﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / svchost.exe  what is this! Am i in danger?[home PC without Internet] / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sun, 07 Sep 2008 10:28:21 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>[b]Clear your 'System Restore' points by doing the following: [/b]&lt;br&gt;Right-click on 'My Computer' and select 'Properties'. &lt;br&gt;Select 'System Restore'. &lt;br&gt;Select 'Turn Off System Restore On All Drives'. &lt;br&gt;Select 'Apply'. &lt;br&gt;You will then get the following warning:&lt;br&gt;"You have chosen to turn off System Restore.&lt;br&gt;If you continue,all existing restore points will be deleted,and you will not be able to track or undo changes to your computer.&lt;br&gt;Do you want to turn off System Restore?".&lt;br&gt;Then select 'Yes',your 'System Restore' directories will be purged. &lt;br&gt;&lt;br&gt;[b]Restart your pc.&lt;br&gt;&lt;br&gt;Turn 'System Restore' back on:[/b]&lt;br&gt;Right click on 'My Computer' and select 'Properties'. &lt;br&gt;Select 'System Restore'. &lt;br&gt;[b]Unselect[/b] 'Turn Off System Restore On All Drives'. &lt;br&gt;Select 'Apply',then click 'Ok'.&lt;br&gt;&lt;br&gt;&lt;br&gt;Your log is clean,please do the following:&lt;br&gt;&lt;br&gt;Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the '[u]O[/u]pen:' space,then press OK.&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;You should now take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Tue, 20 May 2008 02:27:39 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>My PC running good now! No threat detected&lt;/P&gt;&lt;P&gt;SUPERAntiSpyware Scan Log&lt;BR&gt;&lt;A href="http://www.superantispyware.com"&gt;http://www.superantispyware.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Generated 05/14/2008 at 07:07 PM&lt;/P&gt;&lt;P&gt;Application Version : 4.0.1154&lt;/P&gt;&lt;P&gt;Core Rules Database Version : 3462&lt;BR&gt;Trace Rules Database Version: 1453&lt;/P&gt;&lt;P&gt;Scan type       : Quick Scan&lt;BR&gt;Total Scan Time : 00:08:10&lt;/P&gt;&lt;P&gt;Memory items scanned      : 378&lt;BR&gt;Memory threats detected   : 0&lt;BR&gt;Registry items scanned    : 333&lt;BR&gt;Registry threats detected : 0&lt;BR&gt;File items scanned        : 3813&lt;BR&gt;File threats detected     : 41&lt;/P&gt;&lt;P&gt;Trojan.Net-Dungcoi&lt;BR&gt; C:\DOCUMENTS AND SETTINGS\ADMIN\DESKTOP\NADA SURF\NADA SURF.EXE&lt;BR&gt; C:\DOCUMENTS AND SETTINGS\ADMIN\DESKTOP\SHA\SHA.EXE&lt;BR&gt; C:\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP\KEYGENS FOR PROGRAMS\PC WASHER\PC WASHER V1.2.6\CRACK\CRACK.EXE&lt;BR&gt; C:\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP\KEYGENS FOR PROGRAMS\PC WASHER\PC WASHER V1.2.6\GET 'EM ALL ™\GET 'EM ALL ™.EXE&lt;BR&gt; C:\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP\KEYGENS FOR PROGRAMS\PC WASHER\PC WASHER V1.2.6\PC WASHER V1.2.6.EXE&lt;BR&gt; C:\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP\KEYGENS FOR PROGRAMS\PC WASHER\PC WASHER.EXE&lt;BR&gt; C:\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP\KEYGENS FOR PROGRAMS\TUNE UP UTILITIES 2008\KEYGEN\KEYGEN.EXE&lt;BR&gt; C:\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP\KEYGENS FOR PROGRAMS\TUNE UP UTILITIES 2008\TUNE UP UTILITIES 2008.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\BABY RESOURCE\BEGINNING TO WALK\BEGINNING TO WALK.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\BABY RESOURCE\CRAWLER\CRAWLER.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\BABY RESOURCE\INDEPENDENT SITTER\INDEPENDENT SITTER.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\BABY RESOURCE\SUPPORTED SITTER\SUPPORTED SITTER.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\BABY RESOURCE\TODDLER\TODDLER.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\BABY RESOURCE\TOUCH J&amp;amp;J\TOUCH J&amp;amp;J.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (18)\NEW FOLDER (18).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\ANNUAL DINNER AT SINGAPORE 2007\ANNUAL DINNER AT SINGAPORE 2007.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\DAMIA\DAMIA.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\HP\HP.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\MAKCIK\MAKCIK.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (20)\NEW FOLDER (20).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (11)\NEW FOLDER (11).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (10)\NEW FOLDER (10).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (13)\NEW FOLDER (13).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (12)\NEW FOLDER (12).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (15)\NEW FOLDER (15).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (14)\NEW FOLDER (14).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (17)\NEW FOLDER (17).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (16)\NEW FOLDER (16).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (19)\NEW FOLDER\NEW FOLDER.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (19)\NEW FOLDER (19).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER\NEW FOLDER.EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (4)\NEW FOLDER (4).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (5)\NEW FOLDER (5).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (2)\NEW FOLDER (2).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (3)\NEW FOLDER (3).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (6)\NEW FOLDER (6).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (7)\NEW FOLDER (7).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (8)\NEW FOLDER (8).EXE&lt;BR&gt; E:\ALL ABOUT DAMIA\SHA\NEW FOLDER (9)\NEW FOLDER (9).EXE&lt;BR&gt; E:\SHA'S FILE\SAMPLE LETTERS\SAVE.EXE&lt;BR&gt; E:\ZUL LYRIC\BEHRINGER VSTI AMP\BEHRINGER VSTI AMP.EXE&lt;BR&gt;</description><pubDate>Mon, 19 May 2008 22:05:02 GMT</pubDate><dc:creator>sha_eddie</dc:creator></item><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>Copy and paste the contents of the SuperAntiSpyware report into your next reply as requested.&lt;br&gt;Also let me know how your pc is running now.</description><pubDate>Sat, 17 May 2008 03:39:18 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>Avira AntiVir Personal&lt;BR&gt;Report file date: 2008-05-14  19:21&lt;/P&gt;&lt;P&gt;Scanning for 1165085 virus strains and unwanted programs.&lt;/P&gt;&lt;P&gt;Licensed to:      Avira AntiVir PersonalEdition Classic&lt;BR&gt;Serial number:    0000149996-ADJIE-0001&lt;BR&gt;Platform:         Windows XP&lt;BR&gt;Windows version:  (Service Pack 2)  [5.1.2600]&lt;BR&gt;Boot mode:        Normally booted&lt;BR&gt;Username:         SYSTEM&lt;BR&gt;Computer name:    PAL&lt;/P&gt;&lt;P&gt;Version information:&lt;BR&gt;BUILD.DAT     : 8.1.00.295      16479 Bytes  2008-04-09 16:24:00&lt;BR&gt;AVSCAN.EXE    : 8.1.2.12       311553 Bytes  2008-03-18 18:02:56&lt;BR&gt;AVSCAN.DLL    : 8.1.1.0         53505 Bytes  2008-02-07 17:43:37&lt;BR&gt;LUKE.DLL      : 8.1.2.9        151809 Bytes  2008-02-28 17:41:23&lt;BR&gt;LUKERES.DLL   : 8.1.2.1         12033 Bytes  2008-02-21 17:28:40&lt;BR&gt;ANTIVIR0.VDF  : 6.40.0.0     11030528 Bytes  2007-07-18 19:33:34&lt;BR&gt;ANTIVIR1.VDF  : 7.0.3.2       5447168 Bytes  2008-03-07 22:08:58&lt;BR&gt;ANTIVIR2.VDF  : 7.0.3.62       337408 Bytes  2008-03-21 04:12:34&lt;BR&gt;ANTIVIR3.VDF  : 7.0.3.68        57856 Bytes  2008-03-25 17:27:50&lt;BR&gt;Engineversion : 8.1.0.28  &lt;BR&gt;AEVDF.DLL     : 8.1.0.5        102772 Bytes  2008-02-25 18:58:21&lt;BR&gt;AESCRIPT.DLL  : 8.1.0.19       229754 Bytes  2008-04-08 00:34:44&lt;BR&gt;AESCN.DLL     : 8.1.0.12       115060 Bytes  2008-04-08 00:34:44&lt;BR&gt;AERDL.DLL     : 8.1.0.19       418164 Bytes  2008-04-08 00:34:44&lt;BR&gt;AEPACK.DLL    : 8.1.1.0        364918 Bytes  2008-03-18 20:20:42&lt;BR&gt;AEOFFICE.DLL  : 8.1.0.15       192889 Bytes  2008-04-08 00:34:44&lt;BR&gt;AEHEUR.DLL    : 8.1.0.15      1147253 Bytes  2008-04-08 00:34:44&lt;BR&gt;AEHELP.DLL    : 8.1.0.11       115061 Bytes  2008-04-08 00:34:43&lt;BR&gt;AEGEN.DLL     : 8.1.0.15       299379 Bytes  2008-04-08 00:34:43&lt;BR&gt;AEEMU.DLL     : 8.1.0.5        430450 Bytes  2008-04-08 00:34:43&lt;BR&gt;AECORE.DLL    : 8.1.0.25       168309 Bytes  2008-04-08 18:58:32&lt;BR&gt;AVWINLL.DLL   : 1.0.0.7         14593 Bytes  2008-01-24 02:07:53&lt;BR&gt;AVPREF.DLL    : 8.0.0.1         25857 Bytes  2008-02-18 19:37:50&lt;BR&gt;AVREP.DLL     : 7.0.0.1        155688 Bytes  2007-04-16 22:26:47&lt;BR&gt;AVREG.DLL     : 8.0.0.0         30977 Bytes  2008-01-24 02:07:49&lt;BR&gt;AVARKT.DLL    : 1.0.0.23       307457 Bytes  2008-02-12 17:29:23&lt;BR&gt;AVEVTLOG.DLL  : 8.0.0.11       114945 Bytes  2008-02-28 17:31:31&lt;BR&gt;SQLITE3.DLL   : 3.3.17.1       339968 Bytes  2008-01-23 02:28:02&lt;BR&gt;SMTPLIB.DLL   : 1.2.0.19        28929 Bytes  2008-01-24 02:08:39&lt;BR&gt;NETNT.DLL     : 8.0.0.1          7937 Bytes  2008-01-25 21:05:10&lt;BR&gt;RCIMAGE.DLL   : 8.0.0.35      2371841 Bytes  2008-03-10 23:37:25&lt;BR&gt;RCTEXT.DLL    : 8.0.32.0        86273 Bytes  2008-03-06 21:02:11&lt;/P&gt;&lt;P&gt;Configuration settings for the scan:&lt;BR&gt;Jobname..........................: Complete system scan&lt;BR&gt;Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp&lt;BR&gt;Logging..........................: low&lt;BR&gt;Primary action...................: interactive&lt;BR&gt;Secondary action.................: ignore&lt;BR&gt;Scan master boot sector..........: on&lt;BR&gt;Scan boot sector.................: on&lt;BR&gt;Boot sectors.....................: C:, D:, E:, &lt;BR&gt;Scan memory......................: on&lt;BR&gt;Process scan.....................: on&lt;BR&gt;Scan registry....................: on&lt;BR&gt;Search for rootkits..............: off&lt;BR&gt;Scan all files...................: Intelligent file selection&lt;BR&gt;Scan archives....................: on&lt;BR&gt;Recursion depth..................: 20&lt;BR&gt;Smart extensions.................: on&lt;BR&gt;Macro heuristic..................: on&lt;BR&gt;File heuristic...................: medium&lt;/P&gt;&lt;P&gt;Start of the scan: 2008-05-14  19:21&lt;/P&gt;&lt;P&gt;The scan of running processes will be started&lt;BR&gt;Scan process 'avscan.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avcenter.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wscntfy.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'alg.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'sidebar.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'SUPERAntiSpyware.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'sidebar.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avgnt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'rundll32.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'CTSysVol.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'USBGuard.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'acrotray.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'cledx.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'winampa.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avguard.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'sched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'spoolsv.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'explorer.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'lsass.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'services.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'winlogon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'csrss.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'smss.exe' - '1' Module(s) have been scanned&lt;BR&gt;31 processes with 31 modules were scanned&lt;/P&gt;&lt;P&gt;Starting master boot sector scan:&lt;BR&gt;Master boot sector HD0&lt;BR&gt;      [INFO]      No virus was found!&lt;BR&gt;Master boot sector HD1&lt;BR&gt;      [INFO]      No virus was found!&lt;BR&gt;Master boot sector HD2&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Start scanning boot sectors:&lt;BR&gt;Boot sector 'C:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;BR&gt;Boot sector 'D:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;BR&gt;Boot sector 'E:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Starting to scan the registry.&lt;BR&gt;The registry was scanned ( '37' files ).&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Starting the file scan:&lt;/P&gt;&lt;P&gt;Begin scan in 'C:\'&lt;BR&gt;C:\hiberfil.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\pagefile.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\QooBox\Quarantine\C\WINDOWS\inf\Other.exe.vir&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '4893a1d8.qua'!&lt;BR&gt;C:\QooBox\Quarantine\C\WINDOWS\system32\WinSit.exe.vir&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '4899a1ce.qua'!&lt;BR&gt;C:\QooBox\Quarantine\C\WINDOWS\system32\config\Win.exe.vir&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '4899a1d0.qua'!&lt;BR&gt;C:\SDFix\backups\backups.zip&lt;BR&gt;  [0] Archive type: ZIP&lt;BR&gt;  --&amp;gt; backups/nvchost.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Agent.aap.3&lt;BR&gt;  --&amp;gt; backups/winlogon.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Proxy.Agent.KJ.20&lt;BR&gt;      [NOTE]      The file was moved to '488ea1da.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP30\A0004314.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1ab.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP30\A0004315.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1ae.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP30\A0004316.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1b1.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP30\A0004317.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1b2.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004330.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1b6.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004331.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1bd.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004332.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1c0.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004333.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1c2.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004337.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1c4.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004338.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1c5.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004339.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1c7.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004347.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1c9.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004348.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1cb.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP31\A0004350.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1cd.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004397.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1d6.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004398.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1d8.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004399.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1db.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004400.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1dd.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004403.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1df.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004405.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1e0.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004406.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1f0.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004413.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1f2.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004414.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1f7.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004415.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61358.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004416.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1f9.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004425.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6135a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004426.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1f8.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004427.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61359.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004431.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1fa.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004432.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6135b.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004439.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1fb.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004440.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6135c.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004441.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1fd.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004479.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1fc.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004480.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6135e.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004486.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1ff.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004487.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a0.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004488.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba201.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004489.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6135d.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004502.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba1fe.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004503.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6135f.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004504.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61361.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004505.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a2.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004509.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba203.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004510.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a4.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP34\A0004511.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba205.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004520.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a6.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004521.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba207.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004522.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba200.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004523.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a1.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004527.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba202.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004528.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a3.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004529.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a8.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004535.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba209.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004536.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610aa.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004537.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba204.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004538.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a5.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004542.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba206.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004543.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a7.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP35\A0004544.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba20b.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004733.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ac.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004734.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba208.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004735.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610a9.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004736.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba20a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004752.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba20d.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004753.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ae.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004754.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ab.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004755.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba20c.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004758.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ad.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004759.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba20e.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004760.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba20f.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004770.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b0.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004771.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba211.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004772.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b2.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004773.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610af.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004777.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba210.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004778.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b1.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004779.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba212.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004785.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b3.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004788.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba213.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004789.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b4.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004791.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba214.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004792.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b5.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004794.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba216.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004796.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b7.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004799.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba215.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004802.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b6.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004803.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba218.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004805.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b9.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004808.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba21a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004809.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba217.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004812.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610b8.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004813.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba219.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004816.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610bb.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004818.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba21c.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004822.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610bd.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004824.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ba.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004826.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba21b.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004827.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610bc.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004828.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba21d.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004830.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba21e.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004832.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610bf.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004836.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610be.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004842.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba21f.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004845.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba260.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004847.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610c1.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004852.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba262.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004879.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61080.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004880.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610c3.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004881.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba264.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004882.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610c5.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004885.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba266.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004888.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba221.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004889.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61082.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004892.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba223.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004894.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610c7.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004895.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba268.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004901.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61084.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004902.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba225.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004903.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610c9.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004904.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba26a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004905.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610cb.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004907.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba26c.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004908.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61086.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004910.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba227.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004913.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba220.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004917.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61081.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004919.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba222.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004920.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61088.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004921.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba229.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004922.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6108a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004923.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba22b.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004924.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61083.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004926.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba224.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004928.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6108c.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004929.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba22d.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004930.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6108e.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004931.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61085.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004932.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba226.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004933.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61087.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004934.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba228.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004935.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba22f.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004938.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61090.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004947.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61089.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004948.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba22a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004949.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6108b.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP37\A0004950.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba231.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP39\A0005308.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61092.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP39\A0005309.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba22e.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP39\A0005310.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6108f.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP39\A0005311.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba230.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP39\A0005315.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61091.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP39\A0005316.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba233.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP39\A0005317.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61094.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005411.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba235.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005412.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61096.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005413.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba237.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005414.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba234.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005417.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61095.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005419.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba236.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005430.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61097.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005431.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61098.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005432.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba239.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005433.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6109a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005437.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba238.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005438.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61099.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005439.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba23a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005459.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba23b.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005460.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6109c.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005461.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba23d.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP42\A0005463.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6109e.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP43\A0005472.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba23f.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP43\A0005473.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e0.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP43\A0005474.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba241.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP43\A0005475.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e2.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP43\A0005479.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6109b.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005578.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba23c.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005579.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba243.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005580.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e4.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005581.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba245.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005597.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e6.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005598.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba23e.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005599.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6109f.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005600.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610cd.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005604.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba247.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005605.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e8.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005606.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba249.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005615.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba240.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005616.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e1.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005617.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba242.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005618.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e3.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005621.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ea.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005626.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba24b.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005627.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ec.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005628.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba24d.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005629.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba244.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005630.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e5.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005631.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba246.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005633.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Agent.aap.3&lt;BR&gt;      [NOTE]      The file was moved to '49c610e7.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005634.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Proxy.Agent.KJ.20&lt;BR&gt;      [NOTE]      The file was moved to '49c610ee.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005638.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Agent.aap.3&lt;BR&gt;      [NOTE]      The file was moved to '485ba24f.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005640.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Proxy.Agent.KJ.20&lt;BR&gt;      [NOTE]      The file was moved to '49c610f0.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005674.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba248.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005675.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba251.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005676.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610f2.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP44\A0005678.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba253.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP45\A0005685.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610e9.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP45\A0005686.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba24a.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP45\A0005687.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610eb.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP45\A0005688.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610f4.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP45\A0005689.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba255.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP45\A0005690.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba24c.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP45\A0005691.EXE&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ed.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005829.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba24e.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005830.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610ef.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005831.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610f6.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005832.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba257.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005833.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610f8.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005834.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba250.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005835.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c610f1.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005836.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba252.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005876.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the dropper DR/Tool.CloseApp.A.5&lt;BR&gt;      [NOTE]      The file was moved to '49c610f3.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005877.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Keygen.AO&lt;BR&gt;      [NOTE]      The file was moved to '485ba259.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005878.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Keygen.AO&lt;BR&gt;      [NOTE]      The file was moved to '49c610fa.qua'!&lt;BR&gt;C:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005879.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/DelAll.Q.2&lt;BR&gt;      [NOTE]      The file was moved to '485ba25b.qua'!&lt;BR&gt;Begin scan in 'D:\'&lt;BR&gt;D:\nor_maklong\Removable Disk (G)\autorun.inf&lt;BR&gt;      [DETECTION] Contains detection pattern of the VBS script virus VBS/IETitle.A&lt;BR&gt;      [NOTE]      The file was moved to '489fa356.qua'!&lt;BR&gt;D:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005880.inf&lt;BR&gt;      [DETECTION] Contains detection pattern of the VBS script virus VBS/IETitle.A&lt;BR&gt;      [NOTE]      The file was moved to '485ba343.qua'!&lt;BR&gt;Begin scan in 'E:\'&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005837.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d0.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005838.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61171.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005839.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d2.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005840.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d1.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005841.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61172.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005842.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d3.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005843.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61174.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005844.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61173.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005845.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d4.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005846.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61175.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005847.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d6.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005848.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d5.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005849.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61176.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005850.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d7.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005851.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61178.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005852.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61177.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005853.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d8.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005854.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61179.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005855.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3da.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005856.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3d9.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005857.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6117a.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005858.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3db.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005859.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6117b.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005860.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3dc.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005861.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6117d.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005862.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3de.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005863.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6117c.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005864.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3dd.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005865.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6117e.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005866.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba3df.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005867.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c6117f.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005868.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '485ba320.qua'!&lt;BR&gt;E:\System Volume Information\_restore{E0F2DC9D-D381-4410-99DC-0D176B4ABAD0}\RP47\A0005869.exe&lt;BR&gt;      [DETECTION] Contains detection pattern of the worm WORM/VB.AS.21&lt;BR&gt;      [NOTE]      The file was moved to '49c61181.qua'!&lt;/P&gt;&lt;P&gt;&lt;BR&gt;End of the scan: 2008-05-14  19:45&lt;BR&gt;Used time: 23:12 min&lt;/P&gt;&lt;P&gt;The scan has been done completely.&lt;/P&gt;&lt;P&gt;   5081 Scanning directories&lt;BR&gt; 105053 Files were scanned&lt;BR&gt;    265 viruses and/or unwanted programs were found&lt;BR&gt;      0 Files were classified as suspicious:&lt;BR&gt;      0 files were deleted&lt;BR&gt;      0 files were repaired&lt;BR&gt;    264 files were moved to quarantine&lt;BR&gt;      0 files were renamed&lt;BR&gt;      2 Files cannot be scanned&lt;BR&gt; 104788 Files not concerned&lt;BR&gt;    670 Archives were scanned&lt;BR&gt;      2 Warnings&lt;BR&gt;    264 Notes&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 19:46, on 2008-05-14&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Winamp\winampa.exe&lt;BR&gt;C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe&lt;BR&gt;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&lt;BR&gt;C:\Program Files\USB Disk Security\USBGuard.exe&lt;BR&gt;C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe&lt;BR&gt;C:\WINDOWS\system32\Rundll32.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\Program Files\Windows Sidebar\sidebar.exe&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;C:\Program Files\Windows Sidebar\sidebar.exe&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;BR&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;BR&gt;O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll&lt;BR&gt;O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe&lt;BR&gt;O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [USB Antivirus] C:\Program Files\USB Disk Security\USBGuard.exe&lt;BR&gt;O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r&lt;BR&gt;O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun&lt;BR&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Default user')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')&lt;BR&gt;O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;BR&gt;O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html&lt;BR&gt;O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html&lt;BR&gt;O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 7838 bytes&lt;BR&gt;</description><pubDate>Fri, 16 May 2008 22:06:30 GMT</pubDate><dc:creator>sha_eddie</dc:creator></item><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>Please download/install [b]Avira AntiVir Personal - FREE Antivirus[/b]: &lt;br&gt;[url]http://www.free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html[/url]&lt;br&gt;Perform a full scan with Avira and allow it to delete everything it detects.&lt;br&gt;[b]Restart your pc when you've done.[/b]&lt;br&gt;After restart,open Avira Antivirus and select "Reports".&lt;br&gt;Then double click the report from the full scan you have just completed. &lt;br&gt;Click the "Report File" button,then [b]copy and paste the report into your next reply[/b].&lt;br&gt;&lt;br&gt;&lt;br&gt;Download and scan with [b][color="red"]CCleaner[/color][/b]:&lt;br&gt;[url]http://www.ccleaner.com/downloadbuilds.asp[/url]&lt;br&gt;1. Starting with v1.27.260, CCleaner installs the [b]Yahoo Toolbar[/b] as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free Basic or Slim versions instead of the Standard Build.&lt;br&gt;&lt;br&gt;2. Before first use, select Options &gt; Advanced and UNCHECK [b]"Only delete files in Windows Temp folder older than 48 hours"[/b]&lt;br&gt;&lt;br&gt;3. Then select the items you wish to clean up.&lt;br&gt;&lt;br&gt;[b]In the Windows Tab:[/b]&lt;br&gt;* Clean all entries in the "Internet Explorer" section except Cookies.&lt;br&gt;* Clean all the entries in the "Windows Explorer" section.&lt;br&gt;* Clean all entries in the "System" section.&lt;br&gt;* Clean all entries in the "Advanced" section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;[b]In the Applications Tab:[/b]&lt;br&gt;* Clean all except cookies in the Firefox/Mozilla section if you use it.&lt;br&gt;* Clean all in the Opera section if you use it.&lt;br&gt;* Clean Sun Java in the Internet Section.&lt;br&gt;* Clean any others that you choose.&lt;br&gt;&lt;br&gt;4. Click the "Run Cleaner" button.&lt;br&gt;5. A pop up box will appear advising this process will permanently delete files from your system.&lt;br&gt;6. Click "OK" and it will scan and clean your system.&lt;br&gt;7. Click "Exit" when done.&lt;br&gt;&lt;br&gt;&lt;br&gt;Download\install [b]'SuperAntiSpyware Free Version Home Users'[/b] from here:&lt;br&gt;[URL]http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE[/URL]&lt;br&gt;&lt;br&gt;Launch SuperAntiSpyware and click on 'Check for updates'.&lt;br&gt;If you encounter any error messages while downloading the updates,manually download them from [B][URL=http://www.superantispyware.com/definitions.html][COLOR="BLUE"]Here[/COLOR][/URL][/B].&lt;br&gt;Once the updates have been installed,on the main screen click on 'Scan your computer'.&lt;br&gt;Check: 'Perform Complete Scan'.&lt;br&gt;Click 'Next' to start the scan.&lt;br&gt;&lt;br&gt;Superantispyware will now scan your computer,when it's finished it will list all/any infections found.&lt;br&gt;Make sure everything found has a checkmark next to it,then press 'Next'.&lt;br&gt;Click on 'Finish' when you've done.&lt;br&gt;&lt;br&gt;It's possible that the program will ask you to reboot in order to delete some files.&lt;br&gt;&lt;br&gt;Obtain the SuperAntiSpyware log as follows:&lt;br&gt;Click on 'Preferences'.&lt;br&gt;Click on the 'Statistics/Logs' tab.&lt;br&gt;Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.&lt;br&gt;It will then open in your default text editor,such as Notepad.&lt;br&gt;[b]Copy and paste the contents of that report into your next reply.&lt;br&gt;Also post a new Hijackthis log,let me know how your pc is running now.[/b]</description><pubDate>Fri, 16 May 2008 02:47:24 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>Sorry! Here it is&lt;/P&gt;&lt;P&gt;Hijack This&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 14:46, on 2008-05-14&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\Program Files\Winamp\winampa.exe&lt;BR&gt;C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe&lt;BR&gt;C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe&lt;BR&gt;C:\Program Files\USB Disk Security\USBGuard.exe&lt;BR&gt;C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe&lt;BR&gt;C:\WINDOWS\system32\Rundll32.exe&lt;BR&gt;C:\Program Files\Windows Sidebar\sidebar.exe&lt;BR&gt;C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe&lt;BR&gt;C:\Program Files\Windows Sidebar\sidebar.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll&lt;BR&gt;O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;BR&gt;O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll&lt;BR&gt;O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe&lt;BR&gt;O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"&lt;BR&gt;O4 - HKLM\..\Run: [USB Antivirus] C:\Program Files\USB Disk Security\USBGuard.exe&lt;BR&gt;O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r&lt;BR&gt;O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper&lt;BR&gt;O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE&lt;BR&gt;O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Default user')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')&lt;BR&gt;O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe&lt;BR&gt;O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?&lt;BR&gt;O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE&lt;BR&gt;O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html&lt;BR&gt;O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html&lt;BR&gt;O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html&lt;BR&gt;O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 6559 bytes&lt;BR&gt;</description><pubDate>Thu, 15 May 2008 20:20:43 GMT</pubDate><dc:creator>sha_eddie</dc:creator></item><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>Post the new Hijackthis log as requested if you will.</description><pubDate>Thu, 15 May 2008 02:40:13 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>ComboFix 08-05-12.1 - Admin 2008-05-14 13:38:26.1 - NTFSx86&lt;BR&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.563 [GMT -7:00]&lt;BR&gt;Running from: C:\Documents and Settings\Admin\desktop\ComboFix.exe&lt;BR&gt;Command switches used :: /killall&lt;BR&gt; * Created a new restore point&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\Admin\Application Data\inst.exe&lt;BR&gt;C:\Documents and Settings\Admin\Desktop\sha\ISO\_desktop.ini&lt;BR&gt;C:\WINDOWS\dc.exe&lt;BR&gt;C:\WINDOWS\help\Other.exe&lt;BR&gt;C:\WINDOWS\inf\Other.exe&lt;BR&gt;C:\WINDOWS\sviq.exe&lt;BR&gt;C:\WINDOWS\system\Fun.exe&lt;BR&gt;C:\WINDOWS\system32\config\Win.exe&lt;BR&gt;C:\WINDOWS\system32\msvcsv60.dll&lt;BR&gt;C:\WINDOWS\system32\Penx.dat&lt;BR&gt;C:\WINDOWS\system32\WinSit.exe&lt;BR&gt;C:\WINDOWS\system32\Xpen.dat&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-14 to 2008-05-14  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-14 13:29 . 2008-05-14 13:29 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\xircom&lt;BR&gt;2008-05-14 13:29 . 2008-05-14 13:29 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\microsoft frontpage&lt;BR&gt;2008-05-14 13:23 . 2008-05-14 13:23 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\ERUNT&lt;BR&gt;2008-05-14 13:17 . 2008-05-14 13:31 &amp;lt;DIR&amp;gt; d-------- C:\SDFix&lt;BR&gt;2008-05-13 12:00 . 2008-05-13 12:00 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\ASIO4ALL v2&lt;BR&gt;2008-05-11 20:52 . 2008-05-11 20:52 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\directx&lt;BR&gt;2008-05-11 20:52 . 2008-05-11 20:52 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Admin\Application Data\ArcSoft&lt;BR&gt;2008-05-11 20:52 . 1998-09-02 01:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll&lt;BR&gt;2008-05-11 20:52 . 1998-08-26 21:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll&lt;BR&gt;2008-05-11 20:52 . 1998-08-20 04:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax&lt;BR&gt;2008-05-11 20:52 . 1998-09-02 01:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe&lt;BR&gt;2008-05-11 20:52 . 1998-09-02 01:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll&lt;BR&gt;2008-05-11 20:52 . 1998-08-17 02:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv&lt;BR&gt;2008-05-11 20:52 . 1998-08-17 02:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll&lt;BR&gt;2008-05-11 20:52 . 1998-08-17 02:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd&lt;BR&gt;2008-05-11 20:52 . 2008-05-11 20:52 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll&lt;BR&gt;2008-05-11 20:52 . 2008-05-11 20:52 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll&lt;BR&gt;2008-05-11 20:51 . 2008-05-11 20:51 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\ArcSoft&lt;BR&gt;2008-05-11 20:51 . 1999-05-26 09:46 212,480 --a------ C:\WINDOWS\pcdlib32.dll&lt;BR&gt;2008-05-11 20:51 . 2001-10-16 11:23 163,840 --a------ C:\WINDOWS\system32\PhotoImpression Screen Saver.scr&lt;BR&gt;2008-05-11 20:51 . 2001-06-07 16:27 21 --a------ C:\WINDOWS\CS_setup.ini&lt;BR&gt;2008-05-11 18:15 . 2000-12-12 19:21 7,572,224 --------- C:\WINDOWS\system32\CT8MGM.SF2&lt;BR&gt;2008-05-11 18:15 . 2000-12-04 18:11 4,174,814 --------- C:\WINDOWS\system32\CT4MGM.SF2&lt;BR&gt;2008-05-11 18:15 . 1999-09-22 00:18 2,167,684 -ra------ C:\WINDOWS\system32\ct2mgm.sf2&lt;BR&gt;2008-05-11 18:15 . 2005-06-27 03:37 133,632 -ra------ C:\WINDOWS\system32\CtDvInst.dll&lt;BR&gt;2008-05-11 18:15 . 2000-05-11 01:00 90,112 --------- C:\WINDOWS\Updreg.EXE&lt;BR&gt;2008-05-11 18:15 . 2005-07-07 02:26 5,627 -ra------ C:\WINDOWS\system32\Ludap17.ini&lt;BR&gt;2008-05-11 18:15 . 2005-03-07 23:14 39 -ra------ C:\WINDOWS\system32\ctzapxx.ini&lt;BR&gt;2008-05-11 18:11 . 2008-05-11 18:11 29 --a------ C:\WINDOWS\sfbm.INI&lt;BR&gt;2008-05-11 00:20 . 2007-07-20 14:30 14,208 --a------ C:\WINDOWS\system32\drivers\voxthing.sys&lt;BR&gt;2008-05-10 23:32 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll&lt;BR&gt;2008-05-10 23:32 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys&lt;BR&gt;2008-05-10 23:32 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll&lt;BR&gt;2008-05-10 23:28 . 2008-05-10 23:30 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Winamp&lt;BR&gt;2008-05-10 23:28 . 2008-05-10 23:29 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Admin\Application Data\Winamp&lt;BR&gt;2008-05-10 23:17 . 2008-05-10 23:18 &amp;lt;DIR&amp;gt; d-------- C:\InDesignCS2_Setup&lt;BR&gt;2008-05-09 23:24 . 2008-05-11 21:21 &amp;lt;DIR&amp;gt; d-------- C:\Recording&lt;BR&gt;2008-05-08 23:02 . 2008-05-08 23:03 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Hamster Ball&lt;BR&gt;2008-05-08 21:59 . 2008-05-08 21:59 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\DiskTrix&lt;BR&gt;2008-05-08 20:25 . 2008-05-08 20:25 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\inKline Global&lt;BR&gt;2008-05-03 00:44 . 2008-05-03 00:44 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\TuneUp Utilities 2008&lt;BR&gt;2008-05-03 00:44 . 2008-05-03 00:44 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Wise Installation Wizard&lt;BR&gt;2008-05-03 00:44 . 2008-05-03 00:44 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe&lt;BR&gt;2008-05-03 00:44 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll&lt;BR&gt;2008-05-03 00:35 . 2008-05-08 22:05 65,552 --a------ C:\WINDOWS\system32\KeOS386.DLL&lt;BR&gt;2008-05-02 13:44 . 2008-05-04 00:39 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\PC Washer&lt;BR&gt;2008-05-02 13:40 . 2008-05-02 13:40 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\USB Disk Security&lt;BR&gt;2008-05-02 13:37 . 2006-09-29 12:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll&lt;BR&gt;2008-05-02 13:37 . 2006-09-29 12:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll&lt;BR&gt;2008-05-02 13:37 . 2006-09-29 12:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll&lt;BR&gt;2008-05-02 13:37 . 2007-03-18 20:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll&lt;BR&gt;2008-05-02 13:36 . 2008-05-02 13:37 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\VSO&lt;BR&gt;2008-05-02 13:36 . 2004-05-04 11:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll&lt;BR&gt;2008-05-02 13:36 . 2006-05-20 16:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll&lt;BR&gt;2008-05-02 13:36 . 2006-05-11 19:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll&lt;BR&gt;2008-05-02 12:55 . 2008-05-02 12:55 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\MP3 Player Utilities 3.5.02&lt;BR&gt;2008-05-02 12:55 . 2005-11-09 02:57 9,277 -ra------ C:\WINDOWS\AmvTransform.ini&lt;BR&gt;2008-05-02 12:55 . 2005-10-20 23:32 8,913 -ra------ C:\WINDOWS\fwupgrade.ini&lt;BR&gt;2008-05-02 12:55 . 2005-09-15 02:40 8,157 -ra------ C:\WINDOWS\AmvPlayer.ini&lt;BR&gt;2008-05-02 12:55 . 2005-10-20 23:24 7,454 -ra------ C:\WINDOWS\Disktool.INI&lt;BR&gt;2008-05-02 12:55 . 2004-05-11 22:28 3,677 -ra------ C:\WINDOWS\SoundCon.INI&lt;BR&gt;2008-05-02 12:55 . 2005-09-14 20:28 170 -ra------ C:\WINDOWS\settings.ini&lt;BR&gt;2008-05-01 23:06 . 2008-05-01 23:06 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Admin\Application Data\AdobeUM&lt;BR&gt;2008-05-01 17:52 . 2008-05-01 17:52 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems&lt;BR&gt;2008-05-01 17:51 . 2008-05-01 17:51 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Adobe Systems Shared&lt;BR&gt;2008-05-01 17:50 . 2008-05-10 23:19 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Adobe&lt;BR&gt;2008-05-01 16:51 . 2008-05-01 16:51 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\PT Atlantis Programma Prima&lt;BR&gt;2008-05-01 16:51 . 2008-05-01 16:51 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\COD10&lt;BR&gt;2008-05-01 16:50 . 2004-09-02 22:32 269,824 --a------ C:\WINDOWS\uninst.exe&lt;BR&gt;2008-05-01 16:49 . 2008-05-01 16:49 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\OpenSys&lt;BR&gt;2008-05-01 16:49 . 2008-05-01 16:49 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\OpenSys&lt;BR&gt;2008-05-01 16:49 . 1998-06-26 20:22 205,848 --a------ C:\WINDOWS\system32\Threed32.ocx&lt;BR&gt;2008-05-01 16:49 . 1997-07-19 16:01 196,880 --a------ C:\WINDOWS\system32\Richtx32.ocx&lt;BR&gt;2008-05-01 13:43 . 2008-05-01 13:43 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software&lt;BR&gt;2008-05-01 13:43 . 2008-05-01 13:43 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Admin\Application Data\TuneUp Software&lt;BR&gt;2008-05-01 13:38 . 2008-05-01 13:38 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Arturia&lt;BR&gt;2008-05-01 13:38 . 2003-02-24 17:27 151,552 --a------ C:\WINDOWS\system32\FDlg.dll&lt;BR&gt;2008-05-01 13:33 . 2008-05-01 13:33 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Total Video Converter&lt;BR&gt;2008-05-01 13:23 . 2008-05-01 16:39 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro&lt;BR&gt;2008-05-01 13:21 . 2008-05-12 19:06 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Trend Micro&lt;BR&gt;2008-05-01 13:14 . 2008-05-01 13:14 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SpectralDesign&lt;BR&gt;2008-05-01 13:12 . 2008-05-01 13:12 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\YAMAHA&lt;BR&gt;2008-05-01 13:09 . 2008-05-13 11:54 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Antares Audio Technologies&lt;BR&gt;2008-05-01 12:33 . 2008-05-01 12:33 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle&lt;BR&gt;2008-05-01 12:31 . 2008-05-01 12:31 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\VOB&lt;BR&gt;2008-05-01 12:31 . 2002-08-28 11:09 611,840 --a------ C:\WINDOWS\system32\vobhw.dll&lt;BR&gt;2008-05-01 12:31 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe&lt;BR&gt;2008-05-01 12:31 . 2002-09-26 17:34 153,088 --a------ C:\WINDOWS\system32\IWUninstall.exe&lt;BR&gt;2008-05-01 12:31 . 2000-04-27 12:31 19,456 --a------ C:\WINDOWS\system32\asapi.dll&lt;BR&gt;2008-05-01 12:31 . 2002-04-17 20:27 11,264 --a------ C:\WINDOWS\system32\drivers\asapi.sys&lt;BR&gt;2008-05-01 12:30 . 2008-05-01 12:30 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Admin\WINDOWS&lt;BR&gt;2008-05-01 12:28 . 2008-05-01 12:28 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Nomad Factory&lt;BR&gt;2008-05-01 12:28 . 2003-03-18 20:04 765,952 --a------ C:\WINDOWS\system32\msvcp71d.dll&lt;BR&gt;2008-05-01 12:28 . 2003-03-18 20:03 544,768 --a------ C:\WINDOWS\system32\msvcr71d.dll&lt;BR&gt;2008-05-01 12:05 . 2008-05-01 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Native Instruments&lt;BR&gt;2008-05-01 12:05 . 2004-09-30 13:13 233,472 --a------ C:\WINDOWS\system32\REX Shared Library.dll&lt;BR&gt;2008-05-01 11:48 . 2008-05-13 14:27 116 --a------ C:\WINDOWS\NeroDigital.ini&lt;BR&gt;2008-05-01 11:08 . 2008-05-01 11:08 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Bome's Mouse Keyboard&lt;BR&gt;2008-05-01 11:08 . 2008-05-01 11:08 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Admin\Application Data\Propellerhead Software&lt;BR&gt;2008-05-01 10:52 . 2008-05-01 10:54 &amp;lt;DIR&amp;gt; d-------- C:\Audio&lt;BR&gt;2008-05-01 10:52 . 2008-05-13 13:51 32 --a------ C:\WINDOWS\system32\w3data.vss&lt;BR&gt;2008-05-01 10:52 . 2008-05-13 13:51 32 --a------ C:\WINDOWS\msocreg32.dat&lt;BR&gt;2008-05-01 10:51 . 2008-05-01 14:16 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\IK Multimedia&lt;BR&gt;2008-05-01 10:51 . 2008-05-01 10:51 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Admin\Application Data\InstallShield&lt;BR&gt;2008-05-01 10:51 . 2006-11-27 12:29 189 --a------ C:\WINDOWS\system32\.MySCMServerInfo&lt;BR&gt;2008-05-01 10:47 . 2008-05-01 10:47 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Admin\Application Data\Steinberg&lt;BR&gt;2008-05-01 10:43 . 2008-05-01 12:29 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Steinberg&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:08 487,936 --a------ C:\WINDOWS\system32\rmbe3260.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:09 352,768 --a------ C:\WINDOWS\system32\pngu3263.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:09 131,072 --a------ C:\WINDOWS\system32\pneng50.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:09 130,560 --a------ C:\WINDOWS\system32\pnc3250.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:08 87,040 --a------ C:\WINDOWS\system32\ra32sipr.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:11 85,504 --a------ C:\WINDOWS\system32\encdnet.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:09 81,920 --a------ C:\WINDOWS\system32\ra3214_4.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:09 72,704 --a------ C:\WINDOWS\system32\ra3228_8.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:09 61,952 --a------ C:\WINDOWS\system32\decdnet.dll&lt;BR&gt;2008-05-01 10:43 . 2005-06-04 09:09 21,504 --a------ C:\WINDOWS\system32\ra32dnet.dll&lt;BR&gt;2008-05-01 10:41 . 2008-05-01 10:41 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Syncrosoft&lt;BR&gt;2008-05-01 10:41 . 2005-02-01 04:34 700,416 --a------ C:\WINDOWS\system32\SYNSOACC.dll&lt;BR&gt;2008-05-01 10:41 . 2004-05-11 00:58 147,456 --a------ C:\WINDOWS\system32\SynsoLChk.dll&lt;BR&gt;2008-05-01 10:41 . 2003-08-01 05:28 147,425 --a------ C:\WINDOWS\system32\SYNSOACC-Aide.chm&lt;BR&gt;2008-05-01 10:41 . 2003-05-27 00:29 120,468 --a------ C:\WINDOWS\system32\SYNSOACC-Hilfe.chm&lt;BR&gt;2008-05-01 10:41 . 2003-05-27 00:29 114,279 --a------ C:\WINDOWS\system32\SYNSOACC-Help.chm&lt;BR&gt;2008-05-01 10:41 . 2002-11-25 17:36 45,056 --a------ C:\WINDOWS\system32\Synsopos.exe&lt;BR&gt;2008-05-01 10:41 . 2005-05-09 20:08 33,792 --a------ C:\WINDOWS\system32\drivers\cledx.sys&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-05-01 07:25 --------- d-----w C:\Program Files\Windows Sidebar&lt;BR&gt;2008-05-01 07:25 --------- d-----w C:\Program Files\Utilities&lt;BR&gt;2008-05-01 07:25 --------- d-----w C:\Program Files\nLite&lt;BR&gt;2008-03-05 23:03 479,752 ----a-w C:\WINDOWS\system32\XAudio2_0.dll&lt;BR&gt;2008-03-05 23:03 238,088 ----a-w C:\WINDOWS\system32\xactengine3_0.dll&lt;BR&gt;2008-03-05 23:00 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_3.dll&lt;BR&gt;2008-03-05 22:56 3,786,760 ----a-w C:\WINDOWS\system32\D3DX9_37.dll&lt;BR&gt;2008-03-05 22:56 1,420,824 ----a-w C:\WINDOWS\system32\D3DCompiler_37.dll&lt;BR&gt;2006-11-29 13:26 28,160 ----a-w C:\WINDOWS\inf\MEDIAINF\myokent.dll&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;------- Sigcheck -------&lt;/P&gt;&lt;P&gt;2007-01-05 23:31  360576  e7dfcffa380749b8626ad71e8f367dcb C:\WINDOWS\system32\drivers\tcpip.sys&lt;BR&gt;.&lt;BR&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2007-01-04 19:30 1253376]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 11:49 36352]&lt;BR&gt;"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]&lt;BR&gt;"H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2005-05-11 02:46 200069]&lt;BR&gt;"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]&lt;BR&gt;"USB Antivirus"="C:\Program Files\USB Disk Security\USBGuard.exe" [2008-04-01 15:10 798720]&lt;BR&gt;"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 10:51 57344]&lt;BR&gt;"P17Helper"="P17.dll" [2005-05-03 04:38 64512 C:\WINDOWS\system32\P17.dll]&lt;BR&gt;"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]&lt;/P&gt;&lt;P&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2007-01-04 19:30 1253376]&lt;/P&gt;&lt;P&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]&lt;BR&gt;"nltide3"="cmd.exe" [2004-08-03 21:00 388608 C:\WINDOWS\system32\cmd.exe]&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\Admin\Start Menu\Programs\Startup\&lt;BR&gt;Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\All Users\Start Menu\Programs\Startup\&lt;BR&gt;Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-05-01 17:51:29 25214]&lt;BR&gt;Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]&lt;BR&gt;"ForceClassicControlPanel"= 1 (0x1)&lt;BR&gt;"NoResolveTrack"= 1 (0x1)&lt;BR&gt;"NoResolveSearch"= 1 (0x1)&lt;BR&gt;"ForceStartMenuLogoff"= 0 (0x0)&lt;BR&gt;"NoStartMenuPinnedList"= 1 (0x1)&lt;BR&gt;"NoSMConfigurePrograms"= 1 (0x1)&lt;BR&gt;"NoUserNameInStartMenu"= 1 (0x1)&lt;/P&gt;&lt;P&gt;[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]&lt;BR&gt;"ForceClassicControlPanel"= 1 (0x1)&lt;BR&gt;"NoResolveTrack"= 1 (0x1)&lt;BR&gt;"NoResolveSearch"= 1 (0x1)&lt;BR&gt;"NoSMHelp"= 1 (0x1)&lt;BR&gt;"StartMenuLogoff"= 1 (0x1)&lt;BR&gt;"ForceStartMenuLogoff"= 0 (0x0)&lt;BR&gt;"NoStartMenuPinnedList"= 1 (0x1)&lt;BR&gt;"NoSMConfigurePrograms"= 1 (0x1)&lt;BR&gt;"NoUserNameInStartMenu"= 1 (0x1)&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]&lt;BR&gt;"VIDC.ACDV"= ACDV.dll&lt;BR&gt;"MIDI1"= myokent.dll&lt;BR&gt;"MIDI2"= myokent.dll&lt;BR&gt;"MIDI3"= myokent.dll&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"=&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;/P&gt;&lt;P&gt;R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-22 20:38]&lt;BR&gt;R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-22 20:39]&lt;BR&gt;R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2002-04-17 20:27]&lt;BR&gt;R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-03 21:00]&lt;BR&gt;R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]&lt;BR&gt;R3 voxthing;Voice Thing service;C:\WINDOWS\system32\drivers\voxthing.sys [2007-07-20 14:30]&lt;BR&gt;S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-03 00:44]&lt;/P&gt;&lt;P&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs&lt;BR&gt;UxTuneUp&lt;/P&gt;&lt;P&gt;&lt;BR&gt;[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Windows Sidebar]&lt;BR&gt;C:\WINDOWS\system32\hidec /W C:\VAIO\Tools\REGTLIB.EXE "C:\Program Files\Windows Sidebar\sidebar.exe"&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]&lt;BR&gt;"C:\Program Files\Windows Sidebar\.\regsvr32.exe" /s wlsrvc.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]&lt;BR&gt;"C:\Program Files\Windows Sidebar\.\regsvr32.exe" /s sbdrop.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BADA65A0-86B7-462B-B720-CE66655C73F5}]&lt;BR&gt;regsvr32 /s C:\VAIO\.\vshellext.dll&lt;BR&gt;.&lt;BR&gt;Contents of the 'Scheduled Tasks' folder&lt;BR&gt;"2008-05-03 07:44:57 C:\WINDOWS\Tasks\1-Click Maintenance.job"&lt;BR&gt;- C:\Program Files\TuneUp Utilities 2008\OneClick.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-14 13:40:25&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;------------------------ Other Running Processes ------------------------&lt;BR&gt;.&lt;BR&gt;C:\WINDOWS\system32\wdfmgr.exe&lt;BR&gt;C:\WINDOWS\system32\wscntfy.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-14 13:41:47 - machine was rebooted&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-14 20:41:41&lt;/P&gt;&lt;P&gt;Pre-Run: 70,728,728,576 bytes free&lt;BR&gt;Post-Run: 70,719,471,616 bytes free&lt;/P&gt;&lt;P&gt;262&lt;BR&gt;&lt;/P&gt;&lt;P&gt;&lt;BR&gt;[b]SDFix: Version 1.182 [/b]&lt;BR&gt;Run by Admin on Wed 05/14/2008 at 01:26 PM&lt;/P&gt;&lt;P&gt;Microsoft Windows XP [Version 5.1.2600]&lt;BR&gt;Running From: C:\SDFix&lt;/P&gt;&lt;P&gt;[b]Checking Services [/b]:&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Restoring Windows Registry Values&lt;BR&gt;Restoring Windows Default Hosts File&lt;/P&gt;&lt;P&gt;Rebooting&lt;/P&gt;&lt;P&gt;&lt;BR&gt;[b]Checking Files [/b]: &lt;/P&gt;&lt;P&gt;Trojan Files Found:&lt;/P&gt;&lt;P&gt;C:\WINDOWS\nvchost.exe  - Deleted&lt;BR&gt;C:\WINDOWS\winlogon.exe  - Deleted&lt;/P&gt;&lt;P&gt;Removing Temp Files&lt;/P&gt;&lt;P&gt;[b]ADS Check [/b]:&lt;BR&gt; &lt;/P&gt;&lt;P&gt;&lt;BR&gt;                                 [b]Final Check [/b]:&lt;/P&gt;&lt;P&gt;catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-14 13:30:26&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ...&lt;/P&gt;&lt;P&gt;scanning hidden services &amp;amp; system hive ...&lt;/P&gt;&lt;P&gt;scanning hidden registry entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ...&lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden processes: 0&lt;BR&gt;hidden services: 0&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;&lt;BR&gt;[b]Remaining Services [/b]:&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Authorized Application Key Export:&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]&lt;BR&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]&lt;BR&gt;"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"&lt;/P&gt;&lt;P&gt;[b]Remaining Files [/b]:&lt;/P&gt;&lt;P&gt;&lt;BR&gt;File Backups: - C:\SDFix\backups\backups.zip&lt;/P&gt;&lt;P&gt;[b]Files with Hidden Attributes [/b]:&lt;/P&gt;&lt;P&gt;Sun 21 Jul 2002       418,816 ...HR --- "C:\WINDOWS\system32\Tools\All.exe"&lt;BR&gt;Thu 18 Jul 2002       390,144 ...HR --- "C:\WINDOWS\system32\Tools\Change.exe"&lt;BR&gt;Fri 19 Jul 2002       574,464 ...HR --- "C:\WINDOWS\system32\Tools\CheckPath.exe"&lt;BR&gt;Mon 19 Aug 2002       430,592 ...HR --- "C:\WINDOWS\system32\Tools\Counter.exe"&lt;BR&gt;Mon 22 Jul 2002       390,656 ...HR --- "C:\WINDOWS\system32\Tools\DelFolders.exe"&lt;BR&gt;Fri 22 Nov 2002       399,872 ...HR --- "C:\WINDOWS\system32\Tools\DirectSetup.exe"&lt;BR&gt;Fri 19 Jul 2002       388,096 ...HR --- "C:\WINDOWS\system32\Tools\RegClean.exe"&lt;BR&gt;Fri 19 Jul 2002       388,608 ...HR --- "C:\WINDOWS\system32\Tools\Regexe.exe"&lt;BR&gt;Sun  1 Dec 2002       431,616 ...HR --- "C:\WINDOWS\system32\Tools\Restart.exe"&lt;BR&gt;Fri 19 Jul 2002       388,096 ...HR --- "C:\WINDOWS\system32\Tools\RunRegexe.exe"&lt;BR&gt;Sun  9 Mar 2008         1,536 A..H. --- "C:\Documents and Settings\All Users\Desktop\KEYGENS FOR PROGRAMS\Antares VoiceThing 1.0\Softwrap.dll"&lt;BR&gt;Sun  9 Mar 2008         1,536 A..H. --- "C:\Documents and Settings\All Users\Desktop\KEYGENS FOR PROGRAMS\vst\Antares VoiceThing 1.0\Softwrap.dll"&lt;/P&gt;&lt;P&gt;[b]Finished![/b]</description><pubDate>Wed, 14 May 2008 20:33:18 GMT</pubDate><dc:creator>sha_eddie</dc:creator></item><item><title>RE: svchost.exe  what is this! Am i in danger?[home PC without Internet]</title><link>http://forum.tweaks.com/forum/Topic239363-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;Download [b]SDFix.exe[/b] and save it to your desktop:&lt;br&gt;[url]http://downloads.andymanchesta.com/RemovalTools/SDFix.exe[/url]&lt;br&gt;&lt;br&gt;* Double click on SDFix on your desktop,and install the fix to [b]C:\[/b]&lt;br&gt;&lt;br&gt;* [COLOR="blue"][i]You might want to print/copy the following as you need to be in Safe Mode from here on.[/i][/color] &lt;br&gt;&lt;br&gt;* Please then reboot your computer into Safe Mode by doing the following:&lt;br&gt;* Restart your computer&lt;br&gt;* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;&lt;br&gt;* Instead of Windows loading as normal, a menu with options should appear;&lt;br&gt;* Select the first option, to run Windows in Safe Mode, then press "Enter".&lt;br&gt;* Choose your usual account.&lt;br&gt;&lt;br&gt;* In Safe Mode,go to and open the C:\[b]SDFix[/b] folder,then double click on [b]RunThis.bat[/b] to start the script.&lt;br&gt;* Type [b]Y[/b] to begin the script.&lt;br&gt;* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.&lt;br&gt;* Press any Key and it will restart the PC.&lt;br&gt;* Your system will take longer that normal to restart as the fixtool will be running and removing files.&lt;br&gt;* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.&lt;br&gt;[b]* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;[b]If you have previously downloaded ComboFix,please delete that version now.[/b]&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;Close any open browsers. &lt;br&gt;Click on Start/Run,copy and paste the following bold text into the '[u]O[/u]pen:' space,then press OK [See image below]:&lt;br&gt;[b]"%userprofile%\desktop\combofix.exe" /killall[/b]&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/killall.gif[/IMG]&lt;br&gt;&lt;br&gt;Combofix.exe will start,please follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b]: &lt;br&gt;Do not mouseclick combofix's window while it's running. &lt;br&gt;That may cause the program to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b]*Note*[/b]&lt;br&gt;In case your Antivirus or any other realti