Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Please help: Braviax.exe and his friends >__<
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Please help: Braviax.exe and his friends >__<  
Forum Quick Jump
 
New Topic Post reply to : Please help: Braviax.exe and his friends >__< Printable version of : Please help: Braviax.exe and his friends >__<
[ << Previous Thread | Next Thread >> ]

jadesphere
New Member


Date Joined Sep 2009
Total Posts : 5
 
   Posted 9-4-2009 8:02 (GMT +1)    Quote: Please help: Braviax.exe and his friends >__<Alert an admin about: Please help: Braviax.exe and his friends >__<
Got infected on 9/1 and have tried SDFIX, MBAM, Spybot S&D, HJThis fixes among others but to no avail. What seems like success has ended with reinfection when connecting internet cable to PC. Hopefully I haven't created a huge mess, and your trained eyes can still provide support.

I saved combofix as "alg.exe". And ran ComboFix, which appeared to be working fine until running into a problem at the very end when attempting to generate a log file. Notepad pops up and a window says "Cannot find the \ComboFix.txt file. Do you want to create a new file?" When I click yes nothing happens and I am left with a blank notepad. Also interestingly, the Combofix which i had saved as "alg.exe" reverts back to "Combofix" on the desktop.

Ps. I clicked no for installing the Microsoft windows recovery console part, is that the issue?
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16754
 
   Posted 9-4-2009 8:34 (GMT +1)    Quote: Please help: Braviax.exe and his friends >__<Alert an admin about: Please help: Braviax.exe and his friends >__<
Hello jadeshere.

Run combofix again - from safe mode, and see if it wil produce a log. If it do, please post it.

"Also interestingly, the Combofix which i had saved as "alg.exe" reverts back to "Combofix" on the desktop"

It is also supposed to ;-)


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

jadesphere
New Member


Date Joined Sep 2009
Total Posts : 5
 
   Posted 9-4-2009 9:11 (GMT +1)    Quote: Please help: Braviax.exe and his friends >__<Alert an admin about: Please help: Braviax.exe and his friends >__<
Greeting Touch~

Thank you in advance for helping me. I am hopeful and looking forward to your guidance.

1. With my network cable disconnected, I ran combofix in SafeMode and it was quickly interrupted by a pop up window stating "ComboFix is uninstalled". I click "Ok" and the file is removed from the desktop shocked

2. I tried downloading combofix again. But this time I saved is as "alg1". Previously, I had saved as combofix and renamed file to alg when dragging to desktop. The 2nd try worked! Unfortunately, the computer restarted in normal mode, and gets snagged by the "Cannot find the \ComboFix.txt file. Do you want to create a new file?" when combofix tries to create log file. >__< I will try to force a safemode load after combofix restarts system to see if that will resolve issue.

3. From what I saw on the screen, it looks like my infections consist of braviax/cru629/beep/wisd* something.

4. As it is getting late, I will post this update for now, and the combofix log shortly if the safe mode restart method is successful.

5. I will be likely home tomorrow at 5-6pm PST for more thorough updates/investigation if you happen to be available as well.

--------------------------------------------
Back to Top
 

jadesphere
New Member


Date Joined Sep 2009
Total Posts : 5
 
   Posted 9-4-2009 9:36 (GMT +1)    Quote: Please help: Braviax.exe and his friends >__<Alert an admin about: Please help: Braviax.exe and his friends >__<
Ack, so this time in safe mode it didn't restart but met the same error when attempting to create a log at the end of the scan. "Cannot find the \ComboFix.txt file. Do you want to create a new file?" Clicking yes/no/cancel all ends up with a blank opened txt file titled ComboFix. I tried pasting (control V) but nothing on the clipboard.

I did see an odd directory C:\Qoobox which had the following files:
Folder: BackEnv
Folder: Quarantine
txt: Add-remove Programs
txt: ComboFix-quarantined-files
file: LogA
Dat: SnapShot@2009-09-04_08.02.18

The timestamps on these files seem to match a few minutes after I completed scan so I think they are related. Here is what was in the combofix quarantined files txt:


2009-09-04 07:59:24 . 2009-09-04 08:14:44 13,446 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-09-04 07:54:01 . 2009-09-04 08:10:50 308 ----a-w- C:\Qoobox\Quarantine\catchme.log
2009-09-04 07:42:39 . 2009-09-04 07:51:30 6,144 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\cru629.dat.vir
2009-09-04 07:42:39 . 2009-09-04 07:51:30 6,144 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\cru629.dat.vir
2009-09-04 07:42:39 . 2009-09-04 07:51:30 11,264 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\braviax.exe.vir
2009-09-04 07:40:29 . 2009-09-04 07:40:29 1 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\LocalService\oashdihasidhasuidhiasdhiashdiuasdhasd.vir
2009-09-04 07:40:05 . 2009-09-04 07:40:05 191,357 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\wisdstr.exe.vir
2009-09-04 07:40:01 . 2009-09-04 07:51:30 11,264 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\braviax.exe.vir
2009-09-02 06:38:11 . 2009-09-04 07:50:13 29,184 -c--a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\beep.sys.vir
2009-09-02 06:38:11 . 2009-09-04 07:50:13 29,184 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\beep.sys.vir

Would any other log files from SDfix/HJT etc be helpful? Those worked yesterday.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16754
 
   Posted 9-4-2009 10:37 (GMT +1)    Quote: Please help: Braviax.exe and his friends >__<Alert an admin about: Please help: Braviax.exe and his friends >__<
It looks like it got rid of some nastyes.
 
 
Let´s see if DDS can find some infections ->
 
to your Desktop and doubleclick on DDs.scr to run it.
If your security software includes script blocking features, please disable these before you run this utility.
When the scan has finished, two logs will open.
Copy and paste both reports in this topic.
 
The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.



Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

jadesphere
New Member


Date Joined Sep 2009
Total Posts : 5
 
   Posted 9-4-2009 8:07 (GMT +1)    Quote: Please help: Braviax.exe and his friends >__<Alert an admin about: Please help: Braviax.exe and his friends >__<
Hi Touch,

I am headed home and will run DDS as instructed. I will have the whole day to devote to this issue. Thanks.
Back to Top
 

jadesphere
New Member


Date Joined Sep 2009
Total Posts : 5
 
   Posted 9-4-2009 8:41 (GMT +1)    Quote: Please help: Braviax.exe and his friends >__<Alert an admin about: Please help: Braviax.exe and his friends >__<
Back home. Current update is that I still have a red suspicious icon "You computer is infected!" as well as PC Antispyware 2010 pop ups; i think the reason is i connected back to the internet to post this log.


Posted DDS as well as attached Attached as a RAR (I don't think i have winzip, hope that is ok) file.



DDS (Ver_09-07-30.01) - NTFSx86
Run by Roger Yei at 12:37:23.18 on Fri 09/04/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.620 [GMT -7:00]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\KMaestro\KMaestro.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\AcroDist.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Roger Yei\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://mabinogi.nexon.net/Promo/CowboyHat.aspx
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [AIM] c:\program files\aim\aim.exe -cnetwait.odl
mRun: [DeadAIM] rundll32.exe "c:\progra~1\aim\\DeadAIM.ocm",ExportedCheckODLs
mRun: [BtcMaestro] c:\program files\kmaestro\KMaestro.exe
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [ctfmon.exe] c:\windows\system32\CTFMON.EXE
dRun: [braviax]
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: aon.com\www.onlinepackets
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - hxxp://avatar.mabinogi.jp/3drender/renderer/mabiweb.2007.4.4.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {BFBC3059-9C61-5BA1-2075-85C8B6ECFC07} - hxxp://mabinogi.or.tp/etc/mwfre.2.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
AppInit_DLLs: cru629.dat

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\rogery~1\applic~1\mozilla\firefox\profiles\okmzmwox.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - plugin: c:\documents and settings\roger yei\application data\mozilla\firefox\profiles\okmzmwox.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp07100121.dll
FF - HiddenExtension: XUL Cache: {BBB3F497-D300-405F-82B9-FD8D1946BFE7} - c:\documents and settings\roger yei\local settings\application data\{BBB3F497-D300-405F-82B9-FD8D1946BFE7}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2008-11-29 38144]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2008-11-28 572416]
S3 Uniden PCW 100 - Wireless 802.11b USB Adapter(R);Uniden PCW 100 - Wireless 802.11b USB Adapter(R) Service for PCW 100 - Wireless 802.11b USB Adapter;c:\windows\system32\drivers\vnetusbr.sys [2008-7-20 93312]

=============== Created Last 30 ================

2009-09-04 12:36 29,184 ac------ c:\windows\system32\dllcache\figaro.sys
2009-09-04 12:33 11,264 a------- c:\windows\braviax.exe
2009-09-04 12:33 6,144 a------- c:\windows\system32\cru629.dat
2009-09-04 12:33 6,144 a------- c:\windows\cru629.dat
2009-09-04 01:30 191,357 a------- c:\windows\system32\wisdstr.exe
2009-09-04 01:30 29,184 ac------ c:\windows\system32\dllcache\beep.sys
2009-09-04 01:30 11,264 a------- c:\windows\system32\braviax.exe
2009-09-04 00:54 230,912 a------- c:\windows\PEV.exe
2009-09-04 00:54 161,792 a------- c:\windows\SWREG.exe
2009-09-04 00:54 98,816 a------- c:\windows\sed.exe
2009-09-03 23:34 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-09-03 19:43 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-09-03 19:43 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-09-02 19:43 <DIR> --d----- C:\abc
2009-09-02 19:37 <DIR> --d----- c:\program files\test
2009-09-02 19:22 13,502 a------- c:\windows\powe.dat
2009-09-02 19:20 11,368 a------- c:\windows\yfoqe.db
2009-09-02 19:20 10,037 a------- c:\program files\common files\ofovono.dat
2009-09-01 23:38 29,184 a------- c:\windows\system32\drivers\beep.sys
2009-09-01 23:32 16,646 a------- c:\windows\amobucypu.db
2009-09-01 23:27 <DIR> --d----- c:\docume~1\rogery~1\applic~1\Malwarebytes
2009-09-01 23:27 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-01 23:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-01 23:27 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-09-01 23:27 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-01 23:21 <DIR> --d-h--- C:\BJPrinter
2009-09-01 23:15 577,024 ac------ c:\windows\system32\dllcache\user32.dll
2009-09-01 23:14 <DIR> --d----- c:\windows\ERUNT
2009-09-01 23:09 120 a------- c:\windows\Jyowocixaf.dat
2009-09-01 22:48 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-01 22:48 <DIR> --d----- C:\TEMP
2009-09-01 22:36 29,216 a------- c:\windows\system32\sys32_nov.exe
2009-08-08 00:33 22,930 a------- C:\LockBackground.jpg
2009-08-07 21:40 22,930 a------- C:\Wallpaper.jpg

==================== Find3M ====================

2009-09-04 12:36 94,272 ac------ c:\windows\system32\drivers\agp440.sys
2009-09-02 19:22 19,609 a------- c:\program files\common files\imoqugo.lib
2009-08-02 10:52 409,600 a------- c:\windows\system32\wrap_oal.dll
2009-08-02 10:52 114,688 a------- c:\windows\system32\OpenAL32.dll
2005-01-27 18:01 25,280 ac------ c:\docume~1\rogery~1\applic~1\GDIPFONTCACHEV1.DAT

============= FINISH: 12:37:44.46 ===============

File Attachment :
Attach.rar   2KB (application/force-download)
This file has been downloaded 32 time(s).
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16754
 
   Posted 9-5-2009 6:27 (GMT +1)    Quote: Please help: Braviax.exe and his friends >__<Alert an admin about: Please help: Braviax.exe and his friends >__<
 
  by Swandog46 to your Desktop.
Click on Avenger.zip to open the file
Extract avenger2.exe to your desktop
 
Start Avenger
 
Begin copying here:
Files to delete:
c:\windows\system32\dllcache\figaro.sys
c:\windows\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\cru629.dat
c:\windows\system32\wisdstr.exe
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\braviax.exe
c:\windows\powe.dat
c:\windows\yfoqe.db
c:\program files\common files\ofovono.dat
c:\windows\amobucypu.db
c:\windows\Jyowocixaf.dat
c:\windows\system32\sys32_nov.exe
Folders to delete:
C:\TEMP
Registry keys to replace with dummy:
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs




Copy/Paste all the text  in the above codebox into the main window
Click Execute
 
The Avenger will automatically do the following:
It will Restart your computer.
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger’s actions.
 
This log file will be located at  C:\avenger.txt
 
Please download Malwarebytes' Anti-Malware:
http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
to your desktop. Save it as -
smss.exe

Double-click
smss.exe  and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform full scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location.
 
NB. If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.
 
Please post malwarebyte log, along with C:\avenger.txt


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 
New Topic Post reply to : Please help: Braviax.exe and his friends >__< Printable version of : Please help: Braviax.exe and his friends >__<
 
Forum Information
Currently it is Wednesday, March 17, 2010 8:52 PM (GMT +1)
There are a total of 76.277 posts in 17.610 threads.
In the last 3 days there were 11 new threads and 60 reply posts. View Active Threads
Who's Online
This forum has 31151 registered members. Please welcome our newest member, kas.
27 Guest(s), 2 Registered Member(s) are currently online.  Details
taty03, booboo1
5 Latest Threads
Can't perform a full system scan (6)17-03-2010 19:51:51 (booboo1)
Redirect virus - search results cause redirect to ad sites (7)17-03-2010 19:43:46 (kas)
Trojan horse Downloader.Agent2.SNR (0)17-03-2010 19:39:01 (taty03)
Ad.yieldmanager.com problem (6)17-03-2010 19:36:47 (IanR)
Trojan.Generic.KD.4056 (5)17-03-2010 16:20:06 (markusg)