Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!
   
BullGuard Antivirus Forum > General Security > Spyware > System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!  
Forum Quick Jump
 
New Topic Post reply to : System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!! Printable version of : System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!
[ << Previous Thread | Next Thread >> ]

razgee
New Member


Date Joined Jun 2008
Total Posts : 3
 
   Posted 7-10-2008 8:32 (GMT +1)    Quote: System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!Alert an admin about: System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:30:53, on 10/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: (no name) - {1C56E97B-A95F-47B2-93C0-3FEED24479A7} - (no file)
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by137fd.bay137.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: enation - {629340b5-8df6-4211-9245-a86563a35792} - C:\WINDOWS\system32\gnmguxh.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

--
End of file - 10089 bytes

Image Attachment :
Image Preview
system alert.bmp
  150KB (image/x-bmp)
This image has been viewed 25 time(s).

Image Attachment :
Image Preview
system tray icon2.bmp
  13KB (image/x-bmp)
This image has been viewed 21 time(s).

Image Attachment :
system tray icon.bmp
system tray icon.bmp   3KB (image/x-bmp)
Back to Top
 

razgee
New Member


Date Joined Jun 2008
Total Posts : 3
 
   Posted 7-11-2008 11:42 (GMT +1)    Quote: System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!Alert an admin about: System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!
more info:
virus attack happened when i attempted to downlaod video codec to watch UFC video on Wed 9th July 2008 at between 8-9 o'clock. I think file was called 'update.exe' or something similar, it downloaded desktop shortcuts which i have deleted and the file itself. new icon is 1st thing to load up on system tray and system alert message pop-up balloon appears intermittently? hope you can help!

new scan results:

                        $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ 
                        º                                    º 
                                    hjtscanlist v2.0              
                        º                                    º 
                        $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$ 

Microsoft Windows XP [Version 5.1.2600]
 
 
C:

        C:\hiberfil.sys ---------  
        C:\pagefile.sys ---------  
  2008-07-10 22:53      C:\rapport.txt --------- 253582 
  2008-07-10 22:50      C:\WINDOWS --------- 0 
  2008-07-10 21:40      C:\ComboFix --------- 0 
  2008-07-10 20:52      C:\QooBox --------- 0 
  2008-07-10 18:57      C:\Program Files --------- 0 
  2008-07-09 23:18      C:\Config.Msi --------- 0 
  2008-07-03 15:35      C:\System Volume Information --------- 0 
  2008-06-15 04:27      C:\cd6acb79d7ff1f65151395534fba --------- 0 
  2008-06-13 00:10      C:\sqmdata01.sqm --------- 232 
  2008-06-13 00:10      C:\sqmnoopt01.sqm --------- 244 
  2008-06-12 22:01      C:\sqmdata00.sqm --------- 232 
  2008-06-12 22:01      C:\sqmnoopt00.sqm --------- 244 
  2007-12-20 19:40      C:\boot.ini --------- 211 
  2007-11-20 18:50      C:\CLDMA.LOG --------- 11649 
  2007-09-20 20:14      C:\bin --------- 0 
  2007-09-18 18:28      C:\Netgear --------- 0 
  2007-01-30 16:11      C:\spoolerlogs --------- 0 
  2007-01-25 00:58      C:\Netgear.ico --------- 4286 
  2006-11-29 19:55      C:\My Downloads --------- 0 
  2006-10-29 20:19      C:\MSOCache --------- 0 
  2006-10-25 00:35      C:\RECYCLER --------- 0 
  2006-10-24 18:16      C:\Documents and Settings --------- 0 
  2006-06-06 16:18      C:\My Advent Information --------- 0 
  2005-12-06 11:54      C:\MINI --------- 21 
  2005-12-06 11:54      C:\LOCAL --------- 21 
  2005-12-05 13:56      C:\CONFIG.SYS --------- 0 
  2005-12-05 13:56      C:\IO.SYS --------- 0 
  2005-12-05 13:56      C:\AUTOEXEC.BAT --------- 0 
  2005-12-05 13:56      C:\MSDOS.SYS --------- 0 
  2005-01-08 18:21      C:\Applications --------- 0 
  2004-08-04 13:00      C:\ntldr --------- 250032 
  2004-08-04 13:00      C:\NTDETECT.COM --------- 47564 
----------------------------------------

 
C:\WINDOWS

  2008-07-11 11:15     C:\WINDOWS\wiadebug.log --------- 159 
  2008-07-11 11:15     C:\WINDOWS\WindowsUpdate.log --------- 1601890 
  2008-07-11 11:15     C:\WINDOWS\wiaservc.log --------- 50 
  2008-07-11 11:14     C:\WINDOWS\0.log --------- 0 
  2008-07-11 11:14     C:\WINDOWS\bootstat.dat --------- 2048 
  2008-07-10 23:13     C:\WINDOWS\SchedLgU.Txt --------- 32544 
  2008-07-10 22:55     C:\WINDOWS\ntbtlog.txt --------- 301018 
  2008-07-10 22:50     C:\WINDOWS\setuperr.log --------- 0 
  2008-07-10 22:50     C:\WINDOWS\setupact.log --------- 60 
  2008-07-10 20:50     C:\WINDOWS\setupapi.log --------- 1290 
  2008-06-14 12:26     C:\WINDOWS\win.ini --------- 709 
  2008-06-13 18:22     C:\WINDOWS\QTFont.qfn --------- 54156 
  2008-05-17 12:58     C:\WINDOWS\QTFont.for --------- 1409 
  2007-12-20 19:40     C:\WINDOWS\system.ini --------- 227 
  2007-12-16 12:32     C:\WINDOWS\mngui.INI --------- 0 
  2007-12-16 12:32     C:\WINDOWS\ModemLog_Sony Ericsson Device 115 USB WMC Modem.txt --------- 10968 
  2007-09-20 20:21     C:\WINDOWS\hpoins11.dat --------- 117094 
  2007-09-14 20:31     C:\WINDOWS\ModemLog_AC97 SoftV92 Data Fax Modem with SmartCP.txt --------- 31498 
  2007-08-08 20:05     C:\WINDOWS\cdplayer.ini --------- 50 
  2007-06-13 11:23     C:\WINDOWS\explorer.exe --------- 1033216 
  2007-04-17 00:16     C:\WINDOWS\WMSysPr9.prx --------- 316640 
  2007-04-01 13:58     C:\WINDOWS\LEXSTAT.INI --------- 277 
  2007-02-27 13:39     C:\WINDOWS\Setup1.exe --------- 286720 
  2007-02-27 13:39     C:\WINDOWS\ST6UNST.EXE --------- 73216 
  2007-01-22 17:54     C:\WINDOWS\nsreg.dat --------- 0 
  2007-01-22 17:54     C:\WINDOWS\mozver.dat --------- 2301 
  2006-10-29 20:24     C:\WINDOWS\ODBC.INI --------- 376 
  2006-05-06 01:19     C:\WINDOWS\hpomdl11.dat --------- 11634 
  2006-02-16 22:33     C:\WINDOWS\Twunk_32.dll --------- 1216 
  2006-02-16 22:33     C:\WINDOWS\Twunk_16.dll --------- 1216 
  2005-12-08 11:43     C:\WINDOWS\New.flg --------- 8 
  2005-12-06 12:16     C:\WINDOWS\smscfg.ini --------- 61 
  2005-12-05 16:30     C:\WINDOWS\Rev.dsg --------- 1622 
  2005-12-05 16:22     C:\WINDOWS\REGLOCS.OLD --------- 8192 
  2005-12-05 13:56     C:\WINDOWS\control.ini --------- 0 
  2005-12-05 13:55     C:\WINDOWS\ODBCINST.INI --------- 4161 
  2005-12-05 13:54     C:\WINDOWS\WindowsShell.Manifest --------- 749 
  2005-12-05 13:53     C:\WINDOWS\vbaddin.ini --------- 37 
  2005-12-05 13:53     C:\WINDOWS\vb.ini --------- 36 
  2005-12-05 05:51     C:\WINDOWS\Sti_Trace.log --------- 0 
  2005-11-18 00:12     C:\WINDOWS\opuc.dll --------- 533504 
  2005-06-29 04:35     C:\WINDOWS\ciaunwdm.exe --------- 28672 
  2005-05-27 00:22     C:\WINDOWS\hh.exe --------- 10752 
  2005-05-25 16:17     C:\WINDOWS\Wallpaper.bmp --------- 5760054 
  2005-04-26 17:44     C:\WINDOWS\INRES.DLL --------- 11776 
  2005-01-08 14:00     C:\WINDOWS\SIGVERIF.TXT --------- 694660 
  2004-08-04 13:00     C:\WINDOWS\Rhododendron.bmp --------- 17362 
  2004-08-04 13:00     C:\WINDOWS\regedit.exe --------- 146432 
  2004-08-04 13:00     C:\WINDOWS\NOTEPAD.EXE --------- 69120 
  2004-08-04 13:00     C:\WINDOWS\winhlp32.exe --------- 283648 
  2004-08-04 13:00     C:\WINDOWS\winhelp.exe --------- 256192 
  2004-08-04 13:00     C:\WINDOWS\River Sumida.bmp --------- 26680 
  2004-08-04 13:00     C:\WINDOWS\msdfmap.ini --------- 1405 
  2004-08-04 13:00     C:\WINDOWS\Soap Bubbles.bmp --------- 65978 
  2004-08-04 13:00     C:\WINDOWS\winnt.bmp --------- 48680 
  2004-08-04 13:00     C:\WINDOWS\Santa Fe Stucco.bmp --------- 65832 
  2004-08-04 13:00     C:\WINDOWS\winnt256.bmp --------- 48680 
  2004-08-04 13:00     C:\WINDOWS\Greenstone.bmp --------- 26582 
  2004-08-04 13:00     C:\WINDOWS\Gone Fishing.bmp --------- 17336 
  2004-08-04 13:00     C:\WINDOWS\FeatherTexture.bmp --------- 16730 
  2004-08-04 13:00     C:\WINDOWS\TASKMAN.EXE --------- 15360 
  2004-08-04 13:00     C:\WINDOWS\twain.dll --------- 94784 
  2004-08-04 13:00     C:\WINDOWS\twain_32.dll --------- 50688 
  2004-08-04 13:00     C:\WINDOWS\explorer.scf --------- 80 
  2004-08-04 13:00     C:\WINDOWS\twunk_16.exe --------- 49680 
  2004-08-04 13:00     C:\WINDOWS\desktop.ini --------- 2 
  2004-08-04 13:00     C:\WINDOWS\twunk_32.exe --------- 25600 
  2004-08-04 13:00     C:\WINDOWS\Zapotec.bmp --------- 9522 
  2004-08-04 13:00     C:\WINDOWS\Coffee Bean.bmp --------- 17062 
  2004-08-04 13:00     C:\WINDOWS\clock.avi --------- 82944 
  2004-08-04 13:00     C:\WINDOWS\Blue Lace 16.bmp --------- 1272 
  2004-08-04 13:00     C:\WINDOWS\vmmreg32.dll --------- 18944 
  2004-08-04 13:00     C:\WINDOWS\Prairie Wind.bmp --------- 65954 
  2004-08-04 13:00     C:\WINDOWS\_default.pif --------- 707 
  2002-02-27 09:57     C:\WINDOWS\wallpaper2.bmp --------- 2359352 
  2000-08-31 08:00     C:\WINDOWS\Nircmd.exe --------- 28672 
  2000-08-31 08:00     C:\WINDOWS\swxcacls.exe --------- 212480 
  2000-08-31 08:00     C:\WINDOWS\swsc.exe --------- 136704 
  2000-08-31 08:00     C:\WINDOWS\swreg.exe --------- 161792 
  2000-08-31 08:00     C:\WINDOWS\sed.exe --------- 98816 
  2000-08-31 08:00     C:\WINDOWS\VFind.exe --------- 49152 
  2000-08-31 08:00     C:\WINDOWS\fdsv.exe --------- 89504 
  2000-08-31 08:00     C:\WINDOWS\grep.exe --------- 80412 
  2000-08-31 08:00     C:\WINDOWS\zip.exe --------- 68096 
  1999-10-11 02:00     C:\WINDOWS\Ctregrun.exe --------- 41984 
  1998-10-29 16:45     C:\WINDOWS\IsUninst.exe --------- 306688 
  1997-04-08 21:08     C:\WINDOWS\uninst.exe --------- 299520 
----------------------------------------

 
C:\WINDOWS\System

 2004-08-04 13:00    C:\WINDOWS\System\AVICAP.DLL --------- 69584 
 2004-08-04 13:00    C:\WINDOWS\System\AVIFILE.DLL --------- 109456 
 2004-08-04 13:00    C:\WINDOWS\System\COMMDLG.DLL --------- 32816 
 2004-08-04 13:00    C:\WINDOWS\System\KEYBOARD.DRV --------- 2000 
 2004-08-04 13:00    C:\WINDOWS\System\LZEXPAND.DLL --------- 9936 
 2004-08-04 13:00    C:\WINDOWS\System\MCIAVI.DRV --------- 73376 
 2004-08-04 13:00    C:\WINDOWS\System\MCISEQ.DRV --------- 25264 
 2004-08-04 13:00    C:\WINDOWS\System\MCIWAVE.DRV --------- 28160 
 2004-08-04 13:00    C:\WINDOWS\System\MMSYSTEM.DLL --------- 68768 
 2004-08-04 13:00    C:\WINDOWS\System\MMTASK.TSK --------- 1152 
 2004-08-04 13:00    C:\WINDOWS\System\MOUSE.DRV --------- 2032 
 2004-08-04 13:00    C:\WINDOWS\System\MSVIDEO.DLL --------- 126912 
 2004-08-04 13:00    C:\WINDOWS\System\OLECLI.DLL --------- 82944 
 2004-08-04 13:00    C:\WINDOWS\System\OLESVR.DLL --------- 24064 
 2004-08-04 13:00    C:\WINDOWS\System\setup.inf --------- 59167 
 2004-08-04 13:00    C:\WINDOWS\System\SHELL.DLL --------- 5120 
 2004-08-04 13:00    C:\WINDOWS\System\SOUND.DRV --------- 1744 
 2004-08-04 13:00    C:\WINDOWS\System\stdole.tlb --------- 5532 
 2004-08-04 13:00    C:\WINDOWS\System\SYSTEM.DRV --------- 3360 
 2004-08-04 13:00    C:\WINDOWS\System\TAPI.DLL --------- 19200 
 2004-08-04 13:00    C:\WINDOWS\System\TIMER.DRV --------- 4048 
 2004-08-04 13:00    C:\WINDOWS\System\VER.DLL --------- 9008 
 2004-08-04 13:00    C:\WINDOWS\System\VGA.DRV --------- 2176 
 2004-08-04 13:00    C:\WINDOWS\System\WFWNET.DRV --------- 13600 
 2004-08-04 13:00    C:\WINDOWS\System\WINSPOOL.DRV --------- 146432 
----------------------------------------

 
C:\WINDOWS\System32

 2008-07-11 11:16     C:\WINDOWS\system32\wpa.dbl --------- 1170 
 2008-07-11 11:15     C:\WINDOWS\system32\CatRoot2 --------- 0 
 2008-07-10 22:47     C:\WINDOWS\system32\tmp.txt --------- 0 
 2008-07-10 22:47     C:\WINDOWS\system32\tmp.reg --------- 356 
 2008-07-10 20:52     C:\WINDOWS\system32\drivers --------- 0 
 2008-07-09 21:49     C:\WINDOWS\system32\LogFiles --------- 0 
 2008-07-08 22:23     C:\WINDOWS\system32\dllcache --------- 0 
 2008-07-08 22:23     C:\WINDOWS\system32\gnmguxh.dll --------- 13312 
 2008-07-06 13:53     C:\WINDOWS\system32\rmoc3260.dll --------- 185944 
 2008-07-06 13:53     C:\WINDOWS\system32\pndx5032.dll --------- 5632 
 2008-07-06 13:53     C:\WINDOWS\system32\pndx5016.dll --------- 6656 
 2008-07-06 13:53     C:\WINDOWS\system32\pncrt.dll --------- 278528 
 2008-07-06 13:14     C:\WINDOWS\system32\CatRoot --------- 0 
 2008-07-06 13:14     C:\WINDOWS\system32\lvcoinst.log --------- 21381 
 2008-07-03 15:35     C:\WINDOWS\system32\Restore --------- 0 
 2008-06-25 17:15     C:\WINDOWS\system32\MRT.exe --------- 17972344 
 2008-06-20 18:41     C:\WINDOWS\system32\mswsock.dll --------- 245248 
 2008-06-20 18:41     C:\WINDOWS\system32\dnsapi.dll --------- 148992 
 2008-06-14 15:58     C:\WINDOWS\system32\FNTCACHE.DAT --------- 170688 
 2008-06-13 14:45     C:\WINDOWS\system32\SymNeti.dll --------- 579464 
 2008-06-13 14:45     C:\WINDOWS\system32\SymRedir.dll --------- 207240 
 2008-06-07 15:36     C:\WINDOWS\system32\ezsidmv.dat --------- 56 
 2008-06-02 22:58     C:\WINDOWS\system32\S32EVNT1.DLL --------- 60800 
 2008-05-31 00:22     C:\WINDOWS\system32\dpuGUI10.dll --------- 53248 
 2008-05-31 00:22     C:\WINDOWS\system32\dpv11.dll --------- 57344 
 2008-05-31 00:22     C:\WINDOWS\system32\dpus11.dll --------- 344064 
 2008-05-31 00:22     C:\WINDOWS\system32\dpu11.dll --------- 294912 
 2008-05-31 00:22     C:\WINDOWS\system32\dpu10.dll --------- 294912 
 2008-05-31 00:22     C:\WINDOWS\system32\dpuGUI11.dll --------- 593920 
 2008-05-31 00:22     C:\WINDOWS\system32\divx_xx0c.dll --------- 823296 
 2008-05-31 00:22     C:\WINDOWS\system32\divx_xx07.dll --------- 823296 
 2008-05-31 00:22     C:\WINDOWS\system32\divx_xx11.dll --------- 802816 
 2008-05-31 00:22     C:\WINDOWS\system32\DivX.dll --------- 683520 
 2008-05-31 00:22     C:\WINDOWS\system32\divx_xx0a.dll --------- 815104 
 2008-05-31 00:22     C:\WINDOWS\system32\divxdec.ax --------- 630784 
 2008-05-27 19:02     C:\WINDOWS\system32\DRVSTORE --------- 0 
 2008-05-27 18:56     C:\WINDOWS\system32\REX Shared Library.dll --------- 233472 
 2008-05-27 18:56     C:\WINDOWS\system32\ReWire.dll --------- 368640 
 2008-05-27 10:50     C:\WINDOWS\system32\QuickTimeVR.qtx --------- 90112 
 2008-05-27 10:50     C:\WINDOWS\system32\QuickTime.qts --------- 57344 
 2008-05-22 23:22     C:\WINDOWS\system32\divxsm.tlb --------- 4816 
 2008-05-22 23:22     C:\WINDOWS\system32\DivXsm.exe --------- 524288 
 2008-05-22 23:22     C:\WINDOWS\system32\qt-dx331.dll --------- 3596288 
 2008-05-22 23:20     C:\WINDOWS\system32\libdivx.dll --------- 1044480 
 2008-05-22 23:20     C:\WINDOWS\system32\ssldivx.dll --------- 200704 
 2008-05-22 23:19     C:\WINDOWS\system32\dtu100.dll --------- 196608 
 2008-05-22 23:19     C:\WINDOWS\system32\dpl100.dll --------- 81920 
 2008-05-22 23:19     C:\WINDOWS\system32\dpl100.dll.manifest --------- 416 
 2008-05-22 23:19     C:\WINDOWS\system32\dtu100.dll.manifest --------- 416 
 2008-05-22 23:19     C:\WINDOWS\system32\DivXCodecVersionChecker.exe --------- 161096 
 2008-05-22 23:18     C:\WINDOWS\system32\DivXWMPExtType.dll --------- 12288 
 2008-05-16 11:58     C:\WINDOWS\system32\lsdelete.exe --------- 12632 
 2008-05-07 05:55     C:\WINDOWS\system32\quartz.dll --------- 1288192 
 2008-04-23 22:16     C:\WINDOWS\system32\mshtml.dll --------- 3591680 
 2008-04-23 05:16     C:\WINDOWS\system32\urlmon.dll --------- 1159680 
 2008-04-23 05:16     C:\WINDOWS\system32\wininet.dll --------- 826368 
 2008-04-23 05:16     C:\WINDOWS\system32\webcheck.dll --------- 233472 
 2008-04-23 05:16     C:\WINDOWS\system32\msrating.dll --------- 193024 
 2008-04-23 05:16     C:\WINDOWS\system32\url.dll --------- 105984 
 2008-04-23 05:16     C:\WINDOWS\system32\msfeedsbs.dll --------- 52224 
 2008-04-23 05:16     C:\WINDOWS\system32\dxtrans.dll --------- 214528 
 2008-04-23 05:16     C:\WINDOWS\system32\extmgr.dll --------- 133120 
 2008-04-23 05:16     C:\WINDOWS\system32\mshtmled.dll --------- 478208 
 2008-04-23 05:16     C:\WINDOWS\system32\occache.dll --------- 102912 
 2008-04-23 05:16     C:\WINDOWS\system32\mstime.dll --------- 671232 
 2008-04-23 05:16     C:\WINDOWS\system32\icardie.dll --------- 63488 
 2008-04-23 05:16     C:\WINDOWS\system32\pngfilt.dll --------- 44544 
 2008-04-23 05:16     C:\WINDOWS\system32\dxtmsft.dll --------- 347136 
 2008-04-23 05:16     C:\WINDOWS\system32\inetcpl.cpl --------- 1831424 
 2008-04-23 05:16     C:\WINDOWS\system32\msfeeds.dll --------- 459264 
 2008-04-23 05:16     C:\WINDOWS\system32\advpack.dll --------- 124928 
 2008-04-23 05:16     C:\WINDOWS\system32\ieakeng.dll --------- 153088 
 2008-04-23 05:16     C:\WINDOWS\system32\ieaksie.dll --------- 230400 
 2008-04-23 05:16     C:\WINDOWS\system32\jsproxy.dll --------- 27648 
 2008-04-23 05:16     C:\WINDOWS\system32\ieapfltr.dll --------- 383488 
 2008-04-23 05:16     C:\WINDOWS\system32\iedkcs32.dll --------- 384512 
 2008-04-23 05:16     C:\WINDOWS\system32\ieframe.dll --------- 6066176 
 2008-04-23 05:16     C:\WINDOWS\system32\iernonce.dll --------- 44544 
 2008-04-23 05:16     C:\WINDOWS\system32\iertutil.dll --------- 267776 
 2008-04-22 08:39     C:\WINDOWS\system32\ieudinit.exe --------- 13824 
 2008-04-22 08:39     C:\WINDOWS\system32\ie4uinit.exe --------- 70656 
 2008-04-20 06:07     C:\WINDOWS\system32\ieakui.dll --------- 161792 
 2008-04-11 20:05     C:\WINDOWS\system32\perfh009.dat --------- 409566 
 2008-04-11 20:05     C:\WINDOWS\system32\perfc009.dat --------- 64706 
 2008-04-11 20:05     C:\WINDOWS\system32\PerfStringBackup.INI --------- 461288 
 2008-04-06 19:46     C:\WINDOWS\system32\wbem --------- 0 
 2008-04-01 22:22     C:\WINDOWS\system32\jupdate-1.6.0_05-b13.log --------- 6300 
 2008-03-27 09:12     C:\WINDOWS\system32\msjint40.dll --------- 151583 
 2008-03-25 05:50     C:\WINDOWS\system32\msxbde40.dll --------- 355104 
 2008-03-25 05:50     C:\WINDOWS\system32\mswstr10.dll --------- 621344 
 2008-03-25 05:50     C:\WINDOWS\system32\mswdat10.dll --------- 838432 
 2008-03-25 05:50     C:\WINDOWS\system32\mstext40.dll --------- 264992 
 2008-03-25 05:50     C:\WINDOWS\system32\msrepl40.dll --------- 559904 
 2008-03-25 05:50     C:\WINDOWS\system32\msrd3x40.dll --------- 322336 
 2008-03-25 05:50     C:\WINDOWS\system32\msrd2x40.dll --------- 432928 
 2008-03-25 05:50     C:\WINDOWS\system32\mspbde40.dll --------- 355104 
 2008-03-25 05:50     C:\WINDOWS\system32\msltus40.dll --------- 219936 
 2008-03-25 05:50     C:\WINDOWS\system32\msjtes40.dll --------- 248608 
 2008-03-25 05:50     C:\WINDOWS\system32\msjter40.dll --------- 60192 
 2008-03-25 05:50     C:\WINDOWS\system32\msjetoledb40.dll --------- 355112 
----------------------------------------

 
C:\WINDOWS\Prefetch

 2008-07-11 11:21     C:\WINDOWS\Prefetch\SYMLCSVC.EXE-0360BE30.pf --------- 25846 
 2008-07-11 11:21     C:\WINDOWS\Prefetch\SYMLCSV1.EXE-27D30C1B.pf --------- 66708 
 2008-07-11 11:21     C:\WINDOWS\Prefetch\FIREFOX.EXE-28641590.pf --------- 81730 
 2008-07-11 11:18     C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf --------- 32950 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf --------- 27094 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\RUNDLL32.EXE-2BF3472E.pf --------- 40750 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf --------- 16118 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\RUNDLL32.EXE-1F20A0D1.pf --------- 36556 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\RUNDLL32.EXE-1357CA32.pf --------- 34038 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\KHOST.EXE-0B46E9A4.pf --------- 39262 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\CCSVCHST.EXE-1821FA3A.pf --------- 72370 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\RAINLENDAR2.EXE-3177F58F.pf --------- 28744 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\CCLEANER.EXE-0BCE437C.pf --------- 64154 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\GOOGLETOOLBARNOTIFIER.EXE-3629C61D.pf --------- 26662 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf --------- 22544 
 2008-07-11 11:16     C:\WINDOWS\Prefetch\CCAPP.EXE-1207B2A5.pf --------- 10220 
 2008-07-10 23:13     C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf --------- 74352 
 2008-07-10 23:13     C:\WINDOWS\Prefetch\AUPDATE.EXE-2253CB60.pf --------- 72254 
 2008-07-10 23:13     C:\WINDOWS\Prefetch\LUCALLBACKPROXY.EXE-19ED7806.pf --------- 64716 
 2008-07-10 23:13     C:\WINDOWS\Prefetch\LUCOMSERVER_3_4.EXE-2CA41E19.pf --------- 53660 
 2008-07-10 23:12     C:\WINDOWS\Prefetch\DWWIN.EXE-30875ADC.pf --------- 28698 
 2008-07-10 23:11     C:\WINDOWS\Prefetch\DUMPREP.EXE-1B46F901.pf --------- 117506 
 2008-07-10 23:11     C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf --------- 40540 
 2008-07-10 23:02     C:\WINDOWS\Prefetch\WLLOGINPROXY.EXE-1781D844.pf --------- 56260 
 2008-07-10 23:02     C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf --------- 88512 
 2008-07-10 22:59     C:\WINDOWS\Prefetch\ALG.EXE-0F138680.pf --------- 24302 
 2008-07-10 22:28     C:\WINDOWS\Prefetch\VERCLSID.EXE-3667BD89.pf --------- 17142 
 2008-07-10 22:16     C:\WINDOWS\Prefetch\PIFCRAWL.EXE-32801D5D.pf --------- 96568 
 2008-07-10 22:06     C:\WINDOWS\Prefetch\USNSVC.EXE-2DF2835C.pf --------- 57742 
 2008-07-10 22:05     C:\WINDOWS\Prefetch\MSNMSGR.EXE-030AB647.pf --------- 73214 
 2008-07-10 21:58     C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf --------- 54052 
 2008-07-10 21:50     C:\WINDOWS\Prefetch\LOGON.SCR-151EFAEA.pf --------- 190166 
 2008-07-10 20:52     C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf --------- 89498 
 2008-07-10 20:48     C:\WINDOWS\Prefetch\REGEDIT.EXE-1B606482.pf --------- 13440 
 2008-07-10 20:44     C:\WINDOWS\Prefetch\NISOPTUI.EXE-2E3E43D3.pf --------- 63418 
 2008-07-10 19:14     C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf --------- 17138 
 2008-07-10 18:57     C:\WINDOWS\Prefetch\COH32.EXE-25F8395A.pf --------- 72444 
 2008-07-10 18:28     C:\WINDOWS\Prefetch\NAVW32.EXE-0E3FE09C.pf --------- 94748 
 2008-07-10 18:25     C:\WINDOWS\Prefetch\SSAUTORN.EXE-0B474C29.pf --------- 48870 
 2008-07-10 18:21     C:\WINDOWS\Prefetch\RUNDLL32.EXE-2B20730C.pf --------- 49896 
 2008-07-10 08:00     C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf --------- 72876 
 2008-07-10 08:00     C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf --------- 64834 
 2008-07-10 08:00     C:\WINDOWS\Prefetch\Layout.ini --------- 689280 
 2008-07-09 22:57     C:\WINDOWS\Prefetch\LUALL.EXE-30AC8E48.pf --------- 48148 
 2008-07-09 22:51     C:\WINDOWS\Prefetch\MSPAINT.EXE-11CBB631.pf --------- 24794 
 2008-07-09 21:54     C:\WINDOWS\Prefetch\MCUI32.EXE-3360F40B.pf --------- 64818 
 2008-07-09 21:27     C:\WINDOWS\Prefetch\NPCLUSTB.EXE-396D4453.pf --------- 61822 
 2008-07-09 20:51     C:\WINDOWS\Prefetch\WINWORD.EXE-37F6AE09.pf --------- 127508 
 2008-07-09 19:39     C:\WINDOWS\Prefetch\NAVWNT.EXE-2651887A.pf --------- 19900 
 2008-07-09 19:02     C:\WINDOWS\Prefetch\LULNCHR.EXE-1D2DBDC8.pf --------- 19452 
 2008-07-09 19:02     C:\WINDOWS\Prefetch\LOGITECHUPDATE.EXE-2FAF519E.pf --------- 13640 
 2008-07-09 19:00     C:\WINDOWS\Prefetch\COCIMANAGER.EXE-2464DE0A.pf --------- 28758 
 2008-07-09 18:59     C:\WINDOWS\Prefetch\IPODSERVICE.EXE-3192DE38.pf --------- 53498 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\QUICKCAM.EXE-0219A298.pf --------- 70856 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\ITUNESHELPER.EXE-15823303.pf --------- 12798 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\COMMUNICATIONS_HELPER.EXE-17D7A0DD.pf --------- 15692 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\JUSCHED.EXE-0882265F.pf --------- 11796 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\IGFXTRAY.EXE-3391579A.pf --------- 30390 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\ZCFGSVC.EXE-1A56EA85.pf --------- 30354 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\SYNTPENH.EXE-315D3ABC.pf --------- 16560 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\SYNTPLPR.EXE-28BB9F3B.pf --------- 11414 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\HKCMD.EXE-1D05234B.pf --------- 16740 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\RECGUARD.EXE-3990548D.pf --------- 11232 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\WGATRAY.EXE-0ED38BED.pf --------- 50330 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\1XCONFIG.EXE-036E6AE6.pf --------- 21672 
 2008-07-08 22:26     C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf --------- 21102 
 2008-07-08 21:04     C:\WINDOWS\Prefetch\QTTASK.EXE-342507FB.pf --------- 9272 
 2008-07-08 21:04     C:\WINDOWS\Prefetch\IFRMEWRK.EXE-0618C85D.pf --------- 39132 
 2008-07-08 21:04     C:\WINDOWS\Prefetch\PDVDSERV.EXE-0448293E.pf --------- 14378 
 2008-07-08 21:04     C:\WINDOWS\Prefetch\EOUWIZ.EXE-18024749.pf --------- 33054 
 2008-07-07 20:23     C:\WINDOWS\Prefetch\SNDVOL32.EXE-383480B7.pf --------- 30210 
 2008-07-06 22:32     C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf --------- 104010 
 2008-07-06 18:18     C:\WINDOWS\Prefetch\REASON.EXE-0D50A396.pf --------- 113718 
 2008-07-06 18:17     C:\WINDOWS\Prefetch\UNINS000.EXE-35E0E34C.pf --------- 13058 
 2008-07-06 18:15     C:\WINDOWS\Prefetch\DSR.EXE-0F7FB350.pf --------- 24318 
 2008-07-06 18:15     C:\WINDOWS\Prefetch\IS-5RV2P.TMP-08926E1B.pf --------- 19164 
 2008-07-06 18:15     C:\WINDOWS\Prefetch\RECORDSCREEN.EXE-28159448.pf --------- 14888 
 2008-07-06 18:06     C:\WINDOWS\Prefetch\NTVDM.EXE-1A10A423.pf --------- 11928 
 2008-07-06 18:06     C:\WINDOWS\Prefetch\GUNINST.EXE-31EA5C79.pf --------- 15020 
 2008-07-06 18:06     C:\WINDOWS\Prefetch\UNINSTALL.EXE-2126F286.pf --------- 12726 
 2008-07-06 17:41     C:\WINDOWS\Prefetch\REALSCHED.EXE-3282FD31.pf --------- 18278 
 2008-07-06 17:41     C:\WINDOWS\Prefetch\REALONEMESSAGECENTER.EXE-0F115151.pf --------- 15236 
 2008-07-06 17:41     C:\WINDOWS\Prefetch\RPHELPERAPP.EXE-33CB172B.pf --------- 40486 
 2008-07-06 17:41     C:\WINDOWS\Prefetch\REALPLAY.EXE-1BF219BD.pf --------- 143396 
 2008-07-06 17:37     C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEFA4.pf --------- 61416 
 2008-07-06 17:06     C:\WINDOWS\Prefetch\SKYPEPM.EXE-2BC7DD5C.pf --------- 84172 
 2008-07-06 17:06     C:\WINDOWS\Prefetch\SKYPE.EXE-30AE1A60.pf --------- 101008 
 2008-07-06 16:08     C:\WINDOWS\Prefetch\RUNDLL32.EXE-2D8C4CF3.pf --------- 29494 
 2008-07-06 16:05     C:\WINDOWS\Prefetch\CCSETUP209.EXE-2B2D3D4E.pf --------- 18642 
 2008-07-06 15:21     C:\WINDOWS\Prefetch\RECORDINGMANAGER.EXE-34557554.pf --------- 47808 
 2008-07-06 15:13     C:\WINDOWS\Prefetch\PLAYPLUS.EXE-16397344.pf --------- 57408 
 2008-07-06 15:11     C:\WINDOWS\Prefetch\RECORDER.EXE-17A25168.pf --------- 59474 
 2008-07-06 14:13     C:\WINDOWS\Prefetch\ITUNES.EXE-1A268432.pf --------- 114014 
 2008-07-06 13:56     C:\WINDOWS\Prefetch\RNXPROC.EXE-1CD3A84F.pf --------- 13216 
 2008-07-06 13:54     C:\WINDOWS\Prefetch\REALPLAY_MOUNTPOINTS.EXE-35C57E1D.pf --------- 12076 
 2008-07-06 13:54     C:\WINDOWS\Prefetch\SETREG.EXE-2FA0C391.pf --------- 6096 
 2008-07-06 13:54     C:\WINDOWS\Prefetch\DEFENC.EXE-10AC874F.pf --------- 6452 
 2008-07-06 13:52     C:\WINDOWS\Prefetch\REALPLAYER11GOLD.EXE-08A644CF.pf --------- 53822 
 2008-07-06 13:47     C:\WINDOWS\Prefetch\RNSETUP0.EXE-0E1D856E.pf --------- 23452 
 2008-07-06 13:47     C:\WINDOWS\Prefetch\REALPLAYER11GOLD.EXE-248899DA.pf --------- 16526 
 2008-07-06 13:45     C:\WINDOWS\Prefetch\EXPORTCONTROLLER.EXE-0303443A.pf --------- 64972 
 2008-07-06 13:45     C:\WINDOWS\Prefetch\QUICKTIMEPLAYER.EXE-280B4828.pf --------- 94432 
 2008-07-06 13:13     C:\WINDOWS\Prefetch\SRVLNCH.EXE-02CACF76.pf --------- 9906 
 2008-07-06 13:13     C:\WINDOWS\Prefetch\FLTRINST.EXE-154AA3B3.pf --------- 61564 
 2008-07-06 13:13     C:\WINDOWS\Prefetch\WUAPP32.EXE-054290B0.pf --------- 13842 
 2008-07-06 13:13     C:\WINDOWS\Prefetch\RUNDLL32.EXE-4C4CD88B.pf --------- 49546 
 2008-07-06 11:53     C:\WINDOWS\Prefetch\DISTNOTED.EXE-036B52B9.pf --------- 18912 
 2008-07-06 11:53     C:\WINDOWS\Prefetch\APPLEMOBILEDEVICEHELPER.EXE-2864A39D.pf --------- 65692 
 2008-07-05 10:41     C:\WINDOWS\Prefetch\SOFTWAREUPDATE.EXE-1415D1B8.pf --------- 7626 
 2008-07-05 09:41     C:\WINDOWS\Prefetch\SYMLCSV1.EXE-0EE21BE3.pf --------- 8906 
 2008-07-05 09:17     C:\WINDOWS\Prefetch\RUNDLL32.EXE-32D3BE3D.pf --------- 28142 
 2008-07-05 09:13     C:\WINDOWS\Prefetch\RUNDLL32.EXE-147710F4.pf --------- 30976 
 2008-07-05 09:07     C:\WINDOWS\Prefetch\READER_SL.EXE-1A438403.pf --------- 13158 
 2008-07-05 09:07     C:\WINDOWS\Prefetch\OSCHECK.EXE-04203B4E.pf --------- 6668 
 2008-07-04 20:31     C:\WINDOWS\Prefetch\HELPER.EXE-0415776D.pf --------- 19312 
 2008-07-04 20:31     C:\WINDOWS\Prefetch\UPDATER.EXE-07A64772.pf --------- 67240 
 2008-07-03 18:43     C:\WINDOWS\Prefetch\IGFXEXT.EXE-20973E2B.pf --------- 19608 
 2008-07-03 16:19     C:\WINDOWS\Prefetch\WMPLAYER.EXE-18DDEFA3.pf --------- 64896 
 2008-07-01 21:49     C:\WINDOWS\Prefetch\EXCEL.EXE-13B3F319.pf --------- 58314 
 2008-07-01 21:47     C:\WINDOWS\Prefetch\RUNDLL32.EXE-3CF3A328.pf --------- 29802 
 2008-07-01 21:44     C:\WINDOWS\Prefetch\RUNDLL32.EXE-32BB7F4A.pf --------- 30964 
 2008-07-01 21:44     C:\WINDOWS\Prefetch\PSPAD.EXE-398D19B9.pf --------- 49854 
 2008-07-01 20:26     C:\WINDOWS\Prefetch\RUNDLL32.EXE-1727725A.pf --------- 29074 
 2008-07-01 20:11     C:\WINDOWS\Prefetch\RUNDLL32.EXE-3C2FA7FD.pf --------- 29412 
 2008-07-01 19:54     C:\WINDOWS\Prefetch\JAVA.EXE-04FA6B41.pf --------- 6022 
 2008-06-30 18:13     C:\WINDOWS\Prefetch\FWCFG.EXE-244A8B28.pf --------- 58082 
 2008-06-30 18:02     C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf --------- 18406 
 2008-06-30 17:58     C:\WINDOWS\Prefetch\DLLHOST.EXE-36758099.pf --------- 86842 
 2008-06-29 22:32     C:\WINDOWS\Prefetch\SETUP_WM.EXE-3135CBD6.pf --------- 27370 
 2005-12-06 08:29     C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf --------- 581354 
----------------------------------------

 
C:\WINDOWS\Tasks

 2008-07-11 11:15     C:\WINDOWS\Tasks\SA.DAT --------- 6 
 2008-07-05 10:41     C:\WINDOWS\Tasks\AppleSoftwareUpdate.job --------- 284 
 2008-06-30 20:02     C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Rory Garland.job --------- 636 
 2004-08-04 13:00     C:\WINDOWS\Tasks\desktop.ini --------- 65 
----------------------------------------

 
C:\WINDOWS\Temp

 2008-07-11 11:15     C:\WINDOWS\Temp\Perflib_Perfdata_830.dat --------- 16384 
 2008-07-11 11:15     C:\WINDOWS\Temp\JET2390.tmp --------- 0 
----------------------------------------

 
C:\DOCUME~1\RORYGA~1\LOCALS~1\Temp

----------------------------------------

 
C:\Program Files

----------------------------------------

 
C:\Documents and Settings\All Users\.. 

Rory Garland    
Default User    
NetworkService    
LocalService    
All Users    
----------------------------------------

 
C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1       localhost
127.0.0.1    www.007guard.com
127.0.0.1    007guard.com
127.0.0.1    008i.com
127.0.0.1    www.008k.com
127.0.0.1    008k.com
127.0.0.1    www.00hq.com
127.0.0.1    00hq.com
127.0.0.1    010402.com
127.0.0.1    www.032439.com
127.0.0.1    032439.com
127.0.0.1    www.1001-search.info
127.0.0.1    1001-search.info
127.0.0.1    www.100888290cs.com
127.0.0.1    100888290cs.com
127.0.0.1    www.100sexlinks.com
127.0.0.1    100sexlinks.com
127.0.0.1    www.10sek.com
127.0.0.1    10sek.com
127.0.0.1    www.123topsearch.com
127.0.0.1    123topsearch.com
127.0.0.1    www.132.com
127.0.0.1    132.com
127.0.0.1    www.136136.net
127.0.0.1    136136.net
127.0.0.1    www.139mm.com
127.0.0.1    139mm.com
127.0.0.1    www.163ns.com
127.0.0.1    163ns.com
127.0.0.1    171203.com
127.0.0.1    17-plus.com
127.0.0.1    www.1800searchonline.com
127.0.0.1    1800searchonline.com
127.0.0.1    www.180searchassistant.com
127.0.0.1    180searchassistant.com
127.0.0.1    www.180solutions.com
127.0.0.1    180solutions.com
127.0.0.1    www.181.365soft.info
127.0.0.1    181.365soft.info
127.0.0.1    www.1987324.com
127.0.0.1    1987324.com
127.0.0.1    www.1-domains-registrations.com
127.0.0.1    1-domains-registrations.com
127.0.0.1    www.1-extreme.biz
127.0.0.1    1-extreme.biz
127.0.0.1    www.1sexparty.com
127.0.0.1    1sexparty.com
127.0.0.1    www.1stantivirus.com
127.0.0.1    1stantivirus.com
127.0.0.1    www.1stpagehere.com
127.0.0.1    1stpagehere.com
127.0.0.1    www.1stsearchportal.com
127.0.0.1    1stsearchportal.com
127.0.0.1    2.82211.net
127.0.0.1    www.2006ooo.com
127.0.0.1    2006ooo.com
127.0.0.1    www.2007-download.com
127.0.0.1    2007-download.com
127.0.0.1    www.2020search.com
127.0.0.1    2020search.com
127.0.0.1    20x2p.com
127.0.0.1    www.24.365soft.info
127.0.0.1    24.365soft.info
127.0.0.1    www.24-7pharmacy.info
127.0.0.1    24-7pharmacy.info
127.0.0.1    www.24-7searching-and-more.com
127.0.0.1    24-7searching-and-more.com
127.0.0.1    www.24teen.com
127.0.0.1    24teen.com
127.0.0.1    www.2every.net
127.0.0.1    2every.net
127.0.0.1    2ndpower.com
127.0.0.1    www.2search.com
127.0.0.1    2search.com
127.0.0.1    www.2search.org
127.0.0.1    2search.org
127.0.0.1    www.2squared.com
127.0.0.1    2squared.com
127.0.0.1    www.3322.org
127.0.0.1    3322.org
127.0.0.1    365soft.info
127.0.0.1    www.36site.com

----------------------------------------

 

 
***** Ende des Scans 2008-07-11 um 11:24:13.15 ***  
 

Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13599
 
   Posted 7-11-2008 12:05 (GMT +1)    Quote: System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!Alert an admin about: System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!
Hello smile
 
 
Please download Combofix:
 
 
And save to the desktop.

Close all other browser windows.
 
Please connect all your external hard drive/flash drive before running Combofix
 
 
 
Important-> Temporarily disable your anti-virus, real-time protection before performing a scan. They can interfere with combofix or remove some of its embedded files which may cause "unpredictable results".
 
 
Go to Start->Run and copy/paste: ComboFix /snapshot and hit OK. It should run Combofix.
 
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.

 When finished, it will produce a logfile located at C:\combofix.txt.
 

Post the contents of that log in your next reply with a new hijackthis log.
 
Please copy and paste your log files. DO NOT add it as an attachment
Kindly do not annotate or format the log with color or font changes.



NB. If you are using any P2P (file sharing) programs, please remove them before we clean your computer.. We do not clean logs that have P2P applications installed as this can cause reinfection during your cleaning.
 


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

razgee
New Member


Date Joined Jun 2008
Total Posts : 3
 
   Posted 7-12-2008 11:17 (GMT +1)    Quote: System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!Alert an admin about: System Alert-popup Strange flashing icon in system tray- virus/malware?? HELP!!
combofix didn't work, it ran for almost 13 hours ( i left it running overnight) it became stuck at number 37. i exited out of this and re-booted.
after this i downloaded 'Malwarebyte's Anti-Malware after looking at a post on 'The Spy Killer' forums.
I ran the program, scanned (took 1 hour) and it found lots of stuff that needed deleting
the main was a Trojan Zlob, which seemed to create a number of different files on my computer (see below):
Malwarebytes' Anti-Malware 1.20
Database version: 941
Windows 5.1.2600 Service Pack 2

10:43:48 2008-07-12
mbam-log-7-12-2008 (10-43-47).txt

Scan type: Full Scan (C:\|)
Objects scanned: 103905
Time elapsed: 1 hour(s), 3 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 28
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 33
Files Infected: 832

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\gnmguxh.dll (Trojan.Zlob) -> Unloaded module successfully.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{629340b5-8df6-4211-9245-a86563a35792} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/publisher,version=0.2.0 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/updater,version=0.2.0 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{629340b5-8df6-4211-9245-a86563a35792} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{1c56e97b-a95f-47b2-93c0-3feed24479a7} (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\2817 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\2817\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\2817\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\2817\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\2817\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\gid329 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo02\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo03 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\gid329\cid1124\bebo03\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\4520 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\4520\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Updater (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Updater\2663 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Updater\4458 (Adware.VideoEgg) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\gnmguxh.dll (Trojan.Zlob) -> Delete on reboot.
C:\Program Files\VideoEgg\Loader\2663\npvideoegg-loader.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\VideoEgg\user.dat (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\DataLOCKED (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\report.log (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\aol_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\audio_combo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\audio_source.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\bebo_tv_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\bebo_tv_watermark_1.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\big_gray_logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\big_logo_cropped.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\blank_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorders_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_slide copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_left_curve.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_top_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_horiz.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_vertical.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropzone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_instructions.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\eraser.CUR (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\eraser_cursor.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\file_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\file_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\help.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_camcorders.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_ff.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_webcams.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\loading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\loading_movie.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\locating.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_bottom.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_middle.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_top.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_btn_highlighted copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_slide_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\movie_placeholder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fast_forward_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind_to_start.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\playhead.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\powered_by.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\progress.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\skin.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\skin.zip (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_over_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\tab_slide_deselected.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\tape_control.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_medium.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_thumbnail.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_from.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg-large.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg-small.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_gray.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_green.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_orange.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_red.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\waiting_for_email.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcams_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcam_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcam_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\publisher.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\2817\avcodec.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Data\VideoEgg\Publisher\2817\crashRpt.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Rory Garland\Application Da