<?xml version="1.0" encoding="UTF-8"?>
<statistics>
<general>
<statistic_version>1</statistic_version>
<statistic_type>1</statistic_type>
<statistic_guid>1343ba08-fe59-41f5-bf71-f1bda2cd2ece</statistic_guid>
<license>Lavasoft::Pro</license>
<version_id>1241610346</version_id>
<timestamp>2009-05-06 13:10:3</timestamp>
<sdk_version>8.0.4</sdk_version>
<extended_version>8.1</extended_version>
<sdk_def_version>148.0</sdk_def_version>
<extended_def_version>8.1</extended_def_version>
<osmajor>6</osmajor>
<osminor>0</osminor>
<osarchitecture>9</osarchitecture>
</general>
<scan>
<total_scanned>5</total_scanned>
<total_detected>5</total_detected>
<unknown>0</unknown>
<browserhijack>0</browserhijack>
<cookie>0</cookie>
<file>5</file>
<folder>0</folder>
<hostfileentry>0</hostfileentry>
<lsp>0</lsp>
<mru>0</mru>
<process>0</process>
<registry>0</registry>
</scan>
<infections>
<skip>
<item can_quarantine="1" can_remove="1" can_repair="0" can_upload="1" can_whitelist="1" category="file" description="C:\temp\analyze\20090506\1a3076c75c7259e75c2c16e57db55afd_gebttsih.dll" detection_method="2" family="Suspicious Object" filesize="36352" is_avira="1" is_heuristic="1" is_virus="0" md5="1a3076c75c7259e75c2c16e57db55afd" path="C:\temp\analyze\20090506\1a3076c75c7259e75c2c16e57db55afd_gebttsih.dll" tai="7" type="file"/>
<item can_quarantine="1" can_remove="1" can_repair="0" can_whitelist="1" category="trojan" description="C:\temp\analyze\20090506\7d6bd1845f8657e7d356fbe8b8e581f6_wdhofuaw.dll_" detection_method="2" family="TR/Crypt.XPACK.Gen" filesize="113728" is_avira="1" is_heuristic="0" is_virus="0" md5="7d6bd1845f8657e7d356fbe8b8e581f6" path="C:\temp\analyze\20090506\7d6bd1845f8657e7d356fbe8b8e581f6_wdhofuaw.dll_" tai="10" type="file"/>
<item can_quarantine="1" can_remove="1" can_repair="0" can_whitelist="1" category="trojan" description="C:\temp\analyze\20090506\9e5671556cac1c94c229d7be278d040a_svchost.exe_" detection_method="2" family="TR/Crypt.XPACK.Gen" filesize="256512" is_avira="1" is_heuristic="0" is_virus="0" md5="9e5671556cac1c94c229d7be278d040a" path="C:\temp\analyze\20090506\9e5671556cac1c94c229d7be278d040a_svchost.exe_" tai="10" type="file"/>
<item can_quarantine="1" can_remove="1" can_repair="0" can_whitelist="1" category="trojan" description="C:\temp\analyze\20090506\a2dab4b9b021ef5027b59ce364d24c9b_ehnrfmet.dll_" detection_method="2" family="TR/Crypt.XPACK.Gen" filesize="105024" is_avira="1" is_heuristic="0" is_virus="0" md5="a2dab4b9b021ef5027b59ce364d24c9b" path="C:\temp\analyze\20090506\a2dab4b9b021ef5027b59ce364d24c9b_ehnrfmet.dll_" tai="10" type="file"/>
<item can_quarantine="1" can_remove="1" can_repair="0" can_whitelist="1" category="trojan" description="C:\temp\analyze\20090506\763dee5bfd290a778c3f74596ff9c20d_hgGVPgFU.dll" detection_method="2" family="TR/Vundo.Gen" filesize="316096" is_avira="1" is_heuristic="0" is_virus="0" md5="763dee5bfd290a778c3f74596ff9c20d" path="C:\temp\analyze\20090506\763dee5bfd290a778c3f74596ff9c20d_hgGVPgFU.dll" tai="10" type="file"/>
</skip>
<whitelist/>
<remove/>
<repair/>
<quarantine/>
<analyze/>
</infections>
<profile_settings>
<node>
<n_contextmenuscan enabled="1" readonly="0" type="string" value="Context menu scan">
<n_scancriticalareas enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_scanrunningapps enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_scanregistry enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_scanlsp enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_scanads enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_scanhostsfile enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_scanmru enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_scanbrowserhijacks enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_scantrackingcookies enabled="1" readonly="0" type="bool" value="0" behaviour="1">
<n_closebrowsers enabled="0" readonly="0" type="bool" value="0" behaviour="0"/>
</n_scantrackingcookies>
<n_folderstoscan enabled="1" readonly="0" type="stringlist" numvalues="0"/>
<n_scanrootkits enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_usespywareheuristics enabled="1" readonly="0" type="bool" value="1" behaviour="0"/>
<n_extendedengine enabled="1" readonly="0" type="bool" value="1" behaviour="1">
<n_useheuristics enabled="1" readonly="0" type="bool" value="1" behaviour="1">
<n_heuristicslevel enabled="1" readonly="0" type="stringrestricted" value="mild" domainvalue0="medium" domainvalue1="mild" domainvalue2="strict" numdomainvalues="3"/>
</n_useheuristics>
</n_extendedengine>
<n_filescanningoptions enabled="1" readonly="0" type="void">
<n_archives enabled="1" readonly="0" type="bool" value="1" behaviour="0"/>
<n_onlyexecutables enabled="1" readonly="0" type="bool" value="0" behaviour="0"/>
<n_skiplargerthan enabled="1" readonly="0" type="int" value="20480"/>
</n_filescanningoptions>
</n_contextmenuscan>
</node>
</profile_settings>
<global_settings>
<node>
<n_global enabled="1" readonly="0" type="void">
<n_addtocontextmenu enabled="1" readonly="0" type="bool" value="1" behaviour="0"/>
<n_playsoundoninfection enabled="1" readonly="0" type="bool" value="0" behaviour="1">
<n_soundfile enabled="0" readonly="0" type="string" value="*to be filled in automatically*\alert.wav"/>
</n_playsoundoninfection>
</n_global>
</node>
</global_settings>
</statistics>
