member
    Join Date
    Jul 2008
    Posts
    41

    Default

    And here is my new hijack log sorry for the annoyance just got so worried ty ill be awaiting a reply





    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:25:53 PM, on 7/22/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
    C:\program files\powerstrip\pstrip.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DNA\btdna.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
    O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
    O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Michael Gilbertson\Start Menu\Programs\IMVU\Run IMVU.lnk
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.2.100.cab
    O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/...nlineGames.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.co...s/MsnPUpld.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5...ws-i586-jc.cab
    O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://www.playwhat.com/solidPlugin/solidstateion.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    --
    End of file - 11648 bytes

  6. #6
    Security Expert Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,470

    Default

    Hi

    It's not recommended to have multiple antivirus programs installed in same system. In your case there seems to be AVG8 and some parts of CA Antivirus. Following instructions includes removal of those CA AV parts.


    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 7.
    • Scroll down to where it says
      The J2SE Runtime Environment (JRE) allows end-users to run Java applications.
    • Click the
      Download
      button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u7-windows-i586-p.exe to install the newest version.



    Disable Spybot's TeaTimer
    • Run Spybot-S&D in Advanced Mode
    • If it is not already set to do this, go to the Mode menu
      select
      Advanced Mode
    • On the left hand side, click on Tools
    • Then click on the Resident icon in the list
    • Uncheck
      Resident TeaTimer
      and OK any prompts.
    • Restart your computer



    Start hjt, do a system scan, check:
    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)

    Close browsers and other windows. Click fix checked.

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    Driver::
    InoRPC
    InoRT
    InoTask
    
    File::
    C:\WINDOWS\system32\fyctovdo.ini.ren
    C:\WINDOWS\system32\odvotcyf.dll.ren
    C:\WINDOWS\system32\KjRBJRqr.ini2.ren
    C:\WINDOWS\system32\KjRBJRqr.ini.ren
    C:\WINDOWS\system32\rqRJBRjK.dll.ren
    C:\WINDOWS\system32\bwybvtqa.ini.ren
    C:\WINDOWS\system32\aqtvbywb.dll.ren
    C:\WINDOWS\system32\jPonnnpo.ini2.ren
    C:\WINDOWS\system32\jPonnnpo.ini.ren
    C:\WINDOWS\system32\opnnnoPj.dll.ren
    C:\WINDOWS\system32\obkfpisy.ini.ren
    C:\WINDOWS\system32\kkkjlnnn.ini.ren
    C:\WINDOWS\system32\kkkjlnnn.ini2.ren
    C:\WINDOWS\system32\SttvDcdd.ini2.ren
    C:\WINDOWS\system32\SttvDcdd.ini.ren
    C:\WINDOWS\system32\ddcDvttS.dll.ren
    C:\WINDOWS\system32\omkefayu.dll.ren
    C:\WINDOWS\system32\QrAGOXbc.ini2.ren
    C:\WINDOWS\system32\QrAGOXbc.ini.ren
    C:\WINDOWS\system32\cbXOGArQ.dll.ren
    
    Folder::
    C:\Program Files\CA

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.


    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.


    Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, click Yes.
    • The program will launch and start to download the latest definition files.
    • Once the scanner is installed and the definitions downloaded, click Next.
    • Now click on Scan Settings and select the following:
    Scan using the following Anti-Virus database:
    • Extended (If available, otherwise Standard)
    Scan Options:
    • Scan Archives
    • Scan Mail Bases
    • Click OK.
    • Under
      select a target to scan
      , select My Computer.
    • The scan will take a while so be patient and let it run. As it scans your machine very deeply it could take hours to complete, Kaspersky suggests running it during a time of low activity.
    Once the scan is complete:
    • Click on the Save as Text button.
    • Save the file to your desktop.
    • Copy and paste that information into your next post if the AV content will fit into one post only. Post a fresh hjt log (without forgetting above meantioned ComboFix resultant log) too.



    Note for Internet Explorer 7 users: If at any time you have trouble with the Accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.

    If having a problme doing the above

    Make sure that your Internet security settings are set to default values.

    To set default security settings for Internet Explorer:

    * Open Internet Explorer.
    * Go to the Tools menu, then choose Internet Options.
    * Click on the Security tab.
    * Make sure that all four item (Internet, Local intranet, Trusted sites, and Restricted sites) are set to their default settings.
    Microsoft MVP Consumer Security 2008 2009 2010 2011 2012
    ASAP & UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Member
    Join Date
    Jul 2008
    Posts
    41

    Default

    Hello there,

    I about had kaspersky done scanning at 95% and guess what? i went to go right click on a file or folder or anything on my desktop really it pops up something with CA my antivirus i used to have wanting to install or something about a .msi? and i ended the task and welp there went everything i got to start the scan back over and i am wondering will this get fixed as well? because it was fine till the combofix got rid of my CA i hope this gets fixed as well bc i dont need another thing screwed up on my comp ill repost my logs back in say another 2 hours which shoulda been now

  8. #8
    Member
    Join Date
    Jul 2008
    Posts
    41

    Default

    Nevermind i fixed it heres the other logs

    Wednesday, July 23, 2008 9:36:49 AM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 23/07/2008
    Kaspersky Anti-Virus database records: 996706


    Scan Settings
    Scan using the following antivirus database extended
    Scan Archives true
    Scan Mail Bases true

    Scan Target My Computer
    A:\
    C:\
    D:\
    E:\
    F:\

    Scan Statistics
    Total number of scanned objects 163960
    Number of viruses found 3
    Number of infected objects 6
    Number of suspicious objects 0
    Duration of the scan process 02:23:30

    Infected Object Name Virus Name Last Action
    C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

    C:\Documents and Settings\Administrator\Desktop\SmitfraudFix.exe/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

    C:\Documents and Settings\Administrator\Desktop\SmitfraudFix.exe RAR: infected - 1 skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

    C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp Object is locked skipped

    C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped

    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Desktop\Junk\games and stuff\terra aria.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\Application Data\Microsoft\Zune\CurrentDatabase_365.wmdb Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\History\History.IE5\MSHist012008072320080724\index.dat Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\temp\~DF429B.tmp Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\temp\~DF4566.tmp Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\ntuser.dat Object is locked skipped

    C:\Documents and Settings\Michael Gilbertson\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080723-042530.log Object is locked skipped

    C:\QooBox\Quarantine\C\WINDOWS\system32\sysusqyp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.abmp skipped

    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    C:\System Volume Information\_restore{189764FD-CD59-4E40-97DB-67C67E4DE5C2}\RP11\change.log Object is locked skipped

    C:\System Volume Information\_restore{189764FD-CD59-4E40-97DB-67C67E4DE5C2}\RP5\A0000553.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.abmp skipped

    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

    C:\WINDOWS\Sti_Trace.log Object is locked skipped

    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

    C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped

    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\default Object is locked skipped

    C:\WINDOWS\system32\config\default.LOG Object is locked skipped

    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

    C:\WINDOWS\system32\config\SAM Object is locked skipped

    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINDOWS\system32\config\software Object is locked skipped

    C:\WINDOWS\system32\config\software.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\system Object is locked skipped

    C:\WINDOWS\system32\config\system.LOG Object is locked skipped

    C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

    C:\WINDOWS\system32\h323log.txt Object is locked skipped

    C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    C:\WINDOWS\wiadebug.log Object is locked skipped

    C:\WINDOWS\wiaservc.log Object is locked skipped

    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.




    HERE IS MY HIJACK LOG

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:38:32 AM, on 7/23/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
    C:\program files\powerstrip\pstrip.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DNA\btdna.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL
    O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
    O3 - Toolbar: Pando Toolbar - {E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4} - C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL
    O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
    O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Michael Gilbertson\Start Menu\Programs\IMVU\Run IMVU.lnk
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus...an_unicode.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.2.100.cab
    O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/...nlineGames.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.co...s/MsnPUpld.cab
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
    O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://www.playwhat.com/solidPlugin/solidstateion.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    --
    End of file - 9743 bytes

  9. #9
    Member
    Join Date
    Jul 2008
    Posts
    41

    Default

    ComboFix 08-07-22.3 - Michael Gilbertson 2008-07-23 4:19:07.3 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.596 [GMT -4:00]
    Running from: C:\Documents and Settings\Michael Gilbertson\Desktop\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Michael Gilbertson\Desktop\CFScript.txt
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    FILE ::
    C:\WINDOWS\system32\aqtvbywb.dll.ren
    C:\WINDOWS\system32\bwybvtqa.ini.ren
    C:\WINDOWS\system32\cbXOGArQ.dll.ren
    C:\WINDOWS\system32\ddcDvttS.dll.ren
    C:\WINDOWS\system32\fyctovdo.ini.ren
    C:\WINDOWS\system32\jPonnnpo.ini.ren
    C:\WINDOWS\system32\jPonnnpo.ini2.ren
    C:\WINDOWS\system32\KjRBJRqr.ini.ren
    C:\WINDOWS\system32\KjRBJRqr.ini2.ren
    C:\WINDOWS\system32\kkkjlnnn.ini.ren
    C:\WINDOWS\system32\kkkjlnnn.ini2.ren
    C:\WINDOWS\system32\obkfpisy.ini.ren
    C:\WINDOWS\system32\odvotcyf.dll.ren
    C:\WINDOWS\system32\omkefayu.dll.ren
    C:\WINDOWS\system32\opnnnoPj.dll.ren
    C:\WINDOWS\system32\QrAGOXbc.ini.ren
    C:\WINDOWS\system32\QrAGOXbc.ini2.ren
    C:\WINDOWS\system32\rqRJBRjK.dll.ren
    C:\WINDOWS\system32\SttvDcdd.ini.ren
    C:\WINDOWS\system32\SttvDcdd.ini2.ren
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Program Files\CA
    C:\Program Files\CA\eTrust Antivirus\00000001.QSD\QSYS.QJF
    C:\Program Files\CA\eTrust Antivirus\00000001.QSD\QSYS.QUF
    C:\Program Files\CA\eTrust Antivirus\00000002.QSD\QSYS.QJF
    C:\Program Files\CA\eTrust Antivirus\00000002.QSD\QSYS.QUF
    C:\Program Files\CA\eTrust Antivirus\ArcTemp\arc0000.tmp
    C:\Program Files\CA\eTrust Antivirus\ArcTemp\arc0001.tmp
    C:\Program Files\CA\eTrust Antivirus\ArcTemp\arc0002.tmp
    C:\Program Files\CA\eTrust Antivirus\ArcTemp\arc0003.tmp
    C:\Program Files\CA\eTrust Antivirus\backup\ino_flpy.sys.bak
    C:\Program Files\CA\eTrust Antivirus\backup\ino_fltr.sys.bak
    C:\Program Files\CA\eTrust Antivirus\CheyTNG.dll
    C:\Program Files\CA\eTrust Antivirus\csctrlu.dll
    C:\Program Files\CA\eTrust Antivirus\DB\EV2c33af64-225c-49dc-a25f-750149458be8.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\EV2ffba24b-6661-4820-92b2-cf6993534665.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\EV39cd000c-ae6e-410a-ae18-61ea5a5a35d4.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\EV49631ffe-b8a8-4dbb-ae21-3596eab4e6d1.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\EV5e044275-94b3-4198-84dd-c40be923b818.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\EVd95435e4-d711-41d6-88ba-56ff368b413a.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\EVe83e5309-3b97-4475-b455-48ad47da6e47.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\evmaster.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\evmaster.ntx
    C:\Program Files\CA\eTrust Antivirus\DB\RT4b3f55e6-7b1e-4ee3-84ae-e995df150819.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\RT6e665ec0-b7bc-467b-a219-155e61715b6f.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\RT9f808f3b-9a5f-4e39-81d2-8445de42c036.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\RTc3acaa2c-6db6-4c57-9690-7ffeda85b0e6.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\RTc8c97baa-08df-4ee3-8f85-fc12cfea63df.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\rtmaster.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\rtmaster.ntx
    C:\Program Files\CA\eTrust Antivirus\DB\scanlog.dbf
    C:\Program Files\CA\eTrust Antivirus\DB\scanlog.ntx
    C:\Program Files\CA\eTrust Antivirus\Favorite.ico
    C:\Program Files\CA\eTrust Antivirus\IClass32.dll
    C:\Program Files\CA\eTrust Antivirus\IcmDlgNT.dll
    C:\Program Files\CA\eTrust Antivirus\icore4x.dll
    C:\Program Files\CA\eTrust Antivirus\In6Disc.dll
    C:\Program Files\CA\eTrust Antivirus\InConfig.dll
    C:\Program Files\CA\eTrust Antivirus\InDrvCfg.dll
    C:\Program Files\CA\eTrust Antivirus\InoAlert.dll
    C:\Program Files\CA\eTrust Antivirus\InoAnalyze.dll
    C:\Program Files\CA\eTrust Antivirus\inoc6.icf
    C:\Program Files\CA\eTrust Antivirus\InocAdn.dll
    C:\Program Files\CA\eTrust Antivirus\InocDB.dll
    C:\Program Files\CA\eTrust Antivirus\InocIT.exe
    C:\Program Files\CA\eTrust Antivirus\InocIT.ico
    C:\Program Files\CA\eTrust Antivirus\Inocore.dll
    C:\Program Files\CA\eTrust Antivirus\InoDist.ini
    C:\Program Files\CA\eTrust Antivirus\InoOEM.dll
    C:\Program Files\CA\eTrust Antivirus\InoOption.dll
    C:\Program Files\CA\eTrust Antivirus\InoPrf.dll
    C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    C:\Program Files\CA\eTrust Antivirus\InoSetup.dll
    C:\Program Files\CA\eTrust Antivirus\InoShell.dll
    C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    C:\Program Files\CA\eTrust Antivirus\InoTNGui.dll
    C:\Program Files\CA\eTrust Antivirus\InoUpTNG.exe
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\about_the_local_scanner_contents_display.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\about_the_local_scanner_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\about_treating_macro_viruses.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\about_using_procedures_for_policy_settings.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\accessing_netware_domains.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\accessing_policy_options_with_container_selected.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\act_action.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\activate_quarantine.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\activating_the_quarantine_feature.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\add_directories_to_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\add_file_path_to_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\add_folders.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\add_signature_update_source.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\add_to_exclude_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\add_to_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\add_to_my_folders.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\adding_a_folder_to_my_folders.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\adding_a_machine_to_a_container.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\adding_directories_to_a_scheduled_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\adding_system_files_to_a_boot_disk.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\adding_to_the_extension_lists.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_manager_comment.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_manager_e_mail.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_manager_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_manager_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_manager_office.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_manager_phone.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_manager_position.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\admin_server_prompts_for_username_and_password.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\alert_custom_notification.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\alert_filter_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\alert_notification_by_level_of_severity.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\alert_report_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\all_except_the_specified_extensions.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\all_extensions.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\allow_fast_backup.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\animated_icon_for_realtime_monitor.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\app_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\apply_extension_filter_to_files_inside_archives.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\apply_infection_actions_on_archive_file_excluding_cure_action.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\applying_policy_to_a_branch.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\applying_policy_to_a_container_using_drag_and_drop.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\assign_to_branch.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\assigning_access_permissions.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\attributes.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\background_scanning.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\biased_election.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\blank.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\blank2.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\blank3.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\blank4.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\blank5.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\blank6.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\block.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\block_extension_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\boot_sector.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\boot_sector_actions.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\browsnxt.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\browsprv.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\ca.css
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\ca.js
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\can_i_use_windows_9x_as_a_redistribution_server.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cancelling_or_deleting_a_scheduled_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cd_rom_drive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\change_default_organization_for_subnet_discovery.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_access_permissions.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_compressed_file_scanning_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_how_long_log_files_are_kept.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_how_often_a_scheduled_scan_runs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_realtime_monitor_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_scanning_engines.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_the_display_of_drive_and_file_types.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_the_settings_of_a_scheduled_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_the_window_view.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\changing_when_a_scheduled_scan_starts.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\choose_type.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\choosing_file_actions_after_running_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\clean_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\clear_last_scan_output.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\clearing_selections_in_the_signatures_to_download_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\command_line_scanner_for_rescue_disk.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\command_line_scanner_for_rescue_disk_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\command_syntax_for_inocmd32.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\command_syntax_for_inocucmd.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\common_file_extensions_for_the_selected_type.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\company_address.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\company_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\comparing_and_restoring_critical_disk_area_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\compressed_file_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\compressed_file_type.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\conflicting_admin_server_ip_address.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\connecting_to_an_admin_server.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contact_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contact_information_option.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contact_information_option_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contact_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_1.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_10.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_11.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_12.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_13.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_14.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_15.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_16.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_17.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_18.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_19.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_2.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_20.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_21.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_22.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_23.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_24.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_25.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_26.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_3.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_4.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_5.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_6.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_7.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_8.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\contents_1_9.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\controlling_file_types_in_the_contents_display.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\controlling_log_file_content.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\copy_file_before_cure.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cou_number.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cpu_usage_level.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\create_a_new_scheduled_scan_job.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\creating_a_full_access_administrator_view_account.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\creating_a_new_container_or_branch.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\creating_a_rescue_disk.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\creating_policy_settings.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\critical_disk_area_files_on_the_rescue_disk.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cure_boot_sector.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cure_by_deleting.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cure_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\curing_an_infected_file_after_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cut_and_paste_a_machine.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\cut_and_paste_containers.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\days_to_keep_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\default_organization_for_subnet_discovery.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\defined_policy.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\delete_02.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\delete_a_policy_or_container.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\delete_all.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\delete_all_log_files_that_are_older_than.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\delete_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\delete_subnet_instance.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\deleting_a_container_from_organization_tree.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\deleting_a_download_source.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\deleting_a_policy_instance.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\deleting_an_infected_file_after_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\deleting_directories_from_the_list_for_a_scheduled_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\deleting_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\deleting_logs_in_the_administrator_view.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\description.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\description_for_subnet.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\designating_proxy_configuration_machines.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\detailed_result_fields.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\detailed_result_for_selected_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\details.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\detection_method.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\detection_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\determine_compression_method_using_file_contents.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\determine_compression_method_using_file_extension.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\diamond.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\directory_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\disabled.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\discover_now.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\discovering_your_antivirus_network_using_inouptng.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\discovering_your_subnets.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\displaying_scan_result_summary_after_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\distribution_events.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\do_not_delete_log_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\do_not_scan_files_migrated_to_external_storage.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\downloading_signatures_now_with_a_container_selected.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\downloading_signatures_now_with_a_policy_selected.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\downloading_updates_at_a_scheduled_time.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\downloading_updates_from_computer_associates.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\downloading_updates_now.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\driver_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\edit_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\edit_policy_instance.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\edit_selected_item.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\edit_subnet_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\editing_the_download_sources_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enable_mail_option.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enable_scheduled_download.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enable_system_cure.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enable_system_event_log.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\eng_engine.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\engine_directory.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enter_a_file_path.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enter_a_full_directory_path.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enter_a_local_file_or_directory_path.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enter_a_new_file_extension.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\enter_a_process_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\event_detail_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\event_log.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\exclude_directories_and_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\exclude_processes.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\excluding_an_item_from_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\excluding_directories_from_a_scheduled_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\excluding_directories_or_files_from_realtime_monitoring.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\excluding_programs_from_realtime_monitoring.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\exempt_from_blocking.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x1.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x10.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x11.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x12.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x13.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x14.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x15.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x16.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x17.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x18.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x19.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x2.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x3.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x4.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x5.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x6.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x7.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x8.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f3x9.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x1.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x10.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x2.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x3.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x4.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x5.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x6.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x7.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x8.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f4x9.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f5x1.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f5x2.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f5x3.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f5x4.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x1.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x10.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x11.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x12.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x13.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x14.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x2.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x3.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x4.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x5.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x6.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x7.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x8.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f7x9.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\f8x1.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\field.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\fil_pattern.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\file_actions.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\file_directory_drive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\file_menu_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\find_machine.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\floppy_drive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\forward_to.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\free_election.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\general_events.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\getting_version_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\guidelines_for_preparing_for_tng_integration.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\handling_a_suspect_file_manually.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\heuristic_scanner.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\hide_files_not_to_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\holding_time_before_redistribution.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\home_directory.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\host_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\how_do_i_authenticate_to_windows_9x.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\hyphen.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\i_cannot_discover_machines_outside_my_local_subnet.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\importing_the_antivirus_repository_script.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\incoming_and_outgoing_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\infected_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\infected_files_02.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\infected_object.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\infection_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\infection_type.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\inocit.ids
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\inosetapproved.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\integrating_with_unicenter_tng.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\integrating_with_unicenter_tng_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\ip_address_for_subnet.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\job_statistics_for_scheduled_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\last_discovery_of_subnet.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\last_responses.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\launch_etrust_antivirus.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\launch_inoculateit.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\limit_number_of_pop_up_messages.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\lis_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\list_of_excluded_directories_and_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\list_of_excluded_processes.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\list_of_exempt_file_path.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\list_of_file_extensions.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\list_of_file_extensions_02.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\list_of_file_extensions_to_block.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\list_of_quarantine_users.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_alert_manager.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_alert_manager_in_unix_and_os_x_systems.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_alert_manager_in_unix_systems.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_hard_drive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_scanner_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_scanner_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_scanner_options_display.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_scanner_options_display_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\local_scanner_options_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\locking_policy_on_local_machines.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\log_detail_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\log_directory.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\log_viewer_icons.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\log_viewer_log_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\machine_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\mail_options_log_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\mail_options_options_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\mail_options_scan_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\mail_options_selection_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_background_processes_on_windows_9x.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_legacy_domains.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_legacy_domains_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_legacy_machines.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_logs_in_administrator_view.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_machines_in_containers.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_machines_in_containers_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_netware_domains.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_policy_instances.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_policy_instances_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_realtime_monitor_options_from_the_system_tray.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_scheduled_scan_jobs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_services_from_the_administrator_view.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\managing_treatment_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\mask_for_subnet.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\maximum_missed_discoveries.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\mca_action.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\menu.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\minus.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\minutes.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\mod_mod.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\modified.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\modifying_policy_settings.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\monitoring_files_copied_to_the_local_drive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\monitoring_incoming_and_outgoing_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\monitoring_outgoing_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\monitoring_signature_downloads.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\move_directory.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\move_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\move_file_if_cure_fails.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\moving_a_machine_to_another_branch.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\moving_an_infected_file_after_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\my_folders_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\network_drive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\new_proxy.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\new_subnet.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\no_action.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\organizing_your_anti_virus_network_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\organizing_your_antivirus_network.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\outgoing_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\password.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\password_for_admin_server.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\perform_fast_download.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\performing_a_file_action_after_running_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\performing_a_local_scan_basic_procedure.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\permission.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\permission_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\phone_number.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\plus.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\policy_settings_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\policy_settings_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\port_number_for_subnet_discovery.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\preparing_for_tng_integration.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\print_log.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\property.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\protect_cd_rom_drives.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\protect_floppy_drives.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\protect_network_drives.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\protecting_against_infections_from_cd_rom_drives.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\protecting_against_infections_from_floppy_drives.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\protecting_against_infections_from_network_drives.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\proxy_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\proxy_override_option.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\purge_log_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\quarantine_time_minutes.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\queue_up_records.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_misc_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_misc_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_notification_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_notification_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_options_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_options_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_policy_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_policy_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_scan_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_scan_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_selection_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_mail_option_selection_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_advanced.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_advanced_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_filters.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_filters_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_quarantine.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_scan_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_selection.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_selection_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_monitor_options_statistics.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_pop_up_messages.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\realtime_scanner_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\recovering_from_a_boot_sector_infection.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\recovering_from_a_memory_virus.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\recovering_from_infections_on_windows_9x.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\refresh.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\refresh_02.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\refreshing_the_quarantined_users_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_02.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_03.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_04.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_05.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_06.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_07.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_08.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_09.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_10.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_100.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_101.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_102.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_103.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_104.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_105.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_106.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_107.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_108.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_109.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_11.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_110.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_111.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_112.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_113.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_114.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_115.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_116.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_117.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_118.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_119.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_12.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_120.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_121.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_122.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_123.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_124.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_125.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_126.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_127.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_128.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_129.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_13.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_14.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_15.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_16.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_17.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_18.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_19.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_20.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_21.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_22.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_23.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_24.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_25.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_26.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_27.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_28.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_29.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_30.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_31.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_32.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_33.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_34.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_35.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_36.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_37.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_38.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_39.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_40.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_41.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_42.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_43.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_44.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_45.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_46.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_47.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_48.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_49.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_50.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_51.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_52.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_53.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_54.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_55.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_56.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_57.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_58.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_59.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_60.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_61.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_62.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_63.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_64.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_65.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_66.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_67.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_68.html

  10. #10
    Member
    Join Date
    Jul 2008
    Posts
    41

    Default

    COMBO LOG CONTINUED

    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_69.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_70.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_71.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_72.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_73.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_74.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_75.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_76.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_77.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_78.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_79.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_80.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_81.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_82.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_83.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_84.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_85.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_86.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_87.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_88.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_89.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_90.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_91.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_92.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_93.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_94.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_95.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_96.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_97.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_98.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\related_topics_99.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remote_installation_for_windows_9x_machines.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remote_management_and_tcp_ip.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remote_path.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remote_path_for_ftp.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removable_drive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remove_02.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remove_03.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remove_all_folders.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remove_all_macros.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remove_from_branch.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remove_from_the_current_parent.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remove_infected_macros.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\remove_this_folder.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_a_folder_from_my_folders.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_a_machine_from_a_branch.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_all_folders_from_my_folders.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_directories_from_scheduled_scan_exclude_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_directories_or_files_from_the_exclude_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_items_from_the_extension_lists.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_locked_policy.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_policy_from_a_branch.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_programs_from_the_exclude_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\removing_users_from_the_quarantine_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\rename_container.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\rename_email_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\rename_extension.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\rename_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\rename_file_if_cure_fails.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\renaming_an_infected_file_after_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\reply_e_mail_address.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\report_only.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\rescue_disk_information_for_advanced_users.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\restoring_renaming_or_deleting_files_in_the_move_folder.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\sca_action.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scan_alternate_data_streams.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scan_compressed_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scan_floppy_drive_on_shutdown.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scan_job_log_list_summary.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scan_result_summary.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scan_results_displayed.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scan_safety_level.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_directory.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_directory_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_for_inocmd32.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_for_inocucmd.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_log.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_log_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_scan_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_selection.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanner_options_selection_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_a_drive_using_the_local_scanner.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_a_file_using_the_local_scanner.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_a_folder_using_the_local_scanner.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_boot_sector_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_engine.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_everything_on_your_hard_drive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_files_stored_externally.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_for_unknown_viruses.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scanning_using_the_shell_extension.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_at_startup.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_local_email_scan_job_directories_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_mail_scan_exclude_mailbox_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_mail_scan_filters_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_mail_scan_mailbox_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_mail_scan_policy_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_mail_scan_scan_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_mail_scan_schedule_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_mail_scan_selection_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_scan_job_description_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_scan_job_directories_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_scan_job_exclude_directories_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_scan_job_options_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_scan_job_schedule_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\schedule_scan_job_schedule_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scheduled_scan_job.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scheduled_scan_job_modify_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scheduled_scan_jobs_summary.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scheduled_scanner_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scheduling_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\scheduling_a_scan_at_startup.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\selecting_a_drive_to_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\selecting_a_file_or_files_to_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\selecting_a_folder_to_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\selecting_a_treatment_before_starting_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\selecting_different_scanner_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\selecting_items_to_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\selecting_regular_file_extensions_to_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\send_all_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\send_analysis_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\send_e_mail_address.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\send_infected_files_only.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\server_name_for_redistribution_server_source_select_method.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_default_placement_of_machines_in_the_organization_tree.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_local_scanner_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_macro_virus_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_realtime_mail_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_realtime_monitor_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_redistribution_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_scan_tab_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_selection_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_signature_update_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_subnet_election_method.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\setting_the_scan_safety_level.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\show_all_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\show_last_scan_summary.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\show_summary_after_scan_completes.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\signature_redistribution_server.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\signature_update_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\signature_update_options_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\signature_update_options_incoming_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\signature_update_options_incoming_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\signature_update_options_outgoing_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\signature_update_options_outgoing_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\signature_update_options_schedule_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\site_id.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\skip_older_than_days.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\skipped_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\smtp_server.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\source_select.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\source_select_method_ftp.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\source_select_method_http.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\source_select_method_local_path.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\source_select_method_redistribution_server.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\source_select_method_unc.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specified_election.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specified_extensions_only.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specifying_a_local_path_download_source.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specifying_a_redistribution_server_download_source.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specifying_a_unc_download_source.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specifying_an_ftp_download_source.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specifying_download_sources.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specifying_signatures_to_download.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\specifying_when_to_download.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\spm_mode.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\start_scanning.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\starting_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\starting_the_realtime_monitor_manually.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\status_for_scan_result.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\stop_scanning.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\stop_scanning_archive.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\stopping_a_scan.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\stopping_a_scheduled_scan_in_progress.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\subject.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\submitting_a_file_for_analysis.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\subnet_discovery_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\subnet_discovery_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\subnet_summary_information_displayed.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\subnet_tab.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\subnet_tab_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\supported_compressed_file_types.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\sweep_election.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\system_information.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\test_subnet_ip_address.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\thr_threshold.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\time_out_after_minutes.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\timeout_after_for_subnet_discovery.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\treating_a_trojan_or_worm_infection.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\troubleshooting.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\up.gif
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\updating_your_rescue_disk.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\user_name.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\user_name_for_admin_server.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\users_in_the_administrator_view_list.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\users_in_the_administrator_view_list_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_access_permissions.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_access_permissions_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_alert_policy.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_alert_policy_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_alert_settings.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_alert_settings_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_computer_associates_antivirus_software.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_configuration_settings.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_configuration_settings_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_download_now.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_enforced_policies.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_enforced_policies_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_inouptng_to_populate_the_view.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_proxy_configuration_machines.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_proxy_settings.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_realtime_monitor_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_realtime_monitor_options_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_realtime_scanner_policy.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_realtime_scanner_policy_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_rescue_disk_for_vet_engine.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_samba.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_scheduled_jobs_policy.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_scheduled_jobs_policy_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_scheduled_jobs_policy_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_send_for_analysis_policy.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_send_for_analysis_policy_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_signature_distribution_policy.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_signature_distribution_policy_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_admin_server.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_admin_server_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_administration_menu.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_administrator_view_menu_bar.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_administrator_view_toolbar.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_administrator_view_window.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_administrator_view_window_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_command_line_scanner_inocmd32.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_command_line_scanner_inocmd32_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_connect_to_admin_server_option.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_cure_action_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_local_scanner_menu_bar.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_local_scanner_status_bar.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_local_scanner_toolbar.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_local_scanner_window.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_local_scanner_window_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_log_viewer_menu_bar.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_log_viewer_toolbar.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_log_viewer_window.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_log_viewer_window_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_move_folder.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_my_folders_category.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_realtime_mail_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_remote_scan_view_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_rescue_disk_feature.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_rescue_disk_feature_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_schedule_scan_job_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_schedule_scan_job_options_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_service_manager.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_shell_extension.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_shell_extension_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_subnet_options.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_subnet_options_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_subnets_category.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_subnets_category_help.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_the_web_to_get_updates.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_trix_to_import_to_the_repository.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\using_windows_file_sharing_on_os_x_for_signature_updates.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\verifying_your_rescue_disk.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_details_about_an_infected_file.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_directory_locations.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_logs_on_remote_machines.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_policy_instances_by_branch.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_scheduled_jobs_policy_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_scheduled_scan_jobs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_scheduled_scan_properties.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_signature_download_progress.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_signature_update_logs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_the_location_of_moved_files.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_the_location_of_your_engines.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_the_log_directory_location.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_the_realtime_scanner_log.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_user_rights.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_your_home_directory_location.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\viewing_your_reports.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\windows_2000_and_remote_installs.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\windows_9x_considerations.html
    C:\Program Files\CA\eTrust Antivirus\Lang\English\Help\inocit\windows_9x_considerations_help.html
    C:\Program Files\CA\eTrust Antivirus\LogView.dll
    C:\Program Files\CA\eTrust Antivirus\MDA.dll
    C:\Program Files\CA\eTrust Antivirus\Move\372fd41b-b488-46a3-9f86-97e8bea7acc4.AVB
    C:\Program Files\CA\eTrust Antivirus\Move\4d8e9739-19ee-4737-a679-5cb68992f8e4.AVB
    C:\Program Files\CA\eTrust Antivirus\Move\a6c7cda2-2261-4fe7-ad57-875d826947c1.AVB
    C:\Program Files\CA\eTrust Antivirus\Move\a730454a-cb38-4832-bebe-08ddb554223d.AVB
    C:\Program Files\CA\eTrust Antivirus\Move\cfa8ab51-be8d-4f9c-b32a-11816ed1b9cc.AVB
    C:\Program Files\CA\eTrust Antivirus\Move\eef7c822-dc5b-46fd-9de4-842e2089d4a2.AVB
    C:\Program Files\CA\eTrust Antivirus\MovedDir.ico
    C:\Program Files\CA\eTrust Antivirus\NameAPIX.dll
    C:\Program Files\CA\eTrust Antivirus\OemComNA.dll
    C:\Program Files\CA\eTrust Antivirus\polAdn.dll
    C:\Program Files\CA\eTrust Antivirus\poldecod.dll
    C:\Program Files\CA\eTrust Antivirus\PrintAPI.dll
    C:\Program Files\CA\eTrust Antivirus\Realmon.exe
    C:\Program Files\CA\eTrust Antivirus\RPCMtAdn.dll
    C:\Program Files\CA\eTrust Antivirus\RPCMtAPI.dll
    C:\Program Files\CA\eTrust Antivirus\RPCMtDB\events.dbf
    C:\Program Files\CA\eTrust Antivirus\RPCMtDB\events.ntx
    C:\Program Files\CA\eTrust Antivirus\RPCMtDB\jobserv.dbf
    C:\Program Files\CA\eTrust Antivirus\RPCMtDB\jobserv.ntx
    C:\Program Files\CA\eTrust Antivirus\RPCMtDB\recs.ntx
    C:\Program Files\CA\eTrust Antivirus\RScanView.dll
    C:\Program Files\CA\eTrust Antivirus\ScanLog.dll
    C:\Program Files\CA\eTrust Antivirus\ScanView.dll
    C:\Program Files\CA\eTrust Antivirus\ScheduleJob.ico
    C:\Program Files\CA\eTrust Antivirus\secAddIn.dll
    C:\Program Files\CA\eTrust Antivirus\secAPI.dll
    C:\Program Files\CA\eTrust Antivirus\Shellscn.exe
    C:\Program Files\CA\eTrust Antivirus\START.JOB
    C:\Program Files\CA\eTrust Antivirus\summary.dll
    C:\Program Files\CA\eTrust Antivirus\TRIX0.tng
    C:\Program Files\CA\eTrust Antivirus\wBkRsrc.dll
    C:\Program Files\CA\SharedComponents\ScanEngine\arclib.dll
    C:\Program Files\CA\SharedComponents\ScanEngine\avh32dll.dll
    C:\Program Files\CA\SharedComponents\ScanEngine\backup\InoculateIT\InoculateIT.txt1170107762.bak
    C:\Program Files\CA\SharedComponents\ScanEngine\backup\InoculateIT\Pltfrm2.ini1170107762.bak
    C:\Program Files\CA\SharedComponents\ScanEngine\backup\InoculateIT\VIRSIG.DA01170107762.bak
    C:\Program Files\CA\SharedComponents\ScanEngine\backup\VET\Pltfrm2.ini1216780130.bak
    C:\Program Files\CA\SharedComponents\ScanEngine\backup\VET\vet.da11216780130.bak
    C:\Program Files\CA\SharedComponents\ScanEngine\backup\VET\Vet.txt1216780130.bak
    C:\Program Files\CA\SharedComponents\ScanEngine\Boot.dat
    C:\Program Files\CA\SharedComponents\ScanEngine\DistCfg.dll
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\Backup\fi_nt86.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\Backup\fv_nt86.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\Backup\ii_nt86.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\Backup\iv_nt86.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\fi_nt86.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\fv_nt86.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\ii_nt86.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\iv_nt86.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Incoming\Siglist2.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\inocboot.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Inocmd32.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\InoculateIT.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Inodist.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\Inodist.ini
    C:\Program Files\CA\SharedComponents\ScanEngine\InoScan.dll
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080716173051.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080716221019.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080716221608.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080717001437.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080717002028.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080717180008.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080717193254.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080717195409.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080717211108.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080719012347.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080719012929.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080719013449.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080719014509.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080721195806.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080721203600.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080722041349.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080722074759.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723020130.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723021441.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723022302.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723022822.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723074329.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723075137.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723080251.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723081006.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Logs\20080723081540.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\Pltfrm2.ini
    C:\Program Files\CA\SharedComponents\ScanEngine\Rescue.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\ScanRes.dll
    C:\Program Files\CA\SharedComponents\ScanEngine\SigCheck.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\UnCfgEng.exe
    C:\Program Files\CA\SharedComponents\ScanEngine\vet.da1
    C:\Program Files\CA\SharedComponents\ScanEngine\vet.dat
    C:\Program Files\CA\SharedComponents\ScanEngine\Vet.txt
    C:\Program Files\CA\SharedComponents\ScanEngine\VetE.dll
    C:\Program Files\CA\SharedComponents\ScanEngine\Virboot.dat
    C:\Program Files\CA\SharedComponents\ScanEngine\VIRSIG.DA0
    C:\Program Files\CA\SharedComponents\ScanEngine\VIRSIG.DAT
    C:\WINDOWS\system32\aqtvbywb.dll.ren
    C:\WINDOWS\system32\bwybvtqa.ini.ren
    C:\WINDOWS\system32\cbXOGArQ.dll.ren
    C:\WINDOWS\system32\ddcDvttS.dll.ren
    C:\WINDOWS\system32\fyctovdo.ini.ren
    C:\WINDOWS\system32\jPonnnpo.ini.ren
    C:\WINDOWS\system32\jPonnnpo.ini2.ren
    C:\WINDOWS\system32\KjRBJRqr.ini.ren
    C:\WINDOWS\system32\KjRBJRqr.ini2.ren
    C:\WINDOWS\system32\kkkjlnnn.ini.ren
    C:\WINDOWS\system32\kkkjlnnn.ini2.ren
    C:\WINDOWS\system32\obkfpisy.ini.ren
    C:\WINDOWS\system32\odvotcyf.dll.ren
    C:\WINDOWS\system32\omkefayu.dll.ren
    C:\WINDOWS\system32\opnnnoPj.dll.ren
    C:\WINDOWS\system32\QrAGOXbc.ini.ren
    C:\WINDOWS\system32\QrAGOXbc.ini2.ren
    C:\WINDOWS\system32\rqRJBRjK.dll.ren
    C:\WINDOWS\system32\SttvDcdd.ini.ren
    C:\WINDOWS\system32\SttvDcdd.ini2.ren

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_INORPC
    -------\Legacy_INORT
    -------\Legacy_INOTASK
    -------\Service_InoRPC
    -------\Service_InoRT
    -------\Service_InoTask


    ((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))
    .

    2008-07-23 03:47 . 2008-07-23 03:47 <DIR> d-------- C:\Program Files\Common Files\Java
    2008-07-23 03:47 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
    2008-07-23 03:46 . 2008-07-23 03:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
    2008-07-17 01:29 . 2008-07-17 01:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
    2008-07-17 00:26 . 2008-07-17 00:26 <DIR> d-------- C:\Screen Recordings
    2008-07-16 18:24 . 2008-07-16 18:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-07-16 18:24 . 2008-07-16 18:24 <DIR> d-------- C:\Documents and Settings\Michael Gilbertson\Application Data\Malwarebytes
    2008-07-16 18:24 . 2008-07-16 18:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-07-16 18:24 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
    2008-07-16 18:24 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-07-16 17:08 . 2008-07-16 17:08 <DIR> d-------- C:\Program Files\ZD Soft
    2008-07-16 16:51 . 2008-07-16 16:52 <DIR> d-------- C:\Program Files\BSR Screen Recorder 4
    2008-07-16 16:51 . 2008-07-16 16:51 585,728 --a------ C:\WINDOWS\system32\bsratswf.dll
    2008-07-16 16:51 . 2008-07-16 16:51 147,456 --a------ C:\WINDOWS\system32\bsratwmv.dll
    2008-07-16 16:51 . 2008-07-16 17:07 2,048 --a------ C:\WINDOWS\system32\Tr_sttool.dat
    2008-07-15 18:46 . 2008-07-15 18:46 <DIR> d-------- C:\Program Files\Bethesda Softwork
    2008-07-14 16:56 . 2008-07-16 21:29 <DIR> d-------- C:\Program Files\SpyZooka
    2008-07-14 16:56 . 2008-07-14 17:35 <DIR> d-------- C:\Program Files\PowerStrip
    2008-07-14 16:55 . 2008-07-17 13:59 <DIR> d-------- C:\Program Files\Steam
    2008-07-14 12:28 . 2008-07-21 18:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-07-14 12:28 . 2008-07-14 12:28 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-07-14 08:08 . 2008-07-14 16:56 <DIR> d-------- C:\Program Files\PowerStrip(2)
    2008-07-14 00:24 . 2008-07-14 16:56 <DIR> d-------- C:\Program Files\Trojan Remover(2)
    2008-07-13 23:46 . 2008-07-13 23:46 <DIR> d-------- C:\Program Files\INAC
    2008-07-13 19:42 . 2008-07-13 19:42 <DIR> d-------- C:\Program Files\Common Files\Download Manager
    2008-07-13 17:00 . 2008-07-13 17:00 <DIR> d-------- C:\Program Files\Trend Micro
    2008-07-13 01:39 . 2008-07-13 01:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
    2008-07-13 01:38 . 2008-07-13 01:38 0 --a------ C:\WINDOWS\ativpsrm.bin
    2008-07-11 13:04 . 2008-07-13 16:47 <DIR> d-------- C:\Program Files\WHITE
    2008-07-11 12:21 . 2008-07-13 16:47 <DIR> d-------- C:\Program Files\NCH Swift Sound
    2008-07-11 12:21 . 2008-07-13 16:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
    2008-07-10 01:40 . 2008-07-10 01:40 <DIR> d-------- C:\Program Files\cheapestsoft
    2008-07-10 01:22 . 2008-07-10 01:22 <DIR> d-------- C:\temp
    2008-07-10 01:22 . 2008-07-10 01:41 <DIR> d-------- C:\Program Files\PMPro Flash To iPod-PSP-3gp-Mp4 Converter
    2008-07-10 01:22 . 2008-07-10 01:22 <DIR> d-------- C:\MediaOut
    2008-07-09 21:22 . 2008-07-09 21:22 <DIR> d-------- C:\Program Files\Red Kawa
    2008-07-08 17:17 . 2008-07-08 17:17 <DIR> d-------- C:\Program Files\Mediafour
    2008-07-06 21:03 . 2008-07-06 21:21 <DIR> d-------- C:\illusion
    2008-07-06 20:39 . 2008-07-06 20:35 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
    2008-07-06 02:50 . 2008-07-06 02:50 <DIR> d-------- C:\Program Files\Paradox Interactive
    2008-07-05 16:21 . 2008-07-05 16:21 <DIR> d-------- C:\Program Files\OpenAL
    2008-07-05 03:54 . 2008-07-05 03:54 <DIR> d-------- C:\Program Files\Vuze
    2008-07-03 01:56 . 2008-07-03 02:01 <DIR> d-------- C:\Documents and Settings\Michael Gilbertson\Application Data\Hamachi
    2008-07-03 01:55 . 2008-07-03 01:56 <DIR> d-------- C:\Program Files\Hamachi
    2008-07-03 01:55 . 2008-07-03 01:55 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
    2008-06-29 12:38 . 2008-07-06 01:10 <DIR> d-------- C:\Program Files\Frets on Firez
    2008-06-29 12:38 . 2008-06-29 12:39 <DIR> d-------- C:\Documents and Settings\Michael Gilbertson\Application Data\fretsonfire
    2008-06-26 16:10 . 2008-06-26 16:10 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
    2008-06-26 16:09 . 2008-06-29 12:28 <DIR> d-------- C:\Program Files\Frets on Fire
    2008-06-23 23:54 . 2008-06-23 23:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
    2008-06-23 23:54 . 2004-08-09 05:04 73,728 --a------ C:\WINDOWS\system32\ISUSPM.cpl
    2008-06-23 20:17 . 2008-06-26 19:04 96 --ah----- C:\WINDOWS\system32\HsInfo.dat
    2008-06-23 18:22 . 2008-06-23 18:22 <DIR> d-------- C:\Program Files\Gravity
    2008-06-23 04:58 . 2008-06-23 05:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Outspark
    2008-06-23 04:51 . 2008-06-23 04:58 <DIR> d-------- C:\Program Files\Outspark

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-07-23 08:23 --------- d-----w C:\Documents and Settings\Michael Gilbertson\Application Data\DNA
    2008-07-23 07:47 --------- d-----w C:\Program Files\Java
    2008-07-23 06:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
    2008-07-22 07:44 --------- d-----w C:\Program Files\AIM6
    2008-07-22 07:43 --------- d-----w C:\Program Files\Viewpoint
    2008-07-22 07:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
    2008-07-22 07:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
    2008-07-21 21:42 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\Xfire
    2008-07-21 01:13 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2008-07-20 16:54 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\Azureus
    2008-07-17 19:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-07-17 19:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-07-17 01:20 --------- d-----w C:\Program Files\InternetProgram
    2008-07-16 21:51 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
    2008-07-16 17:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-07-16 17:42 --------- d-----w C:\Program Files\Voyage Century Online
    2008-07-16 17:37 --------- d-----w C:\Program Files\1503 AD
    2008-07-14 21:40 --------- d-s---w C:\Program Files\Xfire
    2008-07-14 12:32 --------- d-----w C:\Program Files\CyberLink
    2008-07-13 20:46 --------- d-----w C:\Program Files\VR Mixer ActiveX
    2008-07-13 05:34 --------- d-----w C:\Program Files\ATI Technologies
    2008-07-11 17:14 2,079 ----a-w C:\WINDOWS\wininit.tmp
    2008-07-11 06:11 --------- d-----w C:\Program Files\Bethesda Softworks
    2008-07-10 05:15 --------- d-----w C:\Program Files\AliveMedia
    2008-07-03 20:22 --------- d-----w C:\Program Files\Azureus
    2008-07-03 20:03 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\Ventrilo
    2008-06-30 00:40 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\teamspeak2
    2008-06-29 11:55 --------- d-----w C:\Program Files\LimeWire
    2008-06-24 09:54 --------- d-----w C:\Program Files\CAPCOM
    2008-06-23 22:22 --------- d-----w C:\Program Files\Common Files\InstallShield
    2008-06-21 09:16 --------- d-----w C:\Documents and Settings\Michael Gilbertson\Application Data\acccore
    2008-06-21 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\acccore
    2008-06-21 09:14 --------- d-----w C:\Program Files\Common Files\AOL
    2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    2008-06-19 00:41 --------- d-----w C:\Program Files\Gpotato
    2008-06-17 23:57 --------- d-----w C:\Program Files\Electronic Arts
    2008-06-17 23:57 --------- d-----w C:\Documents and Settings\Michael Gilbertson\Application Data\SPORE Creature Creator
    2008-06-17 22:00 --------- d-----w C:\Program Files\Lionhead Studios
    2008-06-17 21:17 --------- d-----w C:\Documents and Settings\Michael Gilbertson\Application Data\Nexon
    2008-06-14 12:48 --------- d-----w C:\Program Files\RogueRemover FREE
    2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-11 08:49 --------- d-----w C:\Program Files\Maxis
    2008-06-10 23:19 --------- d-----w C:\Program Files\EA GAMES
    2008-06-06 07:52 --------- d-----w C:\Program Files\Microsoft Games
    2008-06-06 07:51 --------- d-----w C:\Program Files\MythWar
    2008-06-06 07:44 --------- d-----w C:\Program Files\Deer Hunter 5
    2008-06-03 17:12 --------- d-----w C:\Program Files\CCleaner
    2008-05-28 08:22 --------- d-----w C:\Program Files\Activision
    2008-05-28 08:19 --------- d-----w C:\Program Files\Atari
    2008-05-28 08:18 --------- d---a-w C:\Documents and Settings\Michael Gilbertson\Application Data\Atari
    2008-05-28 08:16 --------- d-----w C:\Program Files\Firefly Studios
    2008-05-28 08:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Firefly Studios
    2008-05-26 08:50 --------- d-----w C:\Program Files\Microsoft Silverlight
    2008-05-16 01:19 22,328 ----a-w C:\Documents and Settings\Michael Gilbertson\Application Data\PnkBstrK.sys
    2006-01-20 19:06 4,489,216 ----a-w C:\Documents and Settings\All Users\Application Data\EAW Deathstar.scr
    2006-01-20 18:20 1,028,096 ----a-w C:\Documents and Settings\All Users\Application Data\EAW Vehicles.scr
    .

    ((((((((((((((((((((((((((((( snapshot@2008-07-22_22.21.16.07 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2006-11-09 18:28:20 49,248 ----a-w C:\WINDOWS\system32\java.exe
    + 2008-06-10 05:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
    - 2006-11-09 18:28:30 53,346 ----a-w C:\WINDOWS\system32\javaw.exe
    + 2008-06-10 05:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
    - 2006-11-09 20:07:32 127,078 ----a-w C:\WINDOWS\system32\javaws.exe
    + 2008-06-10 06:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{0A94B116-4504-4e26-AB05-E61E474AA38B}"= "C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL" [2007-09-14 08:47 61440]

    [HKEY_CLASSES_ROOT\clsid\{0a94b116-4504-4e26-ab05-e61e474aa38b}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{E3EA4FD9-CADE-4ae5-84F7-086EEE888BE4}"= "C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL" [2008-03-15 05:11 266240]

    [HKEY_CLASSES_ROOT\clsid\{e3ea4fd9-cade-4ae5-84f7-086eee888be4}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{E3EA4FD9-CADE-4AE5-84F7-086EEE888BE4}"= "C:\Program Files\PandoBar\bar\1.bin\PANDOBAR.DLL" [2008-03-15 05:11 266240]

    [HKEY_CLASSES_ROOT\clsid\{e3ea4fd9-cade-4ae5-84f7-086eee888be4}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 06:48 157592]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
    "BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-12 02:23 289088]
    "Power2GoExpress"="C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" [2005-01-07 18:51 1380445]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-03-18 05:34 1228800]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
    "XboxStat"="c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 18:05 734264]
    "PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-02-16 19:09 802552]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 22:32 208952]
    "IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2008-07-06 20:30 44032]
    "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 22:31 59392]
    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 22:32 455168]
    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 22:32 455168]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.iv31"= C:\WINDOWS\system32\ir32_32.dll
    "vidc.iv32"= C:\WINDOWS\system32\ir32_32.dll
    "msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
    "VIDC.XFR1"= xfcodec.dll
    "VIDC.ZDSV"= scrvid.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
    backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Michael Gilbertson^Start Menu^Programs^Startup^OpenOffice.org 2.1.lnk]
    path=C:\Documents and Settings\Michael Gilbertson\Start Menu\Programs\Startup\OpenOffice.org 2.1.lnk
    backup=C:\WINDOWS\pss\OpenOffice.org 2.1.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
    C:\WINDOWS\system32\dumprep 0 -u [X]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
    --a------ 2004-12-16 18:49 49152 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a------ 2004-08-04 00:56 15360 C:\WINDOWS\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    --a------ 2007-08-16 14:35 1838592 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a--c--- 2007-06-01 16:51 257088 C:\Program Files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
    --------- 2005-01-07 18:51 1380445 C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    --a--c--- 2003-10-31 20:42 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-07-24 23:36 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
    --a------ 2007-03-14 17:03 24104 C:\Program Files\Zune\ZuneLauncher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    -ra------ 2005-10-04 18:12 90112 C:\WINDOWS\SOUNDMAN.EXE

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\StubInstaller.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=
    "C:\\Program Files\\BYOND\\bin\\byond.exe"=
    "C:\\Program Files\\Xfire\\xfire.exe"=
    "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\michael_e_g\\half-life 2 deathmatch\\hl2.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=
    "C:\\Program Files\\DNA\\btdna.exe"=
    "C:\\Program Files\\1964\\099\\1964.exe"=
    "C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe"=
    "C:\\WINDOWS\\system32\\PnkBstrA.exe"=
    "C:\\WINDOWS\\system32\\PnkBstrB.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\EA GAMES\\American McGee's Alice\\alice.exe"=
    "C:\\GAMES\\NeoSteam\\NSStarter.exe"=
    "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
    "C:\\GAMES\\Paintball2\\paintball2.exe"=
    "C:\\Program Files\\AIM6\\aim6.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "17533:TCP"= 17533:TCP:BitComet 17533 TCP
    "17533:UDP"= 17533:UDP:BitComet 17533 UDP
    "56820:TCP"= 56820:TCP:Pando P2P TCP Listening Port
    "56820:UDP"= 56820:UDP:Pando P2P UDP Listening Port
    "42823:TCP"= 42823:TCP:SolidNetworkManager
    "42823:UDP"= 42823:UDP:SolidNetworkManager
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
    "13500:TCP"= 13500:TCP:Azureus Vuze
    "13500:UDP"= 13500:UDP:Azureus Vuze

    R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:56]
    R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys [2007-07-14 22:37]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
    R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2005-03-22 20:17]
    R3 scrcap;scrcap;C:\WINDOWS\system32\DRIVERS\scrcap.sys [2006-12-27 10:47]
    .
    Contents of the 'Scheduled Tasks' folder
    "2008-07-07 12:19:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-07-23 04:00:37 C:\WINDOWS\Tasks\User_Feed_Synchronization-{E4FB928C-E500-41EB-9001-155F8E007BBA}.job"
    - C:\WINDOWS\system32\msfeedssync.exe
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-Aim6 - (no file)
    HKLM-Run-Realtime Monitor - C:\PROGRA~1\CA\ETRUST~1\realmon.exe
    MSConfigStartUp-SunJavaUpdateSched - C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe


    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-23 04:25:25
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\system32\ati2evxx.exe
    C:\WINDOWS\system32\ati2evxx.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\Program Files\Zune\ZuneNss.exe
    C:\WINDOWS\system32\wscntfy.exe
    .
    **************************************************************************
    .
    Completion time: 2008-07-23 4:30:28 - machine was rebooted [Michael Gilbertson]
    ComboFix-quarantined-files.txt 2008-07-23 08:30:25
    ComboFix2.txt 2008-07-23 02:21:40

    Pre-Run: 42,109,353,984 bytes free
    Post-Run: 42,183,950,336 bytes free

    1284 --- E O F --- 2008-07-10 01:05:00

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •