CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[MOVE]Services stopped...Can't Run Explorer etc.. Please Help

 
Post new topic   Reply to topic       All -> FavForums -> MIRT Discussion [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
NoahH

Cadet
Cadet


Joined: Jun 04, 2008
Posts: 2
Location: Canada

PostPosted: Sat Jun 07, 2008 1:47 am    Post subject: Services stopped...Can't Run Explorer etc.. Please Help
Reply with quote

I would like to keep this short but my problem seems enormous right now.
#1. Many services are stopped and will not restart including system restore. Not allowed to view properties. RPC is down aswell and adaware too. This is in both normal and safe modes. I get error 1068 or 1069 when i try and restart a service throught services.msc.

#2. Internet Explorer tries to launch on click but will exit right away.

#3. msconfig is blank on the system.ini tab. Most services stopped in the services tab.

and

#4. Kaspersky anti virus has detected these listed and says they are disinfected only to return.

Protection : completed
----------------------
Total scanned: 377322
Detected: 24
Untreated: 0
Start time: unknown
Duration: unknown
Finish time: unknown


Detected
--------
Status Object
------ ------
quarantined: virus Heur.Trojan.Generic (modification) File: C:\WINDOWS\444.471
quarantined: virus Heur.Trojan.Generic (modification) File: C:\WINDOWS\444.471//PE_Patch.UPX
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.wwr File: C:\WINDOWS\SYSTEM32\ssqRKdde.dll
deleted: Trojan program Trojan-Downloader.Win32.Small.wfv File: C:\WINDOWS\system32\2109b\lutdtx2.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.wpv File: C:\WINDOWS\system32\ejhgassy.dll
not found: adware not-a-virus:AdWare.Win32.Virtumonde.wpu File: C:\WINDOWS\system32\hmaeavcn.dll
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\system32\vtUliFur.dll
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\WINDOWS\system32\jlxjjeit.dll
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\windows\system32\ehxrkrkd.dll
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\windows\system32\hnegkhuw.dll
deleted: adware not-a-virus:AdWare.Win32.Agent.byy File: C:\windows\system32\{74651c27-9521-74ec-cf4a-40d3ce7a720b}.dll
deleted: adware not-a-virus:AdWare.Win32.ZenoSearch.bg File: C:\windows\system32\eTM\moolckr.exe
deleted: Trojan program Trojan-Downloader.Win32.VB.epp File: C:\windows\system32\vntiho06\vntiho061083.exe
deleted: malware not-virus:Hoax.Win32.Renos.cqi File: C:\windows\lfn.exe//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.Win32.Homles.bs File: C:\windows\mrofinu1000106.exe
deleted: Trojan program Trojan-Downloader.Win32.Homles.bs File: C:\windows\mrofinu1044.exe
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LZ3YJF94\kb456456[1]
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QW9AIJX2\kb516107[1]
deleted: Trojan program Trojan.Win32.Monder.gen File: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QW9AIJX2\kb767887[1]
deleted: Trojan program Trojan.Win32.Inject.mf File: C:\DOCUME~1\Owner\LOCALS~1\Temp\ugeubgrc.dll
deleted: Trojan program Trojan-Downloader.Win32.Small.buy File: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\hdpars11.exe.bac_a50428//CryptFF.b//UPX
deleted: Trojan program Trojan-Downloader.Win32.Agent.plz File: C:\Documents and Settings\Owner\Application Data\Microsoft\dtsc\28963.exe//PE_Patch.UPX//UPX
deleted: Trojan program Trojan-Downloader.WMA.Wimad.n File: C:\Documents and Settings\Owner\Desktop\My Downloads\all i wanna do.mp3
deleted: adware not-a-virus:AdWare.Win32.Agent.byy File: C:\WINDOWS\system32\g86.exe//stream//data0002


Events
------
Time Event
---- -----
6/3/2008 3:40:19 PM You are advised to perform a full computer scan as soon as possible.
6/3/2008 3:40:20 PM Database is out of date, leaving your computer at risk of infection. Please update your database.
6/3/2008 3:40:20 PM Protection of your computer is enabled.
6/3/2008 3:46:57 PM Process (PID 2020) tried to access Kaspersky Anti-Virus process (PID 2156), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/3/2008 3:51:54 PM File C:\WINDOWS\444.471//PE_Patch.UPX: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 3:51:54 PM Security threats have been detected. You are advised to neutralize them immediately.
6/3/2008 3:51:54 PM File C:\WINDOWS\444.471//PE_Patch.UPX: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 3:51:54 PM File C:\WINDOWS\444.471//PE_Patch.UPX: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 3:53:36 PM File c:\windows\444.471//PE_Patch.UPX: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 3:53:36 PM File c:\windows\444.471//PE_Patch.UPX: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 3:53:36 PM File c:\windows\444.471//PE_Patch.UPX: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 3:58:49 PM Please restart your computer to complete the installation of new or updated protection components.
6/3/2008 3:59:18 PM Please restart your computer to complete the installation of new or updated protection components.
6/3/2008 3:59:21 PM File C:\WINDOWS\SYSTEM32\ssqRKdde.dll: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.wwr'. User: WORKGROUP\FAMILY$, computer: localhost.
6/3/2008 3:59:21 PM Security threats have been detected. You are advised to neutralize them immediately.
6/3/2008 3:59:24 PM Update completed successfully
6/3/2008 3:59:39 PM File C:\WINDOWS\system32\2109b\lutdtx2.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX: detected: Trojan program 'Trojan-Downloader.Win32.Small.wfv'.
6/3/2008 4:00:06 PM File C:\WINDOWS\system32\2109b\lutdtx2.exe: deleted.
6/3/2008 4:00:15 PM File C:\WINDOWS\SYSTEM32\ssqRKdde.dll: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.wwr'.
6/3/2008 4:00:16 PM File C:\WINDOWS\SYSTEM32\ssqRKdde.dll will be deleted on system restart.
6/3/2008 4:00:17 PM Startup object HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqRKdde\ssqRKdde: deleted.
6/3/2008 4:01:22 PM File C:\WINDOWS\SYSTEM32\ssqRKdde.dll: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.wwr'.
6/3/2008 4:07:52 PM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 4:07:52 PM Security threats have been detected. You are advised to neutralize them immediately.
6/3/2008 4:08:22 PM File C:\WINDOWS\system32\ejhgassy.dll: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.wpv'.
6/3/2008 4:48:02 PM You are advised to perform a full computer scan as soon as possible.
6/3/2008 4:48:03 PM System is running in safe mode. Some protection components are disabled.
6/3/2008 4:48:03 PM Security threats have been detected. You are advised to neutralize them immediately.
6/3/2008 4:50:12 PM Scan startup objects cannot be started because of an error: task cannot be started in the safe mode
6/3/2008 4:53:17 PM Update error: A network failure occurred during downloading updates.
6/3/2008 4:54:16 PM Update error: A network failure occurred during downloading updates.
6/3/2008 4:54:34 PM Update error: A network failure occurred during downloading updates.
6/3/2008 4:54:59 PM Update error: A network failure occurred during downloading updates.
6/3/2008 4:57:28 PM Update error: A network failure occurred during downloading updates.
6/3/2008 5:02:58 PM You are advised to perform a full computer scan as soon as possible.
6/3/2008 5:03:00 PM Protection of your computer is enabled.
6/3/2008 5:07:49 PM File C:\WINDOWS\system32\hmaeavcn.dll: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.wpu'. User: FAMILY\Owner, computer: localhost.
6/3/2008 5:07:49 PM Security threats have been detected. You are advised to neutralize them immediately.
6/3/2008 5:07:50 PM File C:\WINDOWS\system32\hmaeavcn.dll: is still infected, skipped by user.
6/3/2008 5:08:24 PM Process (PID 3668) tried to access Kaspersky Anti-Virus process (PID 3468), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/3/2008 5:10:23 PM Process (PID 1840) tried to access Kaspersky Anti-Virus process (PID 248), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/3/2008 5:11:18 PM Some protection components are disabled. You are advised to enable them.
6/3/2008 5:11:18 PM Protection of your computer is disabled. You are advised to enable protection.
6/3/2008 5:17:38 PM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 5:17:38 PM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 5:17:38 PM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 5:21:16 PM File c:\windows\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 5:21:16 PM File c:\windows\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 5:21:16 PM File c:\windows\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/3/2008 5:29:30 PM Update completed successfully
6/3/2008 7:38:45 PM Update completed successfully
6/3/2008 9:59:03 PM Update completed successfully
6/4/2008 12:18:45 AM Update completed successfully
6/4/2008 2:38:42 AM Update completed successfully
6/4/2008 4:58:59 AM Update completed successfully
6/4/2008 7:18:41 AM Update completed successfully
6/4/2008 9:41:58 AM Update completed successfully
6/4/2008 9:56:41 AM File C:\WINDOWS\system32\vtUliFur.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 9:56:41 AM File C:\WINDOWS\system32\vtUliFur.dll: is still infected, postponed.
6/4/2008 9:57:33 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 9:57:33 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 9:57:33 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 10:11:42 AM You are advised to perform a full computer scan as soon as possible.
6/4/2008 10:11:43 AM Protection of your computer is disabled. You are advised to enable protection.
6/4/2008 10:11:43 AM Security threats have been detected. You are advised to neutralize them immediately.
6/4/2008 10:15:32 AM Process (PID 2112) tried to access Kaspersky Anti-Virus process (PID 4040), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 10:18:49 AM File C:\WINDOWS\system32\vtUliFur.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 10:18:49 AM File C:\WINDOWS\system32\vtUliFur.dll: is still infected, postponed.
6/4/2008 10:23:23 AM File C:\WINDOWS\system32\jlxjjeit.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 10:23:23 AM File C:\WINDOWS\system32\jlxjjeit.dll: is still infected, postponed.
6/4/2008 10:23:35 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 10:23:36 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 10:23:36 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 10:25:13 AM File c:\windows\system32\jlxjjeit.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 10:25:13 AM File c:\windows\system32\jlxjjeit.dll: is still infected, postponed.
6/4/2008 10:25:37 AM File c:\windows\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 10:25:37 AM File c:\windows\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 10:25:37 AM File c:\windows\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 10:26:16 AM File c:\windows\system32\vtulifur.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 10:26:16 AM File c:\windows\system32\vtulifur.dll: is still infected, postponed.
6/4/2008 10:28:47 AM File c:\windows\system32\vtulifur.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 11:46:38 AM File c:\windows\system32\vtulifur.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 11:46:38 AM File c:\windows\system32\vtulifur.dll: is still infected, cannot be disinfected.
6/4/2008 11:46:39 AM File c:\windows\system32\vtulifur.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 11:46:39 AM File c:\windows\system32\vtulifur.dll will be deleted on system restart.
6/4/2008 11:46:48 AM Startup object HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4B41C22A-5C83-4F13-9BFE-B8AB23A26830}\{4B41C22A-5C83-4F13-9BFE-B8AB23A26830}: deleted.
6/4/2008 11:47:49 AM File C:\WINDOWS\system32\vtUliFur.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 11:51:22 AM File C:\WINDOWS\system32\jlxjjeit.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 11:51:22 AM File C:\WINDOWS\system32\jlxjjeit.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 11:51:22 AM File C:\WINDOWS\system32\jlxjjeit.dll: is still infected, cannot be disinfected.
6/4/2008 11:51:24 AM File C:\WINDOWS\system32\jlxjjeit.dll will be deleted on system restart.
6/4/2008 11:52:26 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 11:52:28 AM Startup object HKLM\System\ControlSet001\Services\MsSecurity1.209.4\MsSecurity1.209.4: deleted.
6/4/2008 11:52:29 AM File C:\WINDOWS\444.471 will be quarantined on system restart.
6/4/2008 11:52:30 AM Startup object HKLM\System\ControlSet002\Services\MsSecurity1.209.4\MsSecurity1.209.4: deleted.
6/4/2008 11:52:31 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 11:52:31 AM File C:\WINDOWS\444.471: detected modification of virus 'Heur.Trojan.Generic'.
6/4/2008 12:11:34 PM File c:\windows\system32\jlxjjeit.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 12:11:45 PM File c:\windows\system32\vtulifur.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'.
6/4/2008 12:12:18 PM Process (PID 1020) tried to access Kaspersky Anti-Virus process (PID 4036), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 12:12:18 PM Process (PID 1020) tried to access Kaspersky Anti-Virus process (PID 1828), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 12:25:44 PM You are advised to perform a full computer scan as soon as possible.
6/4/2008 12:25:44 PM Protection of your computer is disabled. You are advised to enable protection.
6/4/2008 12:25:44 PM Security threats have been detected. You are advised to neutralize them immediately.
6/4/2008 12:28:18 PM Process (PID 3164) tried to access Kaspersky Anti-Virus process (PID 2860), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 12:29:25 PM Quarantine: File C:\WINDOWS\444.471//PE_Patch.UPX//UPX: detected: Trojan program 'Trojan.Win32.DNSChanger.dxy'.
6/4/2008 12:29:27 PM Update completed successfully
6/4/2008 12:30:24 PM Quarantine: File C:\WINDOWS\444.471: deleted.
6/4/2008 12:32:10 PM Protection of your computer is enabled.
6/4/2008 12:53:25 PM File C:\windows\system32\ehxrkrkd.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'. User: FAMILY\Owner, computer: localhost.
6/4/2008 12:59:14 PM File C:\windows\system32\ehxrkrkd.dll: is still infected, cannot be disinfected.
6/4/2008 12:59:35 PM File C:\windows\system32\ehxrkrkd.dll: deleted.
6/4/2008 12:59:36 PM File C:\windows\system32\hnegkhuw.dll: detected: Trojan program 'Trojan.Win32.Monder.gen'. User: FAMILY\Owner, computer: localhost.
6/4/2008 12:59:41 PM File C:\windows\system32\hnegkhuw.dll: is still infected, cannot be disinfected.
6/4/2008 12:59:44 PM File C:\windows\system32\hnegkhuw.dll: deleted.
6/4/2008 12:59:45 PM File C:\windows\system32\{74651c27-9521-74ec-cf4a-40d3ce7a720b}.dll: detected: adware 'not-a-virus:AdWare.Win32.Agent.byy'. User: FAMILY\Owner, computer: localhost.
6/4/2008 12:59:50 PM File C:\windows\system32\{74651c27-9521-74ec-cf4a-40d3ce7a720b}.dll: deleted.
6/4/2008 12:59:50 PM File C:\windows\system32\eTM\moolckr.exe: detected: adware 'not-a-virus:AdWare.Win32.ZenoSearch.bg'. User: FAMILY\Owner, computer: localhost.
6/4/2008 12:59:53 PM File C:\windows\system32\eTM\moolckr.exe: deleted.
6/4/2008 12:59:53 PM File C:\windows\system32\vntiho06\vntiho061083.exe: detected: Trojan program 'Trojan-Downloader.Win32.VB.epp'. User: FAMILY\Owner, computer: localhost.
6/4/2008 12:59:55 PM File C:\windows\system32\vntiho06\vntiho061083.exe: deleted.
6/4/2008 1:00:05 PM File C:\windows\lfn.exe//PE_Patch.UPX//UPX: detected: malware 'not-virus:Hoax.Win32.Renos.cqi'. User: FAMILY\Owner, computer: localhost.
6/4/2008 1:00:10 PM File C:\windows\lfn.exe: deleted.
6/4/2008 1:00:10 PM File C:\windows\mrofinu1000106.exe: detected: Trojan program 'Trojan-Downloader.Win32.Homles.bs'. User: FAMILY\Owner, computer: localhost.
6/4/2008 1:00:13 PM File C:\windows\mrofinu1000106.exe: deleted.
6/4/2008 1:00:14 PM File C:\windows\mrofinu1044.exe: detected: Trojan program 'Trojan-Downloader.Win32.Homles.bs'. User: FAMILY\Owner, computer: localhost.
6/4/2008 1:00:17 PM File C:\windows\mrofinu1044.exe: deleted.
6/4/2008 1:01:22 PM Process (PID 164) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 1:04:46 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LZ3YJF94\kb456456[1]: detected: Trojan program 'Trojan.Win32.Monder.gen'. User: FAMILY\Owner, computer: localhost.
6/4/2008 1:04:50 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LZ3YJF94\kb456456[1]: is still infected, cannot be disinfected.
6/4/2008 1:04:54 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\LZ3YJF94\kb456456[1]: deleted.
6/4/2008 1:04:54 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QW9AIJX2\kb516107[1]: detected: Trojan program 'Trojan.Win32.Monder.gen'. User: FAMILY\Owner, computer: localhost.
6/4/2008 1:04:58 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QW9AIJX2\kb516107[1]: is still infected, cannot be disinfected.
6/4/2008 1:05:01 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QW9AIJX2\kb516107[1]: deleted.
6/4/2008 1:05:01 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QW9AIJX2\kb767887[1]: detected: Trojan program 'Trojan.Win32.Monder.gen'. User: FAMILY\Owner, computer: localhost.
6/4/2008 1:05:05 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QW9AIJX2\kb767887[1]: is still infected, cannot be disinfected.
6/4/2008 1:05:07 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QW9AIJX2\kb767887[1]: deleted.
6/4/2008 1:33:59 PM File C:\DOCUME~1\Owner\LOCALS~1\Temp\ugeubgrc.dll: detected: Trojan program 'Trojan.Win32.Inject.mf'.
6/4/2008 1:34:06 PM File C:\DOCUME~1\Owner\LOCALS~1\Temp\ugeubgrc.dll: deleted.
6/4/2008 2:19:20 PM Some protection components are disabled. You are advised to enable them.
6/4/2008 2:19:20 PM Protection of your computer is disabled. You are advised to enable protection.
6/4/2008 2:36:03 PM Process (PID 1116) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 2:36:03 PM Process (PID 1116) tried to access Kaspersky Anti-Virus process (PID 2860), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 2:46:27 PM Process (PID 1116) tried to access Kaspersky Anti-Virus process (PID 2444), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 2:48:25 PM Update completed successfully
6/4/2008 3:01:03 PM Process (PID 1044) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 3:01:04 PM Process (PID 1044) tried to access Kaspersky Anti-Virus process (PID 2860), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/4/2008 3:06:25 PM Protection of your computer is enabled.
6/4/2008 5:07:02 PM Update completed successfully
6/4/2008 7:26:42 PM Update completed successfully
6/4/2008 9:46:45 PM Update completed successfully
6/5/2008 12:07:09 AM Update completed successfully
6/5/2008 2:26:52 AM Update completed successfully
6/5/2008 4:47:09 AM Update completed successfully
6/5/2008 7:07:02 AM Update completed successfully
6/5/2008 8:40:19 AM Process (PID 1508) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 8:40:19 AM Process (PID 1508) tried to access Kaspersky Anti-Virus process (PID 2860), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 8:43:04 AM Process (PID 3388) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 8:43:04 AM Process (PID 3388) tried to access Kaspersky Anti-Virus process (PID 2860), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 9:18:57 AM Process (PID 3644) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 9:18:57 AM Process (PID 3644) tried to access Kaspersky Anti-Virus process (PID 2860), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 9:27:47 AM Update completed successfully
6/5/2008 10:35:54 AM Process (PID 3704) tried to access Kaspersky Anti-Virus process (PID 2860), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 10:35:55 AM Process (PID 3704) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 10:36:48 AM Process (PID 2984) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 10:36:52 AM Process (PID 2984) tried to access Kaspersky Anti-Virus process (PID 2860), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 10:51:29 AM Process (PID 208) tried to access Kaspersky Anti-Virus process (PID 604), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 10:57:35 AM You are advised to perform a full computer scan as soon as possible.
6/5/2008 10:57:40 AM Protection of your computer is enabled.
6/5/2008 10:57:41 AM Process (PID 1288) tried to access Kaspersky Anti-Virus process (PID 1880), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 10:57:42 AM Process (PID 356) tried to access Kaspersky Anti-Virus process (PID 1880), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 11:01:13 AM Process (PID 7948) tried to access Kaspersky Anti-Virus process (PID 7884), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 12:42:51 PM Update completed successfully
6/5/2008 1:54:55 PM Protection of your computer is not running. You are advised to resume protection.
6/5/2008 1:59:21 PM You are advised to perform a full computer scan as soon as possible.
6/5/2008 1:59:22 PM Protection of your computer is enabled.
6/5/2008 1:59:27 PM Process (PID 1280) tried to access Kaspersky Anti-Virus process (PID 1896), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 1:59:30 PM Process (PID 384) tried to access Kaspersky Anti-Virus process (PID 1896), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 3:00:05 PM Update completed successfully
6/5/2008 3:34:52 PM Process (PID 26480) tried to access Kaspersky Anti-Virus process (PID 28668), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 3:41:31 PM Process (PID 26444) tried to access Kaspersky Anti-Virus process (PID 1896), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 3:45:42 PM Protection of your computer is not running. You are advised to resume protection.
6/5/2008 3:58:52 PM You are advised to perform a full computer scan as soon as possible.
6/5/2008 3:58:58 PM Protection of your computer is enabled.
6/5/2008 3:59:02 PM Process (PID 356) tried to access Kaspersky Anti-Virus process (PID 1924), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 4:00:19 PM Process (PID 1240) tried to access Kaspersky Anti-Virus process (PID 1100), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 4:05:41 PM Process (PID 2408) tried to access Kaspersky Anti-Virus process (PID 1924), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 4:05:41 PM Process (PID 2408) tried to access Kaspersky Anti-Virus process (PID 1100), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/5/2008 6:37:19 PM Update completed successfully
6/5/2008 10:09:13 PM Update completed successfully
6/6/2008 1:24:59 AM Update completed successfully
6/6/2008 4:29:54 AM Update completed successfully
6/6/2008 7:45:14 AM Update completed successfully
6/6/2008 9:25:18 AM Protection of your computer is not running. You are advised to resume protection.
6/6/2008 9:29:24 AM You are advised to perform a full computer scan as soon as possible.
6/6/2008 9:29:24 AM Protection of your computer is enabled.
6/6/2008 9:29:27 AM Process (PID 368) tried to access Kaspersky Anti-Virus process (PID 1896), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/6/2008 9:30:37 AM Process (PID 3692) tried to access Kaspersky Anti-Virus process (PID 3628), but the action has been blocked by the Self-Defense component. No action on your part is required.
6/6/2008 10:40:51 AM Protection of your computer is not running. You are advised to resume protection.
6/6/2008 1:11:41 PM You are advised to perform a full computer scan as soon as possible.
6/6/2008 1:11:42 PM System is running in safe mode. Some protection components are disabled.
6/6/2008 1:11:43 PM Update cannot be started because of an error: task cannot be started in the safe mode
6/6/2008 1:13:43 PM Scan startup objects cannot be started because of an error: task cannot be started in the safe mode
6/6/2008 1:18:23 PM File C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\hdpars11.exe.bac_a50428//CryptFF.b//UPX: detected: Trojan program 'Trojan-Downloader.Win32.Small.buy'.
6/6/2008 1:18:23 PM Security threats have been detected. You are advised to neutralize them immediately.
6/6/2008 1:18:23 PM File C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\hdpars11.exe.bac_a50428//CryptFF.b//UPX: is still infected, postponed.
6/6/2008 1:19:11 PM File C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 11-12-2007 - 14-44-53.SBU/{31B8C9C1-CB98-4FC1-B553-FC0037C923D4}: is password protected.
6/6/2008 1:19:11 PM File C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 11-12-2007 - 14-44-53.SBU/{5AD04FA1-C176-4D00-A922-4DE461ABFA43}: is password protected.
6/6/2008 1:19:11 PM File C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 11-12-2007 - 14-44-53.SBU/{A4D46ADC-3A6B-4F95-AB69-C8F75FF39246}: is password protected.
6/6/2008 1:19:11 PM File C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 11-12-2007 - 14-44-53.SBU/{CDBC4759-C0ED-4ABC-AA38-0563026F7BA2}: is password protected.
6/6/2008 1:19:11 PM File C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 11-12-2007 - 14-44-53.SBU/{D1ED7909-054D-4969-AB62-E0BDE0F7D0AC}: is password protected.
6/6/2008 1:19:11 PM File C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\Quarantine - 11-12-2007 - 14-44-53.SBU/backup.db: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClientMan.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch2.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch3.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch4.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch4.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch5.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:10 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch5.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch6.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch6.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch7.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch7.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll.zip/iedll.exe: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll1.zip/loader.exe: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffIedll1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow2.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow3.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchAffWinshow3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBlowSearch.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf.zip/msupdate.exe: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBootconf.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchDreplace1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch2.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch3.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnasearch3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch4.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch4.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch5.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGonnaSearch5.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk2.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchk2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers2.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers3.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:11 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers4.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchLeftovers4.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch.zip/notepad32.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmartSearch.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit.zip/mssys.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSvcinit.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWCADW.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinRes.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchWinSearch.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchYexe.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/users32.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip/winmgnt.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip/astctl32.ocx: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip/mtwirl32.dll: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip/winajbm.dll: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip/xplugin.dll: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/avpcc.dll: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/window.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip/systemcritical.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/waol.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip/y.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/accesss.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip/win32e.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip/win64.exe: is password protected.
6/6/2008 1:25:12 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip/systeem.exe: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip/clrssn.exe: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip/olehelp.exe: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric3.zip/iexplorer.exe: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip/x.exe: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ToolbarCC.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip/hgGwWOFW.dll: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll3.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric1.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric1.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric2.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric2.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric3.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric3.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric4.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric4.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric5.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric5.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric6.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric6.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric7.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric7.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VXbBDS.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VXbBDS.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn.zip/sbRecovery.reg: is password protected.
6/6/2008 1:25:13 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn.zip/sbRecovery.ini: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/#1 Video Converter 4.1.37 Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/.45.2006.DVDRip.XViD-ESPiSE Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/00jj99uuii66ddxxqqq.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1 Click DVD Copy Pro v3.0 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1 Click DVD Movie 3.0.0.5 Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1 DVD Ripper 5.3 Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1 DVD Ripper 5.36 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/10 books on Hacking Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/10 Items or Less (2006) [DVDRip] Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/100 Deadliest Karate Moves Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/100% Blowjobs 17 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/100% Jenna Haze Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/110% Natural 12 Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/12 Volt Resource guide Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/121 YukmouthMessy Marv - 100 Racks[2006][retail] Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/123 DVD Clone v2.5.0 Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/123 Flash Menu Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/123 Flash Menu v2.1.0.1059 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/123 Flash Menu v2.6 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/123 Flash Menu v3.2.0.1309 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1408 TS Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1408 [2007] Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/18 Eighteen Xtra 4 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/18 Wheels Of Steel Across America Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/18 Wheels of Steel Haulin Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/18yo - Michamore Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1Click DVD Copy Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1Click Dvd Copy Pro 2.4.1.6 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1Click Dvd Copy Pro 2.4.1.6 Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1CLICK DVD Copy Pro v2.5.0.8 Crack.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/1st Security Agent V6.5 Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/2 Days in Paris (2007) Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/2 guys get nice Jayna Oso Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/2 In 1 Hole Patch.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentcmn1.zip/2 In The Can Keygen.zip: is password protected.
6/6/2008 1:25:17 PM File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinA

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5866

MIRT Premium

PostPosted: Sat Jun 07, 2008 8:07 pm    Post subject:
Reply with quote

The best thing to do is to follow this http://wiki.castlecops.com/MRP

If you think you're still infected with malware post a Hijackthis log in this forum.

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

I also suggest you install Windows Defender (if you use Windows XP), which is free and is available from http://www.microsoft.com/athome/security/spyware/software/default.mspx


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
NoahH

Cadet
Cadet


Joined: Jun 04, 2008
Posts: 2
Location: Canada

PostPosted: Sun Jun 08, 2008 5:29 am    Post subject:
Reply with quote

I have windows defender and it was disabled and can't get it to start. Same with adaware. I tried installing malwarebytes and it gives me some error. I can't run internet explorer either. So alot of what is recommended in the MRP..i can't do. The same symptoms in safe mode. It's like I lost control of my computer. Earlier tonight I couldn't get on the www but my wireless adapter link light kept flashing.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5866

MIRT Premium

PostPosted: Sun Jun 08, 2008 12:50 pm    Post subject:
Reply with quote

Can you post a HijackThis Log in this forum CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

You may need to rename the HijackThis .exe file to something random like fred.exe before you can run it.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> MIRT Discussion All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer