Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijackthis Log: Please Help Diagnose


  • This topic is locked This topic is locked
26 replies to this topic

#1 Alex Kremer

Alex Kremer

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 16 January 2007 - 12:47 PM

I've run Adaware, AVG, Spybot, PC-Cillin and it will occasionally find viruses/spyware and delete them, but they keep regenerating. Here is my HijackThis Log. Thank you very much in advance.

Logfile of HijackThis v1.99.1
Scan saved at 12:40:16 PM, on 1/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\svchost.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Alex Kremer\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {59CD7310-98A4-48BF-BE77-C12032C98D31} - C:\WINDOWS\system32\qommnom.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - Winlogon Notify: qommnom - C:\WINDOWS\SYSTEM32\qommnom.dll
O20 - Winlogon Notify: winrnt32 - C:\WINDOWS\SYSTEM32\winrnt32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000272 (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

BC AdBot (Login to Remove)

 


#2 Shaba

Shaba

    Koutsi


  • Malware Response Team
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:07:10 AM

Posted 16 January 2007 - 01:40 PM

Hi Alex Kremer

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Send:

- a fresh HijackThis log
- vundofix report
- sdfix report
Microsoft MVP Consumer Security
Posted Image

Posted Image

#3 Alex Kremer

Alex Kremer
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 16 January 2007 - 03:32 PM

Ok, I ran vundofix and sdfix. Vundofix couldn't remove "c:\\windows\system3qommnom.dll" even after multiple tries on reboot.

Here are the logfiles:
VundoFix V6.3.2

Checking Java version...

Java version is 1.5.0.6

Scan started at 2:57:21 PM 1/16/2007

Listing files found while scanning....

C:\WINDOWS\system32\cbxvvvt.dll
C:\WINDOWS\system32\qommnom.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\cbxvvvt.dll
C:\WINDOWS\system32\cbxvvvt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qommnom.dll
C:\WINDOWS\system32\qommnom.dll Could not be deleted.

Performing Repairs to the registry.
Done!

VundoFix V6.3.2

Checking Java version...

Java version is 1.5.0.6

Scan started at 3:06:16 PM 1/16/2007

Listing files found while scanning....

C:\WINDOWS\system32\qommnom.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\qommnom.dll
C:\WINDOWS\system32\qommnom.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\qommnom.dll
C:\WINDOWS\system32\qommnom.dll Could not be deleted.

Performing Repairs to the registry.
Done!




SDFix: Version 1.59

Tue 01/16/2007 - 15:20:31.89

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:

Checking Services:

Name:

COM+ Messages

Path:

"C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000272

COM+ Messages Deleted

Restoring Windows Registry Entries
Restoring Default Hosts File

Rebooting

Normal Mode:

Checking Files:


Files will be copied to Backups folder then removed:

C:\WINDOWS\Temp\win70F.tmp.exe - Deleted
C:\WINDOWS\Temp\win711.tmp.exe - Deleted
C:\WINDOWS\Temp\win715.tmp.exe - Deleted
C:\DOCUME~1\ALEXKR~1\LOCALS~1\Temp\uninstall.exe - Deleted
C:\WINDOWS\svchost.exe - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
C:\WINDOWS\Temp\win1.tmp - Deleted
C:\WINDOWS\Temp\win10.tmp - Deleted
C:\WINDOWS\Temp\win100.tmp - Deleted
C:\WINDOWS\Temp\win101.tmp - Deleted
C:\WINDOWS\Temp\win102.tmp - Deleted
C:\WINDOWS\Temp\win103.tmp - Deleted
C:\WINDOWS\Temp\win104.tmp - Deleted
C:\WINDOWS\Temp\win105.tmp - Deleted
C:\WINDOWS\Temp\win106.tmp - Deleted
C:\WINDOWS\Temp\win107.tmp - Deleted
C:\WINDOWS\Temp\win108.tmp - Deleted
C:\WINDOWS\Temp\win109.tmp - Deleted
C:\WINDOWS\Temp\win10A.tmp - Deleted
C:\WINDOWS\Temp\win10B.tmp - Deleted
C:\WINDOWS\Temp\win10C.tmp - Deleted
C:\WINDOWS\Temp\win10D.tmp - Deleted
C:\WINDOWS\Temp\win10E.tmp - Deleted
C:\WINDOWS\Temp\win10F.tmp - Deleted
C:\WINDOWS\Temp\win11.tmp - Deleted
C:\WINDOWS\Temp\win110.tmp - Deleted
C:\WINDOWS\Temp\win111.tmp - Deleted
C:\WINDOWS\Temp\win112.tmp - Deleted
C:\WINDOWS\Temp\win113.tmp - Deleted
C:\WINDOWS\Temp\win114.tmp - Deleted
C:\WINDOWS\Temp\win115.tmp - Deleted
C:\WINDOWS\Temp\win116.tmp - Deleted
C:\WINDOWS\Temp\win117.tmp - Deleted
C:\WINDOWS\Temp\win118.tmp - Deleted
C:\WINDOWS\Temp\win119.tmp - Deleted
C:\WINDOWS\Temp\win11A.tmp - Deleted
C:\WINDOWS\Temp\win11B.tmp - Deleted
C:\WINDOWS\Temp\win11C.tmp - Deleted
C:\WINDOWS\Temp\win11D.tmp - Deleted
C:\WINDOWS\Temp\win11E.tmp - Deleted
C:\WINDOWS\Temp\win11F.tmp - Deleted
C:\WINDOWS\Temp\win12.tmp - Deleted
C:\WINDOWS\Temp\win120.tmp - Deleted
C:\WINDOWS\Temp\win121.tmp - Deleted
C:\WINDOWS\Temp\win122.tmp - Deleted
C:\WINDOWS\Temp\win123.tmp - Deleted
C:\WINDOWS\Temp\win124.tmp - Deleted
C:\WINDOWS\Temp\win125.tmp - Deleted
C:\WINDOWS\Temp\win126.tmp - Deleted
C:\WINDOWS\Temp\win127.tmp - Deleted
C:\WINDOWS\Temp\win128.tmp - Deleted
C:\WINDOWS\Temp\win129.tmp - Deleted
C:\WINDOWS\Temp\win12A.tmp - Deleted
C:\WINDOWS\Temp\win12B.tmp - Deleted
C:\WINDOWS\Temp\win12C.tmp - Deleted
C:\WINDOWS\Temp\win12D.tmp - Deleted
C:\WINDOWS\Temp\win12E.tmp - Deleted
C:\WINDOWS\Temp\win12F.tmp - Deleted
C:\WINDOWS\Temp\win13.tmp - Deleted
C:\WINDOWS\Temp\win130.tmp - Deleted
C:\WINDOWS\Temp\win131.tmp - Deleted
C:\WINDOWS\Temp\win132.tmp - Deleted
C:\WINDOWS\Temp\win133.tmp - Deleted
C:\WINDOWS\Temp\win134.tmp - Deleted
C:\WINDOWS\Temp\win135.tmp - Deleted
C:\WINDOWS\Temp\win136.tmp - Deleted
C:\WINDOWS\Temp\win137.tmp - Deleted
C:\WINDOWS\Temp\win138.tmp - Deleted
C:\WINDOWS\Temp\win139.tmp - Deleted
C:\WINDOWS\Temp\win13A.tmp - Deleted
C:\WINDOWS\Temp\win13B.tmp - Deleted
C:\WINDOWS\Temp\win13C.tmp - Deleted
C:\WINDOWS\Temp\win13D.tmp - Deleted
C:\WINDOWS\Temp\win13E.tmp - Deleted
C:\WINDOWS\Temp\win13F.tmp - Deleted
C:\WINDOWS\Temp\win14.tmp - Deleted
C:\WINDOWS\Temp\win140.tmp - Deleted
C:\WINDOWS\Temp\win141.tmp - Deleted
C:\WINDOWS\Temp\win142.tmp - Deleted
C:\WINDOWS\Temp\win143.tmp - Deleted
C:\WINDOWS\Temp\win144.tmp - Deleted
C:\WINDOWS\Temp\win145.tmp - Deleted
C:\WINDOWS\Temp\win146.tmp - Deleted
C:\WINDOWS\Temp\win147.tmp - Deleted
C:\WINDOWS\Temp\win148.tmp - Deleted
C:\WINDOWS\Temp\win149.tmp - Deleted
C:\WINDOWS\Temp\win14A.tmp - Deleted
C:\WINDOWS\Temp\win14B.tmp - Deleted
C:\WINDOWS\Temp\win14C.tmp - Deleted
C:\WINDOWS\Temp\win14D.tmp - Deleted
C:\WINDOWS\Temp\win14E.tmp - Deleted
C:\WINDOWS\Temp\win14F.tmp - Deleted
C:\WINDOWS\Temp\win15.tmp - Deleted
C:\WINDOWS\Temp\win150.tmp - Deleted
C:\WINDOWS\Temp\win151.tmp - Deleted
C:\WINDOWS\Temp\win152.tmp - Deleted
C:\WINDOWS\Temp\win153.tmp - Deleted
C:\WINDOWS\Temp\win154.tmp - Deleted
C:\WINDOWS\Temp\win155.tmp - Deleted
C:\WINDOWS\Temp\win156.tmp - Deleted
C:\WINDOWS\Temp\win157.tmp - Deleted
C:\WINDOWS\Temp\win158.tmp - Deleted
C:\WINDOWS\Temp\win159.tmp - Deleted
C:\WINDOWS\Temp\win15A.tmp - Deleted
C:\WINDOWS\Temp\win15B.tmp - Deleted
C:\WINDOWS\Temp\win15C.tmp - Deleted
C:\WINDOWS\Temp\win15D.tmp - Deleted
C:\WINDOWS\Temp\win15E.tmp - Deleted
C:\WINDOWS\Temp\win15F.tmp - Deleted
C:\WINDOWS\Temp\win16.tmp - Deleted
C:\WINDOWS\Temp\win160.tmp - Deleted
C:\WINDOWS\Temp\win161.tmp - Deleted
C:\WINDOWS\Temp\win162.tmp - Deleted
C:\WINDOWS\Temp\win163.tmp - Deleted
C:\WINDOWS\Temp\win164.tmp - Deleted
C:\WINDOWS\Temp\win165.tmp - Deleted
C:\WINDOWS\Temp\win166.tmp - Deleted
C:\WINDOWS\Temp\win167.tmp - Deleted
C:\WINDOWS\Temp\win168.tmp - Deleted
C:\WINDOWS\Temp\win169.tmp - Deleted
C:\WINDOWS\Temp\win16A.tmp - Deleted
C:\WINDOWS\Temp\win16B.tmp - Deleted
C:\WINDOWS\Temp\win16C.tmp - Deleted
C:\WINDOWS\Temp\win16D.tmp - Deleted
C:\WINDOWS\Temp\win16E.tmp - Deleted
C:\WINDOWS\Temp\win16F.tmp - Deleted
C:\WINDOWS\Temp\win17.tmp - Deleted
C:\WINDOWS\Temp\win170.tmp - Deleted
C:\WINDOWS\Temp\win171.tmp - Deleted
C:\WINDOWS\Temp\win172.tmp - Deleted
C:\WINDOWS\Temp\win173.tmp - Deleted
C:\WINDOWS\Temp\win174.tmp - Deleted
C:\WINDOWS\Temp\win175.tmp - Deleted
C:\WINDOWS\Temp\win176.tmp - Deleted
C:\WINDOWS\Temp\win177.tmp - Deleted
C:\WINDOWS\Temp\win178.tmp - Deleted
C:\WINDOWS\Temp\win179.tmp - Deleted
C:\WINDOWS\Temp\win17A.tmp - Deleted
C:\WINDOWS\Temp\win17B.tmp - Deleted
C:\WINDOWS\Temp\win17C.tmp - Deleted
C:\WINDOWS\Temp\win17D.tmp - Deleted
C:\WINDOWS\Temp\win17E.tmp - Deleted
C:\WINDOWS\Temp\win17F.tmp - Deleted
C:\WINDOWS\Temp\win18.tmp - Deleted
C:\WINDOWS\Temp\win180.tmp - Deleted
C:\WINDOWS\Temp\win181.tmp - Deleted
C:\WINDOWS\Temp\win182.tmp - Deleted
C:\WINDOWS\Temp\win183.tmp - Deleted
C:\WINDOWS\Temp\win184.tmp - Deleted
C:\WINDOWS\Temp\win185.tmp - Deleted
C:\WINDOWS\Temp\win186.tmp - Deleted
C:\WINDOWS\Temp\win187.tmp - Deleted
C:\WINDOWS\Temp\win188.tmp - Deleted
C:\WINDOWS\Temp\win189.tmp - Deleted
C:\WINDOWS\Temp\win18A.tmp - Deleted
C:\WINDOWS\Temp\win18B.tmp - Deleted
C:\WINDOWS\Temp\win18C.tmp - Deleted
C:\WINDOWS\Temp\win18D.tmp - Deleted
C:\WINDOWS\Temp\win18E.tmp - Deleted
C:\WINDOWS\Temp\win18F.tmp - Deleted
C:\WINDOWS\Temp\win19.tmp - Deleted
C:\WINDOWS\Temp\win190.tmp - Deleted
C:\WINDOWS\Temp\win191.tmp - Deleted
C:\WINDOWS\Temp\win192.tmp - Deleted
C:\WINDOWS\Temp\win193.tmp - Deleted
C:\WINDOWS\Temp\win194.tmp - Deleted
C:\WINDOWS\Temp\win195.tmp - Deleted
C:\WINDOWS\Temp\win196.tmp - Deleted
C:\WINDOWS\Temp\win197.tmp - Deleted
C:\WINDOWS\Temp\win198.tmp - Deleted
C:\WINDOWS\Temp\win199.tmp - Deleted
C:\WINDOWS\Temp\win19A.tmp - Deleted
C:\WINDOWS\Temp\win19B.tmp - Deleted
C:\WINDOWS\Temp\win19C.tmp - Deleted
C:\WINDOWS\Temp\win19D.tmp - Deleted
C:\WINDOWS\Temp\win19E.tmp - Deleted
C:\WINDOWS\Temp\win19F.tmp - Deleted
C:\WINDOWS\Temp\win1A.tmp - Deleted
C:\WINDOWS\Temp\win1A0.tmp - Deleted
C:\WINDOWS\Temp\win1A1.tmp - Deleted
C:\WINDOWS\Temp\win1A2.tmp - Deleted
C:\WINDOWS\Temp\win1A3.tmp - Deleted
C:\WINDOWS\Temp\win1A4.tmp - Deleted
C:\WINDOWS\Temp\win1A5.tmp - Deleted
C:\WINDOWS\Temp\win1A6.tmp - Deleted
C:\WINDOWS\Temp\win1A7.tmp - Deleted
C:\WINDOWS\Temp\win1A8.tmp - Deleted
C:\WINDOWS\Temp\win1A9.tmp - Deleted
C:\WINDOWS\Temp\win1AA.tmp - Deleted
C:\WINDOWS\Temp\win1AB.tmp - Deleted
C:\WINDOWS\Temp\win1AC.tmp - Deleted
C:\WINDOWS\Temp\win1AD.tmp - Deleted
C:\WINDOWS\Temp\win1AE.tmp - Deleted
C:\WINDOWS\Temp\win1AF.tmp - Deleted
C:\WINDOWS\Temp\win1B.tmp - Deleted
C:\WINDOWS\Temp\win1B0.tmp - Deleted
C:\WINDOWS\Temp\win1B1.tmp - Deleted
C:\WINDOWS\Temp\win1B2.tmp - Deleted
C:\WINDOWS\Temp\win1B3.tmp - Deleted
C:\WINDOWS\Temp\win1B4.tmp - Deleted
C:\WINDOWS\Temp\win1B5.tmp - Deleted
C:\WINDOWS\Temp\win1B6.tmp - Deleted
C:\WINDOWS\Temp\win1B7.tmp - Deleted
C:\WINDOWS\Temp\win1B8.tmp - Deleted
C:\WINDOWS\Temp\win1B9.tmp - Deleted
C:\WINDOWS\Temp\win1BA.tmp - Deleted
C:\WINDOWS\Temp\win1BB.tmp - Deleted
C:\WINDOWS\Temp\win1BC.tmp - Deleted
C:\WINDOWS\Temp\win1BD.tmp - Deleted
C:\WINDOWS\Temp\win1BE.tmp - Deleted
C:\WINDOWS\Temp\win1BF.tmp - Deleted
C:\WINDOWS\Temp\win1C.tmp - Deleted
C:\WINDOWS\Temp\win1C0.tmp - Deleted
C:\WINDOWS\Temp\win1C1.tmp - Deleted
C:\WINDOWS\Temp\win1C2.tmp - Deleted
C:\WINDOWS\Temp\win1C3.tmp - Deleted
C:\WINDOWS\Temp\win1C4.tmp - Deleted
C:\WINDOWS\Temp\win1C5.tmp - Deleted
C:\WINDOWS\Temp\win1C6.tmp - Deleted
C:\WINDOWS\Temp\win1C7.tmp - Deleted
C:\WINDOWS\Temp\win1C8.tmp - Deleted
C:\WINDOWS\Temp\win1C9.tmp - Deleted
C:\WINDOWS\Temp\win1CA.tmp - Deleted
C:\WINDOWS\Temp\win1CB.tmp - Deleted
C:\WINDOWS\Temp\win1CC.tmp - Deleted
C:\WINDOWS\Temp\win1CD.tmp - Deleted
C:\WINDOWS\Temp\win1CE.tmp - Deleted
C:\WINDOWS\Temp\win1CF.tmp - Deleted
C:\WINDOWS\Temp\win1D.tmp - Deleted
C:\WINDOWS\Temp\win1D0.tmp - Deleted
C:\WINDOWS\Temp\win1D1.tmp - Deleted
C:\WINDOWS\Temp\win1D2.tmp - Deleted
C:\WINDOWS\Temp\win1D3.tmp - Deleted
C:\WINDOWS\Temp\win1D4.tmp - Deleted
C:\WINDOWS\Temp\win1D5.tmp - Deleted
C:\WINDOWS\Temp\win1D6.tmp - Deleted
C:\WINDOWS\Temp\win1D7.tmp - Deleted
C:\WINDOWS\Temp\win1D8.tmp - Deleted
C:\WINDOWS\Temp\win1D9.tmp - Deleted
C:\WINDOWS\Temp\win1DA.tmp - Deleted
C:\WINDOWS\Temp\win1DB.tmp - Deleted
C:\WINDOWS\Temp\win1DC.tmp - Deleted
C:\WINDOWS\Temp\win1DD.tmp - Deleted
C:\WINDOWS\Temp\win1DE.tmp - Deleted
C:\WINDOWS\Temp\win1DF.tmp - Deleted
C:\WINDOWS\Temp\win1E.tmp - Deleted
C:\WINDOWS\Temp\win1E0.tmp - Deleted
C:\WINDOWS\Temp\win1E1.tmp - Deleted
C:\WINDOWS\Temp\win1E2.tmp - Deleted
C:\WINDOWS\Temp\win1E3.tmp - Deleted
C:\WINDOWS\Temp\win1E4.tmp - Deleted
C:\WINDOWS\Temp\win1E5.tmp - Deleted
C:\WINDOWS\Temp\win1E6.tmp - Deleted
C:\WINDOWS\Temp\win1E7.tmp - Deleted
C:\WINDOWS\Temp\win1E8.tmp - Deleted
C:\WINDOWS\Temp\win1E9.tmp - Deleted
C:\WINDOWS\Temp\win1EA.tmp - Deleted
C:\WINDOWS\Temp\win1EB.tmp - Deleted
C:\WINDOWS\Temp\win1EC.tmp - Deleted
C:\WINDOWS\Temp\win1ED.tmp - Deleted
C:\WINDOWS\Temp\win1EE.tmp - Deleted
C:\WINDOWS\Temp\win1EF.tmp - Deleted
C:\WINDOWS\Temp\win1F.tmp - Deleted
C:\WINDOWS\Temp\win1F0.tmp - Deleted
C:\WINDOWS\Temp\win1F1.tmp - Deleted
C:\WINDOWS\Temp\win1F2.tmp - Deleted
C:\WINDOWS\Temp\win1F3.tmp - Deleted
C:\WINDOWS\Temp\win1F4.tmp - Deleted
C:\WINDOWS\Temp\win1F5.tmp - Deleted
C:\WINDOWS\Temp\win1F6.tmp - Deleted
C:\WINDOWS\Temp\win1F7.tmp - Deleted
C:\WINDOWS\Temp\win1F8.tmp - Deleted
C:\WINDOWS\Temp\win1F9.tmp - Deleted
C:\WINDOWS\Temp\win1FA.tmp - Deleted
C:\WINDOWS\Temp\win1FB.tmp - Deleted
C:\WINDOWS\Temp\win1FC.tmp - Deleted
C:\WINDOWS\Temp\win1FD.tmp - Deleted
C:\WINDOWS\Temp\win1FE.tmp - Deleted
C:\WINDOWS\Temp\win1FF.tmp - Deleted
C:\WINDOWS\Temp\win2.tmp - Deleted
C:\WINDOWS\Temp\win20.tmp - Deleted
C:\WINDOWS\Temp\win200.tmp - Deleted
C:\WINDOWS\Temp\win201.tmp - Deleted
C:\WINDOWS\Temp\win202.tmp - Deleted
C:\WINDOWS\Temp\win203.tmp - Deleted
C:\WINDOWS\Temp\win204.tmp - Deleted
C:\WINDOWS\Temp\win205.tmp - Deleted
C:\WINDOWS\Temp\win206.tmp - Deleted
C:\WINDOWS\Temp\win207.tmp - Deleted
C:\WINDOWS\Temp\win208.tmp - Deleted
C:\WINDOWS\Temp\win209.tmp - Deleted
C:\WINDOWS\Temp\win20A.tmp - Deleted
C:\WINDOWS\Temp\win20B.tmp - Deleted
C:\WINDOWS\Temp\win20C.tmp - Deleted
C:\WINDOWS\Temp\win20D.tmp - Deleted
C:\WINDOWS\Temp\win20E.tmp - Deleted
C:\WINDOWS\Temp\win20F.tmp - Deleted
C:\WINDOWS\Temp\win21.tmp - Deleted
C:\WINDOWS\Temp\win210.tmp - Deleted
C:\WINDOWS\Temp\win211.tmp - Deleted
C:\WINDOWS\Temp\win212.tmp - Deleted
C:\WINDOWS\Temp\win213.tmp - Deleted
C:\WINDOWS\Temp\win214.tmp - Deleted
C:\WINDOWS\Temp\win215.tmp - Deleted
C:\WINDOWS\Temp\win216.tmp - Deleted
C:\WINDOWS\Temp\win217.tmp - Deleted
C:\WINDOWS\Temp\win218.tmp - Deleted
C:\WINDOWS\Temp\win219.tmp - Deleted
C:\WINDOWS\Temp\win21A.tmp - Deleted
C:\WINDOWS\Temp\win21B.tmp - Deleted
C:\WINDOWS\Temp\win21C.tmp - Deleted
C:\WINDOWS\Temp\win21D.tmp - Deleted
C:\WINDOWS\Temp\win21E.tmp - Deleted
C:\WINDOWS\Temp\win21F.tmp - Deleted
C:\WINDOWS\Temp\win22.tmp - Deleted
C:\WINDOWS\Temp\win220.tmp - Deleted
C:\WINDOWS\Temp\win221.tmp - Deleted
C:\WINDOWS\Temp\win222.tmp - Deleted
C:\WINDOWS\Temp\win223.tmp - Deleted
C:\WINDOWS\Temp\win224.tmp - Deleted
C:\WINDOWS\Temp\win225.tmp - Deleted
C:\WINDOWS\Temp\win226.tmp - Deleted
C:\WINDOWS\Temp\win227.tmp - Deleted
C:\WINDOWS\Temp\win228.tmp - Deleted
C:\WINDOWS\Temp\win229.tmp - Deleted
C:\WINDOWS\Temp\win22A.tmp - Deleted
C:\WINDOWS\Temp\win22B.tmp - Deleted
C:\WINDOWS\Temp\win22C.tmp - Deleted
C:\WINDOWS\Temp\win22D.tmp - Deleted
C:\WINDOWS\Temp\win22E.tmp - Deleted
C:\WINDOWS\Temp\win22F.tmp - Deleted
C:\WINDOWS\Temp\win23.tmp - Deleted
C:\WINDOWS\Temp\win230.tmp - Deleted
C:\WINDOWS\Temp\win231.tmp - Deleted
C:\WINDOWS\Temp\win232.tmp - Deleted
C:\WINDOWS\Temp\win233.tmp - Deleted
C:\WINDOWS\Temp\win234.tmp - Deleted
C:\WINDOWS\Temp\win235.tmp - Deleted
C:\WINDOWS\Temp\win236.tmp - Deleted
C:\WINDOWS\Temp\win237.tmp - Deleted
C:\WINDOWS\Temp\win238.tmp - Deleted
C:\WINDOWS\Temp\win239.tmp - Deleted
C:\WINDOWS\Temp\win23A.tmp - Deleted
C:\WINDOWS\Temp\win23B.tmp - Deleted
C:\WINDOWS\Temp\win23C.tmp - Deleted
C:\WINDOWS\Temp\win23D.tmp - Deleted
C:\WINDOWS\Temp\win23E.tmp - Deleted
C:\WINDOWS\Temp\win23F.tmp - Deleted
C:\WINDOWS\Temp\win24.tmp - Deleted
C:\WINDOWS\Temp\win240.tmp - Deleted
C:\WINDOWS\Temp\win241.tmp - Deleted
C:\WINDOWS\Temp\win242.tmp - Deleted
C:\WINDOWS\Temp\win243.tmp - Deleted
C:\WINDOWS\Temp\win244.tmp - Deleted
C:\WINDOWS\Temp\win245.tmp - Deleted
C:\WINDOWS\Temp\win246.tmp - Deleted
C:\WINDOWS\Temp\win247.tmp - Deleted
C:\WINDOWS\Temp\win248.tmp - Deleted
C:\WINDOWS\Temp\win249.tmp - Deleted
C:\WINDOWS\Temp\win24A.tmp - Deleted
C:\WINDOWS\Temp\win24B.tmp - Deleted
C:\WINDOWS\Temp\win24C.tmp - Deleted
C:\WINDOWS\Temp\win24D.tmp - Deleted
C:\WINDOWS\Temp\win24E.tmp - Deleted
C:\WINDOWS\Temp\win24F.tmp - Deleted
C:\WINDOWS\Temp\win25.tmp - Deleted
C:\WINDOWS\Temp\win250.tmp - Deleted
C:\WINDOWS\Temp\win251.tmp - Deleted
C:\WINDOWS\Temp\win252.tmp - Deleted
C:\WINDOWS\Temp\win253.tmp - Deleted
C:\WINDOWS\Temp\win254.tmp - Deleted
C:\WINDOWS\Temp\win255.tmp - Deleted
C:\WINDOWS\Temp\win256.tmp - Deleted
C:\WINDOWS\Temp\win257.tmp - Deleted
C:\WINDOWS\Temp\win258.tmp - Deleted
C:\WINDOWS\Temp\win259.tmp - Deleted
C:\WINDOWS\Temp\win25A.tmp - Deleted
C:\WINDOWS\Temp\win25B.tmp - Deleted
C:\WINDOWS\Temp\win25C.tmp - Deleted
C:\WINDOWS\Temp\win25D.tmp - Deleted
C:\WINDOWS\Temp\win25E.tmp - Deleted
C:\WINDOWS\Temp\win25F.tmp - Deleted
C:\WINDOWS\Temp\win26.tmp - Deleted
C:\WINDOWS\Temp\win260.tmp - Deleted
C:\WINDOWS\Temp\win261.tmp - Deleted
C:\WINDOWS\Temp\win262.tmp - Deleted
C:\WINDOWS\Temp\win263.tmp - Deleted
C:\WINDOWS\Temp\win264.tmp - Deleted
C:\WINDOWS\Temp\win265.tmp - Deleted
C:\WINDOWS\Temp\win266.tmp - Deleted
C:\WINDOWS\Temp\win267.tmp - Deleted
C:\WINDOWS\Temp\win268.tmp - Deleted
C:\WINDOWS\Temp\win269.tmp - Deleted
C:\WINDOWS\Temp\win26A.tmp - Deleted
C:\WINDOWS\Temp\win26B.tmp - Deleted
C:\WINDOWS\Temp\win26C.tmp - Deleted
C:\WINDOWS\Temp\win26D.tmp - Deleted
C:\WINDOWS\Temp\win26E.tmp - Deleted
C:\WINDOWS\Temp\win26F.tmp - Deleted
C:\WINDOWS\Temp\win27.tmp - Deleted
C:\WINDOWS\Temp\win270.tmp - Deleted
C:\WINDOWS\Temp\win271.tmp - Deleted
C:\WINDOWS\Temp\win272.tmp - Deleted
C:\WINDOWS\Temp\win273.tmp - Deleted
C:\WINDOWS\Temp\win274.tmp - Deleted
C:\WINDOWS\Temp\win275.tmp - Deleted
C:\WINDOWS\Temp\win276.tmp - Deleted
C:\WINDOWS\Temp\win277.tmp - Deleted
C:\WINDOWS\Temp\win278.tmp - Deleted
C:\WINDOWS\Temp\win279.tmp - Deleted
C:\WINDOWS\Temp\win27A.tmp - Deleted
C:\WINDOWS\Temp\win27B.tmp - Deleted
C:\WINDOWS\Temp\win27C.tmp - Deleted
C:\WINDOWS\Temp\win27D.tmp - Deleted
C:\WINDOWS\Temp\win27E.tmp - Deleted
C:\WINDOWS\Temp\win27F.tmp - Deleted
C:\WINDOWS\Temp\win28.tmp - Deleted
C:\WINDOWS\Temp\win280.tmp - Deleted
C:\WINDOWS\Temp\win281.tmp - Deleted
C:\WINDOWS\Temp\win282.tmp - Deleted
C:\WINDOWS\Temp\win283.tmp - Deleted
C:\WINDOWS\Temp\win284.tmp - Deleted
C:\WINDOWS\Temp\win285.tmp - Deleted
C:\WINDOWS\Temp\win286.tmp - Deleted
C:\WINDOWS\Temp\win287.tmp - Deleted
C:\WINDOWS\Temp\win288.tmp - Deleted
C:\WINDOWS\Temp\win289.tmp - Deleted
C:\WINDOWS\Temp\win28A.tmp - Deleted
C:\WINDOWS\Temp\win28B.tmp - Deleted
C:\WINDOWS\Temp\win28C.tmp - Deleted
C:\WINDOWS\Temp\win28D.tmp - Deleted
C:\WINDOWS\Temp\win28E.tmp - Deleted
C:\WINDOWS\Temp\win28F.tmp - Deleted
C:\WINDOWS\Temp\win29.tmp - Deleted
C:\WINDOWS\Temp\win290.tmp - Deleted
C:\WINDOWS\Temp\win291.tmp - Deleted
C:\WINDOWS\Temp\win292.tmp - Deleted
C:\WINDOWS\Temp\win293.tmp - Deleted
C:\WINDOWS\Temp\win294.tmp - Deleted
C:\WINDOWS\Temp\win295.tmp - Deleted
C:\WINDOWS\Temp\win296.tmp - Deleted
C:\WINDOWS\Temp\win297.tmp - Deleted
C:\WINDOWS\Temp\win298.tmp - Deleted
C:\WINDOWS\Temp\win299.tmp - Deleted
C:\WINDOWS\Temp\win29A.tmp - Deleted
C:\WINDOWS\Temp\win29B.tmp - Deleted
C:\WINDOWS\Temp\win29C.tmp - Deleted
C:\WINDOWS\Temp\win29D.tmp - Deleted
C:\WINDOWS\Temp\win29E.tmp - Deleted
C:\WINDOWS\Temp\win29F.tmp - Deleted
C:\WINDOWS\Temp\win2A.tmp - Deleted
C:\WINDOWS\Temp\win2A0.tmp - Deleted
C:\WINDOWS\Temp\win2A1.tmp - Deleted
C:\WINDOWS\Temp\win2A2.tmp - Deleted
C:\WINDOWS\Temp\win2A3.tmp - Deleted
C:\WINDOWS\Temp\win2A4.tmp - Deleted
C:\WINDOWS\Temp\win2A5.tmp - Deleted
C:\WINDOWS\Temp\win2A6.tmp - Deleted
C:\WINDOWS\Temp\win2A7.tmp - Deleted
C:\WINDOWS\Temp\win2A8.tmp - Deleted
C:\WINDOWS\Temp\win2A9.tmp - Deleted
C:\WINDOWS\Temp\win2AA.tmp - Deleted
C:\WINDOWS\Temp\win2AB.tmp - Deleted
C:\WINDOWS\Temp\win2AC.tmp - Deleted
C:\WINDOWS\Temp\win2AD.tmp - Deleted
C:\WINDOWS\Temp\win2AE.tmp - Deleted
C:\WINDOWS\Temp\win2AF.tmp - Deleted
C:\WINDOWS\Temp\win2B.tmp - Deleted
C:\WINDOWS\Temp\win2B0.tmp - Deleted
C:\WINDOWS\Temp\win2B1.tmp - Deleted
C:\WINDOWS\Temp\win2B2.tmp - Deleted
C:\WINDOWS\Temp\win2B3.tmp - Deleted
C:\WINDOWS\Temp\win2B4.tmp - Deleted
C:\WINDOWS\Temp\win2B5.tmp - Deleted
C:\WINDOWS\Temp\win2B6.tmp - Deleted
C:\WINDOWS\Temp\win2B7.tmp - Deleted
C:\WINDOWS\Temp\win2B8.tmp - Deleted
C:\WINDOWS\Temp\win2B9.tmp - Deleted
C:\WINDOWS\Temp\win2BA.tmp - Deleted
C:\WINDOWS\Temp\win2BB.tmp - Deleted
C:\WINDOWS\Temp\win2BC.tmp - Deleted
C:\WINDOWS\Temp\win2BD.tmp - Deleted
C:\WINDOWS\Temp\win2BE.tmp - Deleted
C:\WINDOWS\Temp\win2BF.tmp - Deleted
C:\WINDOWS\Temp\win2C.tmp - Deleted
C:\WINDOWS\Temp\win2C0.tmp - Deleted
C:\WINDOWS\Temp\win2C1.tmp - Deleted
C:\WINDOWS\Temp\win2C2.tmp - Deleted
C:\WINDOWS\Temp\win2C3.tmp - Deleted
C:\WINDOWS\Temp\win2C4.tmp - Deleted
C:\WINDOWS\Temp\win2C5.tmp - Deleted
C:\WINDOWS\Temp\win2C6.tmp - Deleted
C:\WINDOWS\Temp\win2C7.tmp - Deleted
C:\WINDOWS\Temp\win2C8.tmp - Deleted
C:\WINDOWS\Temp\win2C9.tmp - Deleted
C:\WINDOWS\Temp\win2CA.tmp - Deleted
C:\WINDOWS\Temp\win2CB.tmp - Deleted
C:\WINDOWS\Temp\win2CC.tmp - Deleted
C:\WINDOWS\Temp\win2CD.tmp - Deleted
C:\WINDOWS\Temp\win2CE.tmp - Deleted
C:\WINDOWS\Temp\win2CF.tmp - Deleted
C:\WINDOWS\Temp\win2D.tmp - Deleted
C:\WINDOWS\Temp\win2D0.tmp - Deleted
C:\WINDOWS\Temp\win2D1.tmp - Deleted
C:\WINDOWS\Temp\win2D2.tmp - Deleted
C:\WINDOWS\Temp\win2D3.tmp - Deleted
C:\WINDOWS\Temp\win2D4.tmp - Deleted
C:\WINDOWS\Temp\win2D5.tmp - Deleted
C:\WINDOWS\Temp\win2D6.tmp - Deleted
C:\WINDOWS\Temp\win2D7.tmp - Deleted
C:\WINDOWS\Temp\win2D8.tmp - Deleted
C:\WINDOWS\Temp\win2D9.tmp - Deleted
C:\WINDOWS\Temp\win2DA.tmp - Deleted
C:\WINDOWS\Temp\win2DB.tmp - Deleted
C:\WINDOWS\Temp\win2DC.tmp - Deleted
C:\WINDOWS\Temp\win2DD.tmp - Deleted
C:\WINDOWS\Temp\win2DE.tmp - Deleted
C:\WINDOWS\Temp\win2DF.tmp - Deleted
C:\WINDOWS\Temp\win2E.tmp - Deleted
C:\WINDOWS\Temp\win2E0.tmp - Deleted
C:\WINDOWS\Temp\win2E1.tmp - Deleted
C:\WINDOWS\Temp\win2E2.tmp - Deleted
C:\WINDOWS\Temp\win2E3.tmp - Deleted
C:\WINDOWS\Temp\win2E4.tmp - Deleted
C:\WINDOWS\Temp\win2E5.tmp - Deleted
C:\WINDOWS\Temp\win2E6.tmp - Deleted
C:\WINDOWS\Temp\win2E7.tmp - Deleted
C:\WINDOWS\Temp\win2E8.tmp - Deleted
C:\WINDOWS\Temp\win2E9.tmp - Deleted
C:\WINDOWS\Temp\win2EA.tmp - Deleted
C:\WINDOWS\Temp\win2EB.tmp - Deleted
C:\WINDOWS\Temp\win2EC.tmp - Deleted
C:\WINDOWS\Temp\win2ED.tmp - Deleted
C:\WINDOWS\Temp\win2EE.tmp - Deleted
C:\WINDOWS\Temp\win2EF.tmp - Deleted
C:\WINDOWS\Temp\win2F.tmp - Deleted
C:\WINDOWS\Temp\win2F0.tmp - Deleted
C:\WINDOWS\Temp\win2F1.tmp - Deleted
C:\WINDOWS\Temp\win2F2.tmp - Deleted
C:\WINDOWS\Temp\win2F3.tmp - Deleted
C:\WINDOWS\Temp\win2F4.tmp - Deleted
C:\WINDOWS\Temp\win2F5.tmp - Deleted
C:\WINDOWS\Temp\win2F6.tmp - Deleted
C:\WINDOWS\Temp\win2F7.tmp - Deleted
C:\WINDOWS\Temp\win2F8.tmp - Deleted
C:\WINDOWS\Temp\win2F9.tmp - Deleted
C:\WINDOWS\Temp\win2FA.tmp - Deleted
C:\WINDOWS\Temp\win2FB.tmp - Deleted
C:\WINDOWS\Temp\win2FC.tmp - Deleted
C:\WINDOWS\Temp\win2FD.tmp - Deleted
C:\WINDOWS\Temp\win2FE.tmp - Deleted
C:\WINDOWS\Temp\win2FF.tmp - Deleted
C:\WINDOWS\Temp\win3.tmp - Deleted
C:\WINDOWS\Temp\win30.tmp - Deleted
C:\WINDOWS\Temp\win300.tmp - Deleted
C:\WINDOWS\Temp\win301.tmp - Deleted
C:\WINDOWS\Temp\win302.tmp - Deleted
C:\WINDOWS\Temp\win303.tmp - Deleted
C:\WINDOWS\Temp\win304.tmp - Deleted
C:\WINDOWS\Temp\win305.tmp - Deleted
C:\WINDOWS\Temp\win306.tmp - Deleted
C:\WINDOWS\Temp\win307.tmp - Deleted
C:\WINDOWS\Temp\win308.tmp - Deleted
C:\WINDOWS\Temp\win309.tmp - Deleted
C:\WINDOWS\Temp\win30A.tmp - Deleted
C:\WINDOWS\Temp\win30B.tmp - Deleted
C:\WINDOWS\Temp\win30C.tmp - Deleted
C:\WINDOWS\Temp\win30D.tmp - Deleted
C:\WINDOWS\Temp\win30E.tmp - Deleted
C:\WINDOWS\Temp\win30F.tmp - Deleted
C:\WINDOWS\Temp\win31.tmp - Deleted
C:\WINDOWS\Temp\win310.tmp - Deleted
C:\WINDOWS\Temp\win311.tmp - Deleted
C:\WINDOWS\Temp\win312.tmp - Deleted
C:\WINDOWS\Temp\win313.tmp - Deleted
C:\WINDOWS\Temp\win314.tmp - Deleted
C:\WINDOWS\Temp\win315.tmp - Deleted
C:\WINDOWS\Temp\win316.tmp - Deleted
C:\WINDOWS\Temp\win317.tmp - Deleted
C:\WINDOWS\Temp\win318.tmp - Deleted
C:\WINDOWS\Temp\win319.tmp - Deleted
C:\WINDOWS\Temp\win31A.tmp - Deleted
C:\WINDOWS\Temp\win31B.tmp - Deleted
C:\WINDOWS\Temp\win31C.tmp - Deleted
C:\WINDOWS\Temp\win31D.tmp - Deleted
C:\WINDOWS\Temp\win31E.tmp - Deleted
C:\WINDOWS\Temp\win31F.tmp - Deleted
C:\WINDOWS\Temp\win32.tmp - Deleted
C:\WINDOWS\Temp\win320.tmp - Deleted
C:\WINDOWS\Temp\win321.tmp - Deleted
C:\WINDOWS\Temp\win322.tmp - Deleted
C:\WINDOWS\Temp\win323.tmp - Deleted
C:\WINDOWS\Temp\win324.tmp - Deleted
C:\WINDOWS\Temp\win325.tmp - Deleted
C:\WINDOWS\Temp\win326.tmp - Deleted
C:\WINDOWS\Temp\win327.tmp - Deleted
C:\WINDOWS\Temp\win328.tmp - Deleted
C:\WINDOWS\Temp\win329.tmp - Deleted
C:\WINDOWS\Temp\win32A.tmp - Deleted
C:\WINDOWS\Temp\win32B.tmp - Deleted
C:\WINDOWS\Temp\win32C.tmp - Deleted
C:\WINDOWS\Temp\win32D.tmp - Deleted
C:\WINDOWS\Temp\win32E.tmp - Deleted
C:\WINDOWS\Temp\win32F.tmp - Deleted
C:\WINDOWS\Temp\win33.tmp - Deleted
C:\WINDOWS\Temp\win330.tmp - Deleted
C:\WINDOWS\Temp\win331.tmp - Deleted
C:\WINDOWS\Temp\win332.tmp - Deleted
C:\WINDOWS\Temp\win333.tmp - Deleted
C:\WINDOWS\Temp\win334.tmp - Deleted
C:\WINDOWS\Temp\win335.tmp - Deleted
C:\WINDOWS\Temp\win336.tmp - Deleted
C:\WINDOWS\Temp\win337.tmp - Deleted
C:\WINDOWS\Temp\win338.tmp - Deleted
C:\WINDOWS\Temp\win339.tmp - Deleted
C:\WINDOWS\Temp\win33A.tmp - Deleted
C:\WINDOWS\Temp\win33B.tmp - Deleted
C:\WINDOWS\Temp\win33C.tmp - Deleted
C:\WINDOWS\Temp\win33D.tmp - Deleted
C:\WINDOWS\Temp\win33E.tmp - Deleted
C:\WINDOWS\Temp\win33F.tmp - Deleted
C:\WINDOWS\Temp\win34.tmp - Deleted
C:\WINDOWS\Temp\win340.tmp - Deleted
C:\WINDOWS\Temp\win341.tmp - Deleted
C:\WINDOWS\Temp\win342.tmp - Deleted
C:\WINDOWS\Temp\win343.tmp - Deleted
C:\WINDOWS\Temp\win344.tmp - Deleted
C:\WINDOWS\Temp\win345.tmp - Deleted
C:\WINDOWS\Temp\win346.tmp - Deleted
C:\WINDOWS\Temp\win347.tmp - Deleted
C:\WINDOWS\Temp\win348.tmp - Deleted
C:\WINDOWS\Temp\win349.tmp - Deleted
C:\WINDOWS\Temp\win34A.tmp - Deleted
C:\WINDOWS\Temp\win34B.tmp - Deleted
C:\WINDOWS\Temp\win34C.tmp - Deleted
C:\WINDOWS\Temp\win34D.tmp - Deleted
C:\WINDOWS\Temp\win34E.tmp - Deleted
C:\WINDOWS\Temp\win34F.tmp - Deleted
C:\WINDOWS\Temp\win35.tmp - Deleted
C:\WINDOWS\Temp\win350.tmp - Deleted
C:\WINDOWS\Temp\win351.tmp - Deleted
C:\WINDOWS\Temp\win352.tmp - Deleted
C:\WINDOWS\Temp\win353.tmp - Deleted
C:\WINDOWS\Temp\win354.tmp - Deleted
C:\WINDOWS\Temp\win355.tmp - Deleted
C:\WINDOWS\Temp\win356.tmp - Deleted
C:\WINDOWS\Temp\win357.tmp - Deleted
C:\WINDOWS\Temp\win358.tmp - Deleted
C:\WINDOWS\Temp\win359.tmp - Deleted
C:\WINDOWS\Temp\win35A.tmp - Deleted
C:\WINDOWS\Temp\win35B.tmp - Deleted
C:\WINDOWS\Temp\win35C.tmp - Deleted
C:\WINDOWS\Temp\win35D.tmp - Deleted
C:\WINDOWS\Temp\win35E.tmp - Deleted
C:\WINDOWS\Temp\win35F.tmp - Deleted
C:\WINDOWS\Temp\win36.tmp - Deleted
C:\WINDOWS\Temp\win360.tmp - Deleted
C:\WINDOWS\Temp\win361.tmp - Deleted
C:\WINDOWS\Temp\win362.tmp - Deleted
C:\WINDOWS\Temp\win363.tmp - Deleted
C:\WINDOWS\Temp\win364.tmp - Deleted
C:\WINDOWS\Temp\win365.tmp - Deleted
C:\WINDOWS\Temp\win366.tmp - Deleted
C:\WINDOWS\Temp\win367.tmp - Deleted
C:\WINDOWS\Temp\win368.tmp - Deleted
C:\WINDOWS\Temp\win369.tmp - Deleted
C:\WINDOWS\Temp\win36A.tmp - Deleted
C:\WINDOWS\Temp\win36B.tmp - Deleted
C:\WINDOWS\Temp\win36C.tmp - Deleted
C:\WINDOWS\Temp\win36D.tmp - Deleted
C:\WINDOWS\Temp\win36E.tmp - Deleted
C:\WINDOWS\Temp\win36F.tmp - Deleted
C:\WINDOWS\Temp\win37.tmp - Deleted
C:\WINDOWS\Temp\win370.tmp - Deleted
C:\WINDOWS\Temp\win371.tmp - Deleted
C:\WINDOWS\Temp\win372.tmp - Deleted
C:\WINDOWS\Temp\win373.tmp - Deleted
C:\WINDOWS\Temp\win374.tmp - Deleted
C:\WINDOWS\Temp\win375.tmp - Deleted
C:\WINDOWS\Temp\win376.tmp - Deleted
C:\WINDOWS\Temp\win377.tmp - Deleted
C:\WINDOWS\Temp\win378.tmp - Deleted
C:\WINDOWS\Temp\win379.tmp - Deleted
C:\WINDOWS\Temp\win37A.tmp - Deleted
C:\WINDOWS\Temp\win37B.tmp - Deleted
C:\WINDOWS\Temp\win37C.tmp - Deleted
C:\WINDOWS\Temp\win37D.tmp - Deleted
C:\WINDOWS\Temp\win37E.tmp - Deleted
C:\WINDOWS\Temp\win37F.tmp - Deleted
C:\WINDOWS\Temp\win38.tmp - Deleted
C:\WINDOWS\Temp\win380.tmp - Deleted
C:\WINDOWS\Temp\win381.tmp - Deleted
C:\WINDOWS\Temp\win382.tmp - Deleted
C:\WINDOWS\Temp\win383.tmp - Deleted
C:\WINDOWS\Temp\win384.tmp - Deleted
C:\WINDOWS\Temp\win385.tmp - Deleted
C:\WINDOWS\Temp\win386.tmp - Deleted
C:\WINDOWS\Temp\win387.tmp - Deleted
C:\WINDOWS\Temp\win388.tmp - Deleted
C:\WINDOWS\Temp\win389.tmp - Deleted
C:\WINDOWS\Temp\win38A.tmp - Deleted
C:\WINDOWS\Temp\win38B.tmp - Deleted
C:\WINDOWS\Temp\win38C.tmp - Deleted
C:\WINDOWS\Temp\win38D.tmp - Deleted
C:\WINDOWS\Temp\win38E.tmp - Deleted
C:\WINDOWS\Temp\win38F.tmp - Deleted
C:\WINDOWS\Temp\win39.tmp - Deleted
C:\WINDOWS\Temp\win390.tmp - Deleted
C:\WINDOWS\Temp\win391.tmp - Deleted
C:\WINDOWS\Temp\win392.tmp - Deleted
C:\WINDOWS\Temp\win393.tmp - Deleted
C:\WINDOWS\Temp\win394.tmp - Deleted
C:\WINDOWS\Temp\win395.tmp - Deleted
C:\WINDOWS\Temp\win396.tmp - Deleted
C:\WINDOWS\Temp\win397.tmp - Deleted
C:\WINDOWS\Temp\win398.tmp - Deleted
C:\WINDOWS\Temp\win399.tmp - Deleted
C:\WINDOWS\Temp\win39A.tmp - Deleted
C:\WINDOWS\Temp\win39B.tmp - Deleted
C:\WINDOWS\Temp\win39C.tmp - Deleted
C:\WINDOWS\Temp\win39D.tmp - Deleted
C:\WINDOWS\Temp\win39E.tmp - Deleted
C:\WINDOWS\Temp\win39F.tmp - Deleted
C:\WINDOWS\Temp\win3A.tmp - Deleted
C:\WINDOWS\Temp\win3A0.tmp - Deleted
C:\WINDOWS\Temp\win3A1.tmp - Deleted
C:\WINDOWS\Temp\win3A2.tmp - Deleted
C:\WINDOWS\Temp\win3A3.tmp - Deleted
C:\WINDOWS\Temp\win3A4.tmp - Deleted
C:\WINDOWS\Temp\win3A5.tmp - Deleted
C:\WINDOWS\Temp\win3A6.tmp - Deleted
C:\WINDOWS\Temp\win3A7.tmp - Deleted
C:\WINDOWS\Temp\win3A8.tmp - Deleted
C:\WINDOWS\Temp\win3A9.tmp - Deleted
C:\WINDOWS\Temp\win3AA.tmp - Deleted
C:\WINDOWS\Temp\win3AB.tmp - Deleted
C:\WINDOWS\Temp\win3AC.tmp - Deleted
C:\WINDOWS\Temp\win3AD.tmp - Deleted
C:\WINDOWS\Temp\win3AE.tmp - Deleted
C:\WINDOWS\Temp\win3AF.tmp - Deleted
C:\WINDOWS\Temp\win3B.tmp - Deleted
C:\WINDOWS\Temp\win3B0.tmp - Deleted
C:\WINDOWS\Temp\win3B1.tmp - Deleted
C:\WINDOWS\Temp\win3B2.tmp - Deleted
C:\WINDOWS\Temp\win3B3.tmp - Deleted
C:\WINDOWS\Temp\win3B4.tmp - Deleted
C:\WINDOWS\Temp\win3B5.tmp - Deleted
C:\WINDOWS\Temp\win3B6.tmp - Deleted
C:\WINDOWS\Temp\win3B7.tmp - Deleted
C:\WINDOWS\Temp\win3B8.tmp - Deleted
C:\WINDOWS\Temp\win3B9.tmp - Deleted
C:\WINDOWS\Temp\win3BA.tmp - Deleted
C:\WINDOWS\Temp\win3BB.tmp - Deleted
C:\WINDOWS\Temp\win3BC.tmp - Deleted
C:\WINDOWS\Temp\win3BD.tmp - Deleted
C:\WINDOWS\Temp\win3BE.tmp - Deleted
C:\WINDOWS\Temp\win3BF.tmp - Deleted
C:\WINDOWS\Temp\win3C.tmp - Deleted
C:\WINDOWS\Temp\win3C0.tmp - Deleted
C:\WINDOWS\Temp\win3C1.tmp - Deleted
C:\WINDOWS\Temp\win3C2.tmp - Deleted
C:\WINDOWS\Temp\win3C3.tmp - Deleted
C:\WINDOWS\Temp\win3C4.tmp - Deleted
C:\WINDOWS\Temp\win3C5.tmp - Deleted
C:\WINDOWS\Temp\win3C6.tmp - Deleted
C:\WINDOWS\Temp\win3C7.tmp - Deleted
C:\WINDOWS\Temp\win3C8.tmp - Deleted
C:\WINDOWS\Temp\win3C9.tmp - Deleted
C:\WINDOWS\Temp\win3CA.tmp - Deleted
C:\WINDOWS\Temp\win3CB.tmp - Deleted
C:\WINDOWS\Temp\win3CC.tmp - Deleted
C:\WINDOWS\Temp\win3CD.tmp - Deleted
C:\WINDOWS\Temp\win3CE.tmp - Deleted
C:\WINDOWS\Temp\win3CF.tmp - Deleted
C:\WINDOWS\Temp\win3D.tmp - Deleted
C:\WINDOWS\Temp\win3D0.tmp - Deleted
C:\WINDOWS\Temp\win3D1.tmp - Deleted
C:\WINDOWS\Temp\win3D2.tmp - Deleted
C:\WINDOWS\Temp\win3D3.tmp - Deleted
C:\WINDOWS\Temp\win3D4.tmp - Deleted
C:\WINDOWS\Temp\win3D5.tmp - Deleted
C:\WINDOWS\Temp\win3D6.tmp - Deleted
C:\WINDOWS\Temp\win3D7.tmp - Deleted
C:\WINDOWS\Temp\win3D8.tmp - Deleted
C:\WINDOWS\Temp\win3D9.tmp - Deleted
C:\WINDOWS\Temp\win3DA.tmp - Deleted
C:\WINDOWS\Temp\win3DB.tmp - Deleted
C:\WINDOWS\Temp\win3DC.tmp - Deleted
C:\WINDOWS\Temp\win3DD.tmp - Deleted
C:\WINDOWS\Temp\win3DE.tmp - Deleted
C:\WINDOWS\Temp\win3DF.tmp - Deleted
C:\WINDOWS\Temp\win3E.tmp - Deleted
C:\WINDOWS\Temp\win3E0.tmp - Deleted
C:\WINDOWS\Temp\win3E1.tmp - Deleted
C:\WINDOWS\Temp\win3E2.tmp - Deleted
C:\WINDOWS\Temp\win3E3.tmp - Deleted
C:\WINDOWS\Temp\win3E4.tmp - Deleted
C:\WINDOWS\Temp\win3E5.tmp - Deleted
C:\WINDOWS\Temp\win3E6.tmp - Deleted
C:\WINDOWS\Temp\win3E7.tmp - Deleted
C:\WINDOWS\Temp\win3E8.tmp - Deleted
C:\WINDOWS\Temp\win3E9.tmp - Deleted
C:\WINDOWS\Temp\win3EA.tmp - Deleted
C:\WINDOWS\Temp\win3EB.tmp - Deleted
C:\WINDOWS\Temp\win3EC.tmp - Deleted
C:\WINDOWS\Temp\win3ED.tmp - Deleted
C:\WINDOWS\Temp\win3EE.tmp - Deleted
C:\WINDOWS\Temp\win3EF.tmp - Deleted
C:\WINDOWS\Temp\win3F.tmp - Deleted
C:\WINDOWS\Temp\win3F0.tmp - Deleted
C:\WINDOWS\Temp\win3F1.tmp - Deleted
C:\WINDOWS\Temp\win3F2.tmp - Deleted
C:\WINDOWS\Temp\win3F3.tmp - Deleted
C:\WINDOWS\Temp\win3F4.tmp - Deleted
C:\WINDOWS\Temp\win3F5.tmp - Deleted
C:\WINDOWS\Temp\win3F6.tmp - Deleted
C:\WINDOWS\Temp\win3F7.tmp - Deleted
C:\WINDOWS\Temp\win3F8.tmp - Deleted
C:\WINDOWS\Temp\win3F9.tmp - Deleted
C:\WINDOWS\Temp\win3FA.tmp - Deleted
C:\WINDOWS\Temp\win3FB.tmp - Deleted
C:\WINDOWS\Temp\win3FC.tmp - Deleted
C:\WINDOWS\Temp\win3FD.tmp - Deleted
C:\WINDOWS\Temp\win3FE.tmp - Deleted
C:\WINDOWS\Temp\win3FF.tmp - Deleted
C:\WINDOWS\Temp\win4.tmp - Deleted
C:\WINDOWS\Temp\win40.tmp - Deleted
C:\WINDOWS\Temp\win400.tmp - Deleted
C:\WINDOWS\Temp\win401.tmp - Deleted
C:\WINDOWS\Temp\win402.tmp - Deleted
C:\WINDOWS\Temp\win403.tmp - Deleted
C:\WINDOWS\Temp\win404.tmp - Deleted
C:\WINDOWS\Temp\win405.tmp - Deleted
C:\WINDOWS\Temp\win406.tmp - Deleted
C:\WINDOWS\Temp\win407.tmp - Deleted
C:\WINDOWS\Temp\win408.tmp - Deleted
C:\WINDOWS\Temp\win409.tmp - Deleted
C:\WINDOWS\Temp\win40A.tmp - Deleted
C:\WINDOWS\Temp\win40B.tmp - Deleted
C:\WINDOWS\Temp\win40C.tmp - Deleted
C:\WINDOWS\Temp\win40D.tmp - Deleted
C:\WINDOWS\Temp\win40E.tmp - Deleted
C:\WINDOWS\Temp\win40F.tmp - Deleted
C:\WINDOWS\Temp\win41.tmp - Deleted
C:\WINDOWS\Temp\win410.tmp - Deleted
C:\WINDOWS\Temp\win411.tmp - Deleted
C:\WINDOWS\Temp\win412.tmp - Deleted
C:\WINDOWS\Temp\win413.tmp - Deleted
C:\WINDOWS\Temp\win414.tmp - Deleted
C:\WINDOWS\Temp\win415.tmp - Deleted
C:\WINDOWS\Temp\win416.tmp - Deleted
C:\WINDOWS\Temp\win417.tmp - Deleted
C:\WINDOWS\Temp\win418.tmp - Deleted
C:\WINDOWS\Temp\win419.tmp - Deleted
C:\WINDOWS\Temp\win41A.tmp - Deleted
C:\WINDOWS\Temp\win41B.tmp - Deleted
C:\WINDOWS\Temp\win41C.tmp - Deleted
C:\WINDOWS\Temp\win41D.tmp - Deleted
C:\WINDOWS\Temp\win41E.tmp - Deleted
C:\WINDOWS\Temp\win41F.tmp - Deleted
C:\WINDOWS\Temp\win42.tmp - Deleted
C:\WINDOWS\Temp\win420.tmp - Deleted
C:\WINDOWS\Temp\win421.tmp - Deleted
C:\WINDOWS\Temp\win422.tmp - Deleted
C:\WINDOWS\Temp\win423.tmp - Deleted
C:\WINDOWS\Temp\win424.tmp - Deleted
C:\WINDOWS\Temp\win425.tmp - Deleted
C:\WINDOWS\Temp\win426.tmp - Deleted
C:\WINDOWS\Temp\win427.tmp - Deleted
C:\WINDOWS\Temp\win428.tmp - Deleted
C:\WINDOWS\Temp\win429.tmp - Deleted
C:\WINDOWS\Temp\win42A.tmp - Deleted
C:\WINDOWS\Temp\win42B.tmp - Deleted
C:\WINDOWS\Temp\win42C.tmp - Deleted
C:\WINDOWS\Temp\win42D.tmp - Deleted
C:\WINDOWS\Temp\win42E.tmp - Deleted
C:\WINDOWS\Temp\win42F.tmp - Deleted
C:\WINDOWS\Temp\win43.tmp - Deleted
C:\WINDOWS\Temp\win430.tmp - Deleted
C:\WINDOWS\Temp\win431.tmp - Deleted
C:\WINDOWS\Temp\win432.tmp - Deleted
C:\WINDOWS\Temp\win433.tmp - Deleted
C:\WINDOWS\Temp\win434.tmp - Deleted
C:\WINDOWS\Temp\win435.tmp - Deleted
C:\WINDOWS\Temp\win436.tmp - Deleted
C:\WINDOWS\Temp\win437.tmp - Deleted
C:\WINDOWS\Temp\win438.tmp - Deleted
C:\WINDOWS\Temp\win439.tmp - Deleted
C:\WINDOWS\Temp\win43A.tmp - Deleted
C:\WINDOWS\Temp\win43B.tmp - Deleted
C:\WINDOWS\Temp\win43C.tmp - Deleted
C:\WINDOWS\Temp\win43D.tmp - Deleted
C:\WINDOWS\Temp\win43E.tmp - Deleted
C:\WINDOWS\Temp\win43F.tmp - Deleted
C:\WINDOWS\Temp\win44.tmp - Deleted
C:\WINDOWS\Temp\win440.tmp - Deleted
C:\WINDOWS\Temp\win441.tmp - Deleted
C:\WINDOWS\Temp\win442.tmp - Deleted
C:\WINDOWS\Temp\win443.tmp - Deleted
C:\WINDOWS\Temp\win444.tmp - Deleted
C:\WINDOWS\Temp\win445.tmp - Deleted
C:\WINDOWS\Temp\win446.tmp - Deleted
C:\WINDOWS\Temp\win447.tmp - Deleted
C:\WINDOWS\Temp\win448.tmp - Deleted
C:\WINDOWS\Temp\win449.tmp - Deleted
C:\WINDOWS\Temp\win44A.tmp - Deleted
C:\WINDOWS\Temp\win44B.tmp - Deleted
C:\WINDOWS\Temp\win44C.tmp - Deleted
C:\WINDOWS\Temp\win44D.tmp - Deleted
C:\WINDOWS\Temp\win44E.tmp - Deleted
C:\WINDOWS\Temp\win44F.tmp - Deleted
C:\WINDOWS\Temp\win45.tmp - Deleted
C:\WINDOWS\Temp\win450.tmp - Deleted
C:\WINDOWS\Temp\win451.tmp - Deleted
C:\WINDOWS\Temp\win452.tmp - Deleted
C:\WINDOWS\Temp\win453.tmp - Deleted
C:\WINDOWS\Temp\win454.tmp - Deleted
C:\WINDOWS\Temp\win455.tmp - Deleted
C:\WINDOWS\Temp\win456.tmp - Deleted
C:\WINDOWS\Temp\win457.tmp - Deleted
C:\WINDOWS\Temp\win458.tmp - Deleted
C:\WINDOWS\Temp\win459.tmp - Deleted
C:\WINDOWS\Temp\win45A.tmp - Deleted
C:\WINDOWS\Temp\win45B.tmp - Deleted
C:\WINDOWS\Temp\win45C.tmp - Deleted
C:\WINDOWS\Temp\win45D.tmp - Deleted
C:\WINDOWS\Temp\win45E.tmp - Deleted
C:\WINDOWS\Temp\win45F.tmp - Deleted
C:\WINDOWS\Temp\win46.tmp - Deleted
C:\WINDOWS\Temp\win460.tmp - Deleted
C:\WINDOWS\Temp\win461.tmp - Deleted
C:\WINDOWS\Temp\win462.tmp - Deleted
C:\WINDOWS\Temp\win463.tmp - Deleted
C:\WINDOWS\Temp\win464.tmp - Deleted
C:\WINDOWS\Temp\win465.tmp - Deleted
C:\WINDOWS\Temp\win466.tmp - Deleted
C:\WINDOWS\Temp\win467.tmp - Deleted
C:\WINDOWS\Temp\win468.tmp - Deleted
C:\WINDOWS\Temp\win469.tmp - Deleted
C:\WINDOWS\Temp\win46A.tmp - Deleted
C:\WINDOWS\Temp\win46B.tmp - Deleted
C:\WINDOWS\Temp\win46C.tmp - Deleted
C:\WINDOWS\Temp\win46D.tmp - Deleted
C:\WINDOWS\Temp\win46E.tmp - Deleted
C:\WINDOWS\Temp\win46F.tmp - Deleted
C:\WINDOWS\Temp\win47.tmp - Deleted
C:\WINDOWS\Temp\win470.tmp - Deleted
C:\WINDOWS\Temp\win471.tmp - Deleted
C:\WINDOWS\Temp\win472.tmp - Deleted
C:\WINDOWS\Temp\win473.tmp - Deleted
C:\WINDOWS\Temp\win474.tmp - Deleted
C:\WINDOWS\Temp\win475.tmp - Deleted
C:\WINDOWS\Temp\win476.tmp - Deleted
C:\WINDOWS\Temp\win477.tmp - Deleted
C:\WINDOWS\Temp\win478.tmp - Deleted
C:\WINDOWS\Temp\win479.tmp - Deleted
C:\WINDOWS\Temp\win47A.tmp - Deleted
C:\WINDOWS\Temp\win47B.tmp - Deleted
C:\WINDOWS\Temp\win47C.tmp - Deleted
C:\WINDOWS\Temp\win47D.tmp - Deleted
C:\WINDOWS\Temp\win47E.tmp - Deleted
C:\WINDOWS\Temp\win47F.tmp - Deleted
C:\WINDOWS\Temp\win48.tmp - Deleted
C:\WINDOWS\Temp\win480.tmp - Deleted
C:\WINDOWS\Temp\win481.tmp - Deleted
C:\WINDOWS\Temp\win482.tmp - Deleted
C:\WINDOWS\Temp\win483.tmp - Deleted
C:\WINDOWS\Temp\win484.tmp - Deleted
C:\WINDOWS\Temp\win485.tmp - Deleted
C:\WINDOWS\Temp\win486.tmp - Deleted
C:\WINDOWS\Temp\win487.tmp - Deleted
C:\WINDOWS\Temp\win488.tmp - Deleted
C:\WINDOWS\Temp\win489.tmp - Deleted
C:\WINDOWS\Temp\win48A.tmp - Deleted
C:\WINDOWS\Temp\win48B.tmp - Deleted
C:\WINDOWS\Temp\win48C.tmp - Deleted
C:\WINDOWS\Temp\win48D.tmp - Deleted
C:\WINDOWS\Temp\win48E.tmp - Deleted
C:\WINDOWS\Temp\win48F.tmp - Deleted
C:\WINDOWS\Temp\win49.tmp - Deleted
C:\WINDOWS\Temp\win490.tmp - Deleted
C:\WINDOWS\Temp\win491.tmp - Deleted
C:\WINDOWS\Temp\win492.tmp - Deleted
C:\WINDOWS\Temp\win493.tmp - Deleted
C:\WINDOWS\Temp\win494.tmp - Deleted
C:\WINDOWS\Temp\win495.tmp - Deleted
C:\WINDOWS\Temp\win496.tmp - Deleted
C:\WINDOWS\Temp\win497.tmp - Deleted
C:\WINDOWS\Temp\win498.tmp - Deleted
C:\WINDOWS\Temp\win499.tmp - Deleted
C:\WINDOWS\Temp\win49A.tmp - Deleted
C:\WINDOWS\Temp\win49B.tmp - Deleted
C:\WINDOWS\Temp\win49C.tmp - Deleted
C:\WINDOWS\Temp\win49D.tmp - Deleted
C:\WINDOWS\Temp\win49E.tmp - Deleted
C:\WINDOWS\Temp\win49F.tmp - Deleted
C:\WINDOWS\Temp\win4A.tmp - Deleted
C:\WINDOWS\Temp\win4A0.tmp - Deleted
C:\WINDOWS\Temp\win4A1.tmp - Deleted
C:\WINDOWS\Temp\win4A2.tmp - Deleted
C:\WINDOWS\Temp\win4A3.tmp - Deleted
C:\WINDOWS\Temp\win4A4.tmp - Deleted
C:\WINDOWS\Temp\win4A5.tmp - Deleted
C:\WINDOWS\Temp\win4A6.tmp - Deleted
C:\WINDOWS\Temp\win4A7.tmp - Deleted
C:\WINDOWS\Temp\win4A8.tmp - Deleted
C:\WINDOWS\Temp\win4A9.tmp - Deleted
C:\WINDOWS\Temp\win4AA.tmp - Deleted
C:\WINDOWS\Temp\win4AB.tmp - Deleted
C:\WINDOWS\Temp\win4AC.tmp - Deleted
C:\WINDOWS\Temp\win4AD.tmp - Deleted
C:\WINDOWS\Temp\win4AE.tmp - Deleted
C:\WINDOWS\Temp\win4AF.tmp - Deleted
C:\WINDOWS\Temp\win4B.tmp - Deleted
C:\WINDOWS\Temp\win4B0.tmp - Deleted
C:\WINDOWS\Temp\win4B1.tmp - Deleted
C:\WINDOWS\Temp\win4B2.tmp - Deleted
C:\WINDOWS\Temp\win4B3.tmp - Deleted
C:\WINDOWS\Temp\win4B4.tmp - Deleted
C:\WINDOWS\Temp\win4B5.tmp - Deleted
C:\WINDOWS\Temp\win4B6.tmp - Deleted
C:\WINDOWS\Temp\win4B7.tmp - Deleted
C:\WINDOWS\Temp\win4B8.tmp - Deleted
C:\WINDOWS\Temp\win4B9.tmp - Deleted
C:\WINDOWS\Temp\win4BA.tmp - Deleted
C:\WINDOWS\Temp\win4BB.tmp - Deleted
C:\WINDOWS\Temp\win4BC.tmp - Deleted
C:\WINDOWS\Temp\win4BD.tmp - Deleted
C:\WINDOWS\Temp\win4BE.tmp - Deleted
C:\WINDOWS\Temp\win4BF.tmp - Deleted
C:\WINDOWS\Temp\win4C.tmp - Deleted
C:\WINDOWS\Temp\win4C0.tmp - Deleted
C:\WINDOWS\Temp\win4C1.tmp - Deleted
C:\WINDOWS\Temp\win4C2.tmp - Deleted
C:\WINDOWS\Temp\win4C3.tmp - Deleted
C:\WINDOWS\Temp\win4C4.tmp - Deleted
C:\WINDOWS\Temp\win4C5.tmp - Deleted
C:\WINDOWS\Temp\win4C6.tmp - Deleted
C:\WINDOWS\Temp\win4C7.tmp - Deleted
C:\WINDOWS\Temp\win4C8.tmp - Deleted
C:\WINDOWS\Temp\win4C9.tmp - Deleted
C:\WINDOWS\Temp\win4CA.tmp - Deleted
C:\WINDOWS\Temp\win4CB.tmp - Deleted
C:\WINDOWS\Temp\win4CC.tmp - Deleted
C:\WINDOWS\Temp\win4CD.tmp - Deleted
C:\WINDOWS\Temp\win4CE.tmp - Deleted
C:\WINDOWS\Temp\win4CF.tmp - Deleted
C:\WINDOWS\Temp\win4D.tmp - Deleted
C:\WINDOWS\Temp\win4D0.tmp - Deleted
C:\WINDOWS\Temp\win4D1.tmp - Deleted
C:\WINDOWS\Temp\win4D2.tmp - Deleted
C:\WINDOWS\Temp\win4D3.tmp - Deleted
C:\WINDOWS\Temp\win4D4.tmp - Deleted
C:\WINDOWS\Temp\win4D5.tmp - Deleted
C:\WINDOWS\Temp\win4D6.tmp - Deleted
C:\WINDOWS\Temp\win4D7.tmp - Deleted
C:\WINDOWS\Temp\win4D8.tmp - Deleted
C:\WINDOWS\Temp\win4D9.tmp - Deleted
C:\WINDOWS\Temp\win4DA.tmp - Deleted
C:\WINDOWS\Temp\win4DB.tmp - Deleted
C:\WINDOWS\Temp\win4DC.tmp - Deleted
C:\WINDOWS\Temp\win4DD.tmp - Deleted
C:\WINDOWS\Temp\win4DE.tmp - Deleted
C:\WINDOWS\Temp\win4DF.tmp - Deleted
C:\WINDOWS\Temp\win4E.tmp - Deleted
C:\WINDOWS\Temp\win4E0.tmp - Deleted
C:\WINDOWS\Temp\win4E1.tmp - Deleted
C:\WINDOWS\Temp\win4E2.tmp - Deleted
C:\WINDOWS\Temp\win4E3.tmp - Deleted
C:\WINDOWS\Temp\win4E4.tmp - Deleted
C:\WINDOWS\Temp\win4E5.tmp - Deleted
C:\WINDOWS\Temp\win4E6.tmp - Deleted
C:\WINDOWS\Temp\win4E7.tmp - Deleted
C:\WINDOWS\Temp\win4E8.tmp - Deleted
C:\WINDOWS\Temp\win4E9.tmp - Deleted
C:\WINDOWS\Temp\win4EA.tmp - Deleted
C:\WINDOWS\Temp\win4EB.tmp - Deleted
C:\WINDOWS\Temp\win4EC.tmp - Deleted
C:\WINDOWS\Temp\win4ED.tmp - Deleted
C:\WINDOWS\Temp\win4EE.tmp - Deleted
C:\WINDOWS\Temp\win4EF.tmp - Deleted
C:\WINDOWS\Temp\win4F.tmp - Deleted
C:\WINDOWS\Temp\win4F0.tmp - Deleted
C:\WINDOWS\Temp\win4F1.tmp - Deleted
C:\WINDOWS\Temp\win4F2.tmp - Deleted
C:\WINDOWS\Temp\win4F3.tmp - Deleted
C:\WINDOWS\Temp\win4F4.tmp - Deleted
C:\WINDOWS\Temp\win4F5.tmp - Deleted
C:\WINDOWS\Temp\win4F6.tmp - Deleted
C:\WINDOWS\Temp\win4F7.tmp - Deleted
C:\WINDOWS\Temp\win4F8.tmp - Deleted

#4 Alex Kremer

Alex Kremer
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 16 January 2007 - 03:34 PM

C:\WINDOWS\Temp\win4F9.tmp - Deleted
C:\WINDOWS\Temp\win4FA.tmp - Deleted
C:\WINDOWS\Temp\win4FB.tmp - Deleted
C:\WINDOWS\Temp\win4FC.tmp - Deleted
C:\WINDOWS\Temp\win4FD.tmp - Deleted
C:\WINDOWS\Temp\win4FE.tmp - Deleted
C:\WINDOWS\Temp\win4FF.tmp - Deleted
C:\WINDOWS\Temp\win5.tmp - Deleted
C:\WINDOWS\Temp\win50.tmp - Deleted
C:\WINDOWS\Temp\win500.tmp - Deleted
C:\WINDOWS\Temp\win501.tmp - Deleted
C:\WINDOWS\Temp\win502.tmp - Deleted
C:\WINDOWS\Temp\win503.tmp - Deleted
C:\WINDOWS\Temp\win504.tmp - Deleted
C:\WINDOWS\Temp\win505.tmp - Deleted
C:\WINDOWS\Temp\win506.tmp - Deleted
C:\WINDOWS\Temp\win507.tmp - Deleted
C:\WINDOWS\Temp\win508.tmp - Deleted
C:\WINDOWS\Temp\win509.tmp - Deleted
C:\WINDOWS\Temp\win50A.tmp - Deleted
C:\WINDOWS\Temp\win50B.tmp - Deleted
C:\WINDOWS\Temp\win50C.tmp - Deleted
C:\WINDOWS\Temp\win50D.tmp - Deleted
C:\WINDOWS\Temp\win50E.tmp - Deleted
C:\WINDOWS\Temp\win50F.tmp - Deleted
C:\WINDOWS\Temp\win51.tmp - Deleted
C:\WINDOWS\Temp\win510.tmp - Deleted
C:\WINDOWS\Temp\win511.tmp - Deleted
C:\WINDOWS\Temp\win512.tmp - Deleted
C:\WINDOWS\Temp\win513.tmp - Deleted
C:\WINDOWS\Temp\win514.tmp - Deleted
C:\WINDOWS\Temp\win515.tmp - Deleted
C:\WINDOWS\Temp\win516.tmp - Deleted
C:\WINDOWS\Temp\win517.tmp - Deleted
C:\WINDOWS\Temp\win518.tmp - Deleted
C:\WINDOWS\Temp\win519.tmp - Deleted
C:\WINDOWS\Temp\win51A.tmp - Deleted
C:\WINDOWS\Temp\win51B.tmp - Deleted
C:\WINDOWS\Temp\win51C.tmp - Deleted
C:\WINDOWS\Temp\win51D.tmp - Deleted
C:\WINDOWS\Temp\win51E.tmp - Deleted
C:\WINDOWS\Temp\win51F.tmp - Deleted
C:\WINDOWS\Temp\win52.tmp - Deleted
C:\WINDOWS\Temp\win520.tmp - Deleted
C:\WINDOWS\Temp\win521.tmp - Deleted
C:\WINDOWS\Temp\win522.tmp - Deleted
C:\WINDOWS\Temp\win523.tmp - Deleted
C:\WINDOWS\Temp\win524.tmp - Deleted
C:\WINDOWS\Temp\win525.tmp - Deleted
C:\WINDOWS\Temp\win526.tmp - Deleted
C:\WINDOWS\Temp\win527.tmp - Deleted
C:\WINDOWS\Temp\win528.tmp - Deleted
C:\WINDOWS\Temp\win529.tmp - Deleted
C:\WINDOWS\Temp\win52A.tmp - Deleted
C:\WINDOWS\Temp\win52B.tmp - Deleted
C:\WINDOWS\Temp\win52C.tmp - Deleted
C:\WINDOWS\Temp\win52D.tmp - Deleted
C:\WINDOWS\Temp\win52E.tmp - Deleted
C:\WINDOWS\Temp\win52F.tmp - Deleted
C:\WINDOWS\Temp\win53.tmp - Deleted
C:\WINDOWS\Temp\win530.tmp - Deleted
C:\WINDOWS\Temp\win531.tmp - Deleted
C:\WINDOWS\Temp\win532.tmp - Deleted
C:\WINDOWS\Temp\win533.tmp - Deleted
C:\WINDOWS\Temp\win534.tmp - Deleted
C:\WINDOWS\Temp\win535.tmp - Deleted
C:\WINDOWS\Temp\win536.tmp - Deleted
C:\WINDOWS\Temp\win537.tmp - Deleted
C:\WINDOWS\Temp\win538.tmp - Deleted
C:\WINDOWS\Temp\win539.tmp - Deleted
C:\WINDOWS\Temp\win53A.tmp - Deleted
C:\WINDOWS\Temp\win53B.tmp - Deleted
C:\WINDOWS\Temp\win53C.tmp - Deleted
C:\WINDOWS\Temp\win53D.tmp - Deleted
C:\WINDOWS\Temp\win53E.tmp - Deleted
C:\WINDOWS\Temp\win53F.tmp - Deleted
C:\WINDOWS\Temp\win54.tmp - Deleted
C:\WINDOWS\Temp\win540.tmp - Deleted
C:\WINDOWS\Temp\win541.tmp - Deleted
C:\WINDOWS\Temp\win542.tmp - Deleted
C:\WINDOWS\Temp\win543.tmp - Deleted
C:\WINDOWS\Temp\win544.tmp - Deleted
C:\WINDOWS\Temp\win545.tmp - Deleted
C:\WINDOWS\Temp\win546.tmp - Deleted
C:\WINDOWS\Temp\win547.tmp - Deleted
C:\WINDOWS\Temp\win548.tmp - Deleted
C:\WINDOWS\Temp\win549.tmp - Deleted
C:\WINDOWS\Temp\win54A.tmp - Deleted
C:\WINDOWS\Temp\win54B.tmp - Deleted
C:\WINDOWS\Temp\win54C.tmp - Deleted
C:\WINDOWS\Temp\win54D.tmp - Deleted
C:\WINDOWS\Temp\win54E.tmp - Deleted
C:\WINDOWS\Temp\win54F.tmp - Deleted
C:\WINDOWS\Temp\win55.tmp - Deleted
C:\WINDOWS\Temp\win550.tmp - Deleted
C:\WINDOWS\Temp\win551.tmp - Deleted
C:\WINDOWS\Temp\win552.tmp - Deleted
C:\WINDOWS\Temp\win553.tmp - Deleted
C:\WINDOWS\Temp\win554.tmp - Deleted
C:\WINDOWS\Temp\win555.tmp - Deleted
C:\WINDOWS\Temp\win556.tmp - Deleted
C:\WINDOWS\Temp\win557.tmp - Deleted
C:\WINDOWS\Temp\win558.tmp - Deleted
C:\WINDOWS\Temp\win559.tmp - Deleted
C:\WINDOWS\Temp\win55A.tmp - Deleted
C:\WINDOWS\Temp\win55B.tmp - Deleted
C:\WINDOWS\Temp\win55C.tmp - Deleted
C:\WINDOWS\Temp\win55D.tmp - Deleted
C:\WINDOWS\Temp\win55E.tmp - Deleted
C:\WINDOWS\Temp\win55F.tmp - Deleted
C:\WINDOWS\Temp\win56.tmp - Deleted
C:\WINDOWS\Temp\win560.tmp - Deleted
C:\WINDOWS\Temp\win561.tmp - Deleted
C:\WINDOWS\Temp\win562.tmp - Deleted
C:\WINDOWS\Temp\win563.tmp - Deleted
C:\WINDOWS\Temp\win564.tmp - Deleted
C:\WINDOWS\Temp\win565.tmp - Deleted
C:\WINDOWS\Temp\win566.tmp - Deleted
C:\WINDOWS\Temp\win567.tmp - Deleted
C:\WINDOWS\Temp\win568.tmp - Deleted
C:\WINDOWS\Temp\win569.tmp - Deleted
C:\WINDOWS\Temp\win56A.tmp - Deleted
C:\WINDOWS\Temp\win56B.tmp - Deleted
C:\WINDOWS\Temp\win56C.tmp - Deleted
C:\WINDOWS\Temp\win56D.tmp - Deleted
C:\WINDOWS\Temp\win56E.tmp - Deleted
C:\WINDOWS\Temp\win56F.tmp - Deleted
C:\WINDOWS\Temp\win57.tmp - Deleted
C:\WINDOWS\Temp\win570.tmp - Deleted
C:\WINDOWS\Temp\win571.tmp - Deleted
C:\WINDOWS\Temp\win572.tmp - Deleted
C:\WINDOWS\Temp\win573.tmp - Deleted
C:\WINDOWS\Temp\win574.tmp - Deleted
C:\WINDOWS\Temp\win575.tmp - Deleted
C:\WINDOWS\Temp\win576.tmp - Deleted
C:\WINDOWS\Temp\win577.tmp - Deleted
C:\WINDOWS\Temp\win578.tmp - Deleted
C:\WINDOWS\Temp\win579.tmp - Deleted
C:\WINDOWS\Temp\win57A.tmp - Deleted
C:\WINDOWS\Temp\win57B.tmp - Deleted
C:\WINDOWS\Temp\win57C.tmp - Deleted
C:\WINDOWS\Temp\win57D.tmp - Deleted
C:\WINDOWS\Temp\win57E.tmp - Deleted
C:\WINDOWS\Temp\win57F.tmp - Deleted
C:\WINDOWS\Temp\win58.tmp - Deleted
C:\WINDOWS\Temp\win580.tmp - Deleted
C:\WINDOWS\Temp\win581.tmp - Deleted
C:\WINDOWS\Temp\win582.tmp - Deleted
C:\WINDOWS\Temp\win583.tmp - Deleted
C:\WINDOWS\Temp\win584.tmp - Deleted
C:\WINDOWS\Temp\win585.tmp - Deleted
C:\WINDOWS\Temp\win586.tmp - Deleted
C:\WINDOWS\Temp\win587.tmp - Deleted
C:\WINDOWS\Temp\win588.tmp - Deleted
C:\WINDOWS\Temp\win589.tmp - Deleted
C:\WINDOWS\Temp\win58A.tmp - Deleted
C:\WINDOWS\Temp\win58B.tmp - Deleted
C:\WINDOWS\Temp\win58C.tmp - Deleted
C:\WINDOWS\Temp\win58D.tmp - Deleted
C:\WINDOWS\Temp\win58E.tmp - Deleted
C:\WINDOWS\Temp\win58F.tmp - Deleted
C:\WINDOWS\Temp\win59.tmp - Deleted
C:\WINDOWS\Temp\win590.tmp - Deleted
C:\WINDOWS\Temp\win591.tmp - Deleted
C:\WINDOWS\Temp\win592.tmp - Deleted
C:\WINDOWS\Temp\win593.tmp - Deleted
C:\WINDOWS\Temp\win594.tmp - Deleted
C:\WINDOWS\Temp\win595.tmp - Deleted
C:\WINDOWS\Temp\win596.tmp - Deleted
C:\WINDOWS\Temp\win597.tmp - Deleted
C:\WINDOWS\Temp\win598.tmp - Deleted
C:\WINDOWS\Temp\win599.tmp - Deleted
C:\WINDOWS\Temp\win59A.tmp - Deleted
C:\WINDOWS\Temp\win59B.tmp - Deleted
C:\WINDOWS\Temp\win59C.tmp - Deleted
C:\WINDOWS\Temp\win59D.tmp - Deleted
C:\WINDOWS\Temp\win59E.tmp - Deleted
C:\WINDOWS\Temp\win59F.tmp - Deleted
C:\WINDOWS\Temp\win5A.tmp - Deleted
C:\WINDOWS\Temp\win5A0.tmp - Deleted
C:\WINDOWS\Temp\win5A1.tmp - Deleted
C:\WINDOWS\Temp\win5A2.tmp - Deleted
C:\WINDOWS\Temp\win5A3.tmp - Deleted
C:\WINDOWS\Temp\win5A4.tmp - Deleted
C:\WINDOWS\Temp\win5A5.tmp - Deleted
C:\WINDOWS\Temp\win5A6.tmp - Deleted
C:\WINDOWS\Temp\win5A7.tmp - Deleted
C:\WINDOWS\Temp\win5A8.tmp - Deleted
C:\WINDOWS\Temp\win5A9.tmp - Deleted
C:\WINDOWS\Temp\win5AA.tmp - Deleted
C:\WINDOWS\Temp\win5AB.tmp - Deleted
C:\WINDOWS\Temp\win5AC.tmp - Deleted
C:\WINDOWS\Temp\win5AD.tmp - Deleted
C:\WINDOWS\Temp\win5AE.tmp - Deleted
C:\WINDOWS\Temp\win5AF.tmp - Deleted
C:\WINDOWS\Temp\win5B.tmp - Deleted
C:\WINDOWS\Temp\win5B0.tmp - Deleted
C:\WINDOWS\Temp\win5B1.tmp - Deleted
C:\WINDOWS\Temp\win5B2.tmp - Deleted
C:\WINDOWS\Temp\win5B3.tmp - Deleted
C:\WINDOWS\Temp\win5B4.tmp - Deleted
C:\WINDOWS\Temp\win5B5.tmp - Deleted
C:\WINDOWS\Temp\win5B6.tmp - Deleted
C:\WINDOWS\Temp\win5B7.tmp - Deleted
C:\WINDOWS\Temp\win5B8.tmp - Deleted
C:\WINDOWS\Temp\win5B9.tmp - Deleted
C:\WINDOWS\Temp\win5BA.tmp - Deleted
C:\WINDOWS\Temp\win5BB.tmp - Deleted
C:\WINDOWS\Temp\win5BC.tmp - Deleted
C:\WINDOWS\Temp\win5BD.tmp - Deleted
C:\WINDOWS\Temp\win5BE.tmp - Deleted
C:\WINDOWS\Temp\win5BF.tmp - Deleted
C:\WINDOWS\Temp\win5C.tmp - Deleted
C:\WINDOWS\Temp\win5C0.tmp - Deleted
C:\WINDOWS\Temp\win5C1.tmp - Deleted
C:\WINDOWS\Temp\win5C2.tmp - Deleted
C:\WINDOWS\Temp\win5C3.tmp - Deleted
C:\WINDOWS\Temp\win5C4.tmp - Deleted
C:\WINDOWS\Temp\win5C5.tmp - Deleted
C:\WINDOWS\Temp\win5C6.tmp - Deleted
C:\WINDOWS\Temp\win5C7.tmp - Deleted
C:\WINDOWS\Temp\win5C8.tmp - Deleted
C:\WINDOWS\Temp\win5C9.tmp - Deleted
C:\WINDOWS\Temp\win5CA.tmp - Deleted
C:\WINDOWS\Temp\win5CB.tmp - Deleted
C:\WINDOWS\Temp\win5CC.tmp - Deleted
C:\WINDOWS\Temp\win5CD.tmp - Deleted
C:\WINDOWS\Temp\win5CE.tmp - Deleted
C:\WINDOWS\Temp\win5CF.tmp - Deleted
C:\WINDOWS\Temp\win5D.tmp - Deleted
C:\WINDOWS\Temp\win5D0.tmp - Deleted
C:\WINDOWS\Temp\win5D1.tmp - Deleted
C:\WINDOWS\Temp\win5D2.tmp - Deleted
C:\WINDOWS\Temp\win5D3.tmp - Deleted
C:\WINDOWS\Temp\win5D4.tmp - Deleted
C:\WINDOWS\Temp\win5D5.tmp - Deleted
C:\WINDOWS\Temp\win5D6.tmp - Deleted
C:\WINDOWS\Temp\win5D7.tmp - Deleted
C:\WINDOWS\Temp\win5D8.tmp - Deleted
C:\WINDOWS\Temp\win5D9.tmp - Deleted
C:\WINDOWS\Temp\win5DA.tmp - Deleted
C:\WINDOWS\Temp\win5DB.tmp - Deleted
C:\WINDOWS\Temp\win5DC.tmp - Deleted
C:\WINDOWS\Temp\win5DD.tmp - Deleted
C:\WINDOWS\Temp\win5DE.tmp - Deleted
C:\WINDOWS\Temp\win5DF.tmp - Deleted
C:\WINDOWS\Temp\win5E.tmp - Deleted
C:\WINDOWS\Temp\win5E0.tmp - Deleted
C:\WINDOWS\Temp\win5E1.tmp - Deleted
C:\WINDOWS\Temp\win5E2.tmp - Deleted
C:\WINDOWS\Temp\win5E3.tmp - Deleted
C:\WINDOWS\Temp\win5E4.tmp - Deleted
C:\WINDOWS\Temp\win5E5.tmp - Deleted
C:\WINDOWS\Temp\win5E6.tmp - Deleted
C:\WINDOWS\Temp\win5E7.tmp - Deleted
C:\WINDOWS\Temp\win5E8.tmp - Deleted
C:\WINDOWS\Temp\win5E9.tmp - Deleted
C:\WINDOWS\Temp\win5EA.tmp - Deleted
C:\WINDOWS\Temp\win5EB.tmp - Deleted
C:\WINDOWS\Temp\win5EC.tmp - Deleted
C:\WINDOWS\Temp\win5ED.tmp - Deleted
C:\WINDOWS\Temp\win5EE.tmp - Deleted
C:\WINDOWS\Temp\win5EF.tmp - Deleted
C:\WINDOWS\Temp\win5F.tmp - Deleted
C:\WINDOWS\Temp\win5F0.tmp - Deleted
C:\WINDOWS\Temp\win5F1.tmp - Deleted
C:\WINDOWS\Temp\win5F2.tmp - Deleted
C:\WINDOWS\Temp\win5F3.tmp - Deleted
C:\WINDOWS\Temp\win5F4.tmp - Deleted
C:\WINDOWS\Temp\win5F5.tmp - Deleted
C:\WINDOWS\Temp\win5F6.tmp - Deleted
C:\WINDOWS\Temp\win5F7.tmp - Deleted
C:\WINDOWS\Temp\win5F8.tmp - Deleted
C:\WINDOWS\Temp\win5F9.tmp - Deleted
C:\WINDOWS\Temp\win5FA.tmp - Deleted
C:\WINDOWS\Temp\win5FB.tmp - Deleted
C:\WINDOWS\Temp\win5FC.tmp - Deleted
C:\WINDOWS\Temp\win5FD.tmp - Deleted
C:\WINDOWS\Temp\win5FE.tmp - Deleted
C:\WINDOWS\Temp\win5FF.tmp - Deleted
C:\WINDOWS\Temp\win6.tmp - Deleted
C:\WINDOWS\Temp\win60.tmp - Deleted
C:\WINDOWS\Temp\win600.tmp - Deleted
C:\WINDOWS\Temp\win601.tmp - Deleted
C:\WINDOWS\Temp\win602.tmp - Deleted
C:\WINDOWS\Temp\win603.tmp - Deleted
C:\WINDOWS\Temp\win604.tmp - Deleted
C:\WINDOWS\Temp\win605.tmp - Deleted
C:\WINDOWS\Temp\win606.tmp - Deleted
C:\WINDOWS\Temp\win607.tmp - Deleted
C:\WINDOWS\Temp\win608.tmp - Deleted
C:\WINDOWS\Temp\win609.tmp - Deleted
C:\WINDOWS\Temp\win60A.tmp - Deleted
C:\WINDOWS\Temp\win60B.tmp - Deleted
C:\WINDOWS\Temp\win60C.tmp - Deleted
C:\WINDOWS\Temp\win60D.tmp - Deleted
C:\WINDOWS\Temp\win60E.tmp - Deleted
C:\WINDOWS\Temp\win60F.tmp - Deleted
C:\WINDOWS\Temp\win61.tmp - Deleted
C:\WINDOWS\Temp\win610.tmp - Deleted
C:\WINDOWS\Temp\win611.tmp - Deleted
C:\WINDOWS\Temp\win612.tmp - Deleted
C:\WINDOWS\Temp\win613.tmp - Deleted
C:\WINDOWS\Temp\win614.tmp - Deleted
C:\WINDOWS\Temp\win615.tmp - Deleted
C:\WINDOWS\Temp\win616.tmp - Deleted
C:\WINDOWS\Temp\win617.tmp - Deleted
C:\WINDOWS\Temp\win618.tmp - Deleted
C:\WINDOWS\Temp\win619.tmp - Deleted
C:\WINDOWS\Temp\win61A.tmp - Deleted
C:\WINDOWS\Temp\win61B.tmp - Deleted
C:\WINDOWS\Temp\win61C.tmp - Deleted
C:\WINDOWS\Temp\win61D.tmp - Deleted
C:\WINDOWS\Temp\win61E.tmp - Deleted
C:\WINDOWS\Temp\win61F.tmp - Deleted
C:\WINDOWS\Temp\win62.tmp - Deleted
C:\WINDOWS\Temp\win620.tmp - Deleted
C:\WINDOWS\Temp\win621.tmp - Deleted
C:\WINDOWS\Temp\win622.tmp - Deleted
C:\WINDOWS\Temp\win623.tmp - Deleted
C:\WINDOWS\Temp\win624.tmp - Deleted
C:\WINDOWS\Temp\win625.tmp - Deleted
C:\WINDOWS\Temp\win626.tmp - Deleted
C:\WINDOWS\Temp\win627.tmp - Deleted
C:\WINDOWS\Temp\win628.tmp - Deleted
C:\WINDOWS\Temp\win629.tmp - Deleted
C:\WINDOWS\Temp\win62A.tmp - Deleted
C:\WINDOWS\Temp\win62B.tmp - Deleted
C:\WINDOWS\Temp\win62C.tmp - Deleted
C:\WINDOWS\Temp\win62D.tmp - Deleted
C:\WINDOWS\Temp\win62E.tmp - Deleted
C:\WINDOWS\Temp\win62F.tmp - Deleted
C:\WINDOWS\Temp\win63.tmp - Deleted
C:\WINDOWS\Temp\win630.tmp - Deleted
C:\WINDOWS\Temp\win631.tmp - Deleted
C:\WINDOWS\Temp\win632.tmp - Deleted
C:\WINDOWS\Temp\win633.tmp - Deleted
C:\WINDOWS\Temp\win634.tmp - Deleted
C:\WINDOWS\Temp\win635.tmp - Deleted
C:\WINDOWS\Temp\win636.tmp - Deleted
C:\WINDOWS\Temp\win637.tmp - Deleted
C:\WINDOWS\Temp\win638.tmp - Deleted
C:\WINDOWS\Temp\win639.tmp - Deleted
C:\WINDOWS\Temp\win63A.tmp - Deleted
C:\WINDOWS\Temp\win63B.tmp - Deleted
C:\WINDOWS\Temp\win63C.tmp - Deleted
C:\WINDOWS\Temp\win63D.tmp - Deleted
C:\WINDOWS\Temp\win63E.tmp - Deleted
C:\WINDOWS\Temp\win63F.tmp - Deleted
C:\WINDOWS\Temp\win64.tmp - Deleted
C:\WINDOWS\Temp\win640.tmp - Deleted
C:\WINDOWS\Temp\win641.tmp - Deleted
C:\WINDOWS\Temp\win642.tmp - Deleted
C:\WINDOWS\Temp\win643.tmp - Deleted
C:\WINDOWS\Temp\win644.tmp - Deleted
C:\WINDOWS\Temp\win645.tmp - Deleted
C:\WINDOWS\Temp\win646.tmp - Deleted
C:\WINDOWS\Temp\win647.tmp - Deleted
C:\WINDOWS\Temp\win648.tmp - Deleted
C:\WINDOWS\Temp\win649.tmp - Deleted
C:\WINDOWS\Temp\win64A.tmp - Deleted
C:\WINDOWS\Temp\win64B.tmp - Deleted
C:\WINDOWS\Temp\win64C.tmp - Deleted
C:\WINDOWS\Temp\win64D.tmp - Deleted
C:\WINDOWS\Temp\win64E.tmp - Deleted
C:\WINDOWS\Temp\win64F.tmp - Deleted
C:\WINDOWS\Temp\win65.tmp - Deleted
C:\WINDOWS\Temp\win650.tmp - Deleted
C:\WINDOWS\Temp\win651.tmp - Deleted
C:\WINDOWS\Temp\win652.tmp - Deleted
C:\WINDOWS\Temp\win653.tmp - Deleted
C:\WINDOWS\Temp\win654.tmp - Deleted
C:\WINDOWS\Temp\win655.tmp - Deleted
C:\WINDOWS\Temp\win656.tmp - Deleted
C:\WINDOWS\Temp\win657.tmp - Deleted
C:\WINDOWS\Temp\win658.tmp - Deleted
C:\WINDOWS\Temp\win659.tmp - Deleted
C:\WINDOWS\Temp\win65A.tmp - Deleted
C:\WINDOWS\Temp\win65B.tmp - Deleted
C:\WINDOWS\Temp\win65C.tmp - Deleted
C:\WINDOWS\Temp\win65D.tmp - Deleted
C:\WINDOWS\Temp\win65E.tmp - Deleted
C:\WINDOWS\Temp\win65F.tmp - Deleted
C:\WINDOWS\Temp\win66.tmp - Deleted
C:\WINDOWS\Temp\win660.tmp - Deleted
C:\WINDOWS\Temp\win661.tmp - Deleted
C:\WINDOWS\Temp\win662.tmp - Deleted
C:\WINDOWS\Temp\win663.tmp - Deleted
C:\WINDOWS\Temp\win664.tmp - Deleted
C:\WINDOWS\Temp\win665.tmp - Deleted
C:\WINDOWS\Temp\win666.tmp - Deleted
C:\WINDOWS\Temp\win667.tmp - Deleted
C:\WINDOWS\Temp\win668.tmp - Deleted
C:\WINDOWS\Temp\win669.tmp - Deleted
C:\WINDOWS\Temp\win66A.tmp - Deleted
C:\WINDOWS\Temp\win66B.tmp - Deleted
C:\WINDOWS\Temp\win66C.tmp - Deleted
C:\WINDOWS\Temp\win66D.tmp - Deleted
C:\WINDOWS\Temp\win66E.tmp - Deleted
C:\WINDOWS\Temp\win66F.tmp - Deleted
C:\WINDOWS\Temp\win67.tmp - Deleted
C:\WINDOWS\Temp\win670.tmp - Deleted
C:\WINDOWS\Temp\win671.tmp - Deleted
C:\WINDOWS\Temp\win672.tmp - Deleted
C:\WINDOWS\Temp\win673.tmp - Deleted
C:\WINDOWS\Temp\win674.tmp - Deleted
C:\WINDOWS\Temp\win675.tmp - Deleted
C:\WINDOWS\Temp\win676.tmp - Deleted
C:\WINDOWS\Temp\win677.tmp - Deleted
C:\WINDOWS\Temp\win678.tmp - Deleted
C:\WINDOWS\Temp\win679.tmp - Deleted
C:\WINDOWS\Temp\win67A.tmp - Deleted
C:\WINDOWS\Temp\win67B.tmp - Deleted
C:\WINDOWS\Temp\win67C.tmp - Deleted
C:\WINDOWS\Temp\win67D.tmp - Deleted
C:\WINDOWS\Temp\win67E.tmp - Deleted
C:\WINDOWS\Temp\win67F.tmp - Deleted
C:\WINDOWS\Temp\win68.tmp - Deleted
C:\WINDOWS\Temp\win680.tmp - Deleted
C:\WINDOWS\Temp\win681.tmp - Deleted
C:\WINDOWS\Temp\win682.tmp - Deleted
C:\WINDOWS\Temp\win683.tmp - Deleted
C:\WINDOWS\Temp\win684.tmp - Deleted
C:\WINDOWS\Temp\win685.tmp - Deleted
C:\WINDOWS\Temp\win686.tmp - Deleted
C:\WINDOWS\Temp\win687.tmp - Deleted
C:\WINDOWS\Temp\win688.tmp - Deleted
C:\WINDOWS\Temp\win689.tmp - Deleted
C:\WINDOWS\Temp\win68A.tmp - Deleted
C:\WINDOWS\Temp\win68B.tmp - Deleted
C:\WINDOWS\Temp\win68C.tmp - Deleted
C:\WINDOWS\Temp\win68D.tmp - Deleted
C:\WINDOWS\Temp\win68E.tmp - Deleted
C:\WINDOWS\Temp\win68F.tmp - Deleted
C:\WINDOWS\Temp\win69.tmp - Deleted
C:\WINDOWS\Temp\win690.tmp - Deleted
C:\WINDOWS\Temp\win691.tmp - Deleted
C:\WINDOWS\Temp\win692.tmp - Deleted
C:\WINDOWS\Temp\win693.tmp - Deleted
C:\WINDOWS\Temp\win694.tmp - Deleted
C:\WINDOWS\Temp\win695.tmp - Deleted
C:\WINDOWS\Temp\win696.tmp - Deleted
C:\WINDOWS\Temp\win697.tmp - Deleted
C:\WINDOWS\Temp\win698.tmp - Deleted
C:\WINDOWS\Temp\win699.tmp - Deleted
C:\WINDOWS\Temp\win69A.tmp - Deleted
C:\WINDOWS\Temp\win69B.tmp - Deleted
C:\WINDOWS\Temp\win69C.tmp - Deleted
C:\WINDOWS\Temp\win69D.tmp - Deleted
C:\WINDOWS\Temp\win69E.tmp - Deleted
C:\WINDOWS\Temp\win69F.tmp - Deleted
C:\WINDOWS\Temp\win6A.tmp - Deleted
C:\WINDOWS\Temp\win6A0.tmp - Deleted
C:\WINDOWS\Temp\win6A1.tmp - Deleted
C:\WINDOWS\Temp\win6A2.tmp - Deleted
C:\WINDOWS\Temp\win6A3.tmp - Deleted
C:\WINDOWS\Temp\win6A4.tmp - Deleted
C:\WINDOWS\Temp\win6A5.tmp - Deleted
C:\WINDOWS\Temp\win6A6.tmp - Deleted
C:\WINDOWS\Temp\win6A7.tmp - Deleted
C:\WINDOWS\Temp\win6A8.tmp - Deleted
C:\WINDOWS\Temp\win6A9.tmp - Deleted
C:\WINDOWS\Temp\win6AA.tmp - Deleted
C:\WINDOWS\Temp\win6AB.tmp - Deleted
C:\WINDOWS\Temp\win6AC.tmp - Deleted
C:\WINDOWS\Temp\win6AD.tmp - Deleted
C:\WINDOWS\Temp\win6AE.tmp - Deleted
C:\WINDOWS\Temp\win6AF.tmp - Deleted
C:\WINDOWS\Temp\win6B.tmp - Deleted
C:\WINDOWS\Temp\win6B0.tmp - Deleted
C:\WINDOWS\Temp\win6B1.tmp - Deleted
C:\WINDOWS\Temp\win6B2.tmp - Deleted
C:\WINDOWS\Temp\win6B3.tmp - Deleted
C:\WINDOWS\Temp\win6B4.tmp - Deleted
C:\WINDOWS\Temp\win6B5.tmp - Deleted
C:\WINDOWS\Temp\win6B6.tmp - Deleted
C:\WINDOWS\Temp\win6B7.tmp - Deleted
C:\WINDOWS\Temp\win6B8.tmp - Deleted
C:\WINDOWS\Temp\win6B9.tmp - Deleted
C:\WINDOWS\Temp\win6BA.tmp - Deleted
C:\WINDOWS\Temp\win6BB.tmp - Deleted
C:\WINDOWS\Temp\win6BC.tmp - Deleted
C:\WINDOWS\Temp\win6BD.tmp - Deleted
C:\WINDOWS\Temp\win6BE.tmp - Deleted
C:\WINDOWS\Temp\win6BF.tmp - Deleted
C:\WINDOWS\Temp\win6C.tmp - Deleted
C:\WINDOWS\Temp\win6C0.tmp - Deleted
C:\WINDOWS\Temp\win6C1.tmp - Deleted
C:\WINDOWS\Temp\win6C2.tmp - Deleted
C:\WINDOWS\Temp\win6C3.tmp - Deleted
C:\WINDOWS\Temp\win6C4.tmp - Deleted
C:\WINDOWS\Temp\win6C5.tmp - Deleted
C:\WINDOWS\Temp\win6C6.tmp - Deleted
C:\WINDOWS\Temp\win6C7.tmp - Deleted
C:\WINDOWS\Temp\win6C8.tmp - Deleted
C:\WINDOWS\Temp\win6C9.tmp - Deleted
C:\WINDOWS\Temp\win6CA.tmp - Deleted
C:\WINDOWS\Temp\win6CB.tmp - Deleted
C:\WINDOWS\Temp\win6CC.tmp - Deleted
C:\WINDOWS\Temp\win6CD.tmp - Deleted
C:\WINDOWS\Temp\win6CE.tmp - Deleted
C:\WINDOWS\Temp\win6CF.tmp - Deleted
C:\WINDOWS\Temp\win6D.tmp - Deleted
C:\WINDOWS\Temp\win6D0.tmp - Deleted
C:\WINDOWS\Temp\win6D1.tmp - Deleted
C:\WINDOWS\Temp\win6D2.tmp - Deleted
C:\WINDOWS\Temp\win6D3.tmp - Deleted
C:\WINDOWS\Temp\win6D4.tmp - Deleted
C:\WINDOWS\Temp\win6D5.tmp - Deleted
C:\WINDOWS\Temp\win6D6.tmp - Deleted
C:\WINDOWS\Temp\win6D7.tmp - Deleted
C:\WINDOWS\Temp\win6D8.tmp - Deleted
C:\WINDOWS\Temp\win6D9.tmp - Deleted
C:\WINDOWS\Temp\win6DA.tmp - Deleted
C:\WINDOWS\Temp\win6DB.tmp - Deleted
C:\WINDOWS\Temp\win6DC.tmp - Deleted
C:\WINDOWS\Temp\win6DD.tmp - Deleted
C:\WINDOWS\Temp\win6DE.tmp - Deleted
C:\WINDOWS\Temp\win6DF.tmp - Deleted
C:\WINDOWS\Temp\win6E.tmp - Deleted
C:\WINDOWS\Temp\win6E0.tmp - Deleted
C:\WINDOWS\Temp\win6E1.tmp - Deleted
C:\WINDOWS\Temp\win6E2.tmp - Deleted
C:\WINDOWS\Temp\win6E3.tmp - Deleted
C:\WINDOWS\Temp\win6E4.tmp - Deleted
C:\WINDOWS\Temp\win6E5.tmp - Deleted
C:\WINDOWS\Temp\win6E6.tmp - Deleted
C:\WINDOWS\Temp\win6E7.tmp - Deleted
C:\WINDOWS\Temp\win6E8.tmp - Deleted
C:\WINDOWS\Temp\win6E9.tmp - Deleted
C:\WINDOWS\Temp\win6EA.tmp - Deleted
C:\WINDOWS\Temp\win6EB.tmp - Deleted
C:\WINDOWS\Temp\win6EC.tmp - Deleted
C:\WINDOWS\Temp\win6ED.tmp - Deleted
C:\WINDOWS\Temp\win6EE.tmp - Deleted
C:\WINDOWS\Temp\win6EF.tmp - Deleted
C:\WINDOWS\Temp\win6F.tmp - Deleted
C:\WINDOWS\Temp\win6F0.tmp - Deleted
C:\WINDOWS\Temp\win6F1.tmp - Deleted
C:\WINDOWS\Temp\win6F2.tmp - Deleted
C:\WINDOWS\Temp\win6F3.tmp - Deleted
C:\WINDOWS\Temp\win6F4.tmp - Deleted
C:\WINDOWS\Temp\win6F5.tmp - Deleted
C:\WINDOWS\Temp\win6F6.tmp - Deleted
C:\WINDOWS\Temp\win6F7.tmp - Deleted
C:\WINDOWS\Temp\win6F8.tmp - Deleted
C:\WINDOWS\Temp\win6F9.tmp - Deleted
C:\WINDOWS\Temp\win6FA.tmp - Deleted
C:\WINDOWS\Temp\win6FB.tmp - Deleted
C:\WINDOWS\Temp\win6FC.tmp - Deleted
C:\WINDOWS\Temp\win6FD.tmp - Deleted
C:\WINDOWS\Temp\win6FE.tmp - Deleted
C:\WINDOWS\Temp\win6FF.tmp - Deleted
C:\WINDOWS\Temp\win7.tmp - Deleted
C:\WINDOWS\Temp\win70.tmp - Deleted
C:\WINDOWS\Temp\win700.tmp - Deleted
C:\WINDOWS\Temp\win701.tmp - Deleted
C:\WINDOWS\Temp\win702.tmp - Deleted
C:\WINDOWS\Temp\win703.tmp - Deleted
C:\WINDOWS\Temp\win70B.tmp - Deleted
C:\WINDOWS\Temp\win70C.tmp - Deleted
C:\WINDOWS\Temp\win70E.tmp - Deleted
C:\WINDOWS\Temp\win71.tmp - Deleted
C:\WINDOWS\Temp\win710.tmp - Deleted
C:\WINDOWS\Temp\win712.tmp - Deleted
C:\WINDOWS\Temp\win713.tmp - Deleted
C:\WINDOWS\Temp\win714.tmp - Deleted
C:\WINDOWS\Temp\win716.tmp - Deleted
C:\WINDOWS\Temp\win717.tmp - Deleted
C:\WINDOWS\Temp\win719.tmp - Deleted
C:\WINDOWS\Temp\win72.tmp - Deleted
C:\WINDOWS\Temp\win73.tmp - Deleted
C:\WINDOWS\Temp\win74.tmp - Deleted
C:\WINDOWS\Temp\win75.tmp - Deleted
C:\WINDOWS\Temp\win76.tmp - Deleted
C:\WINDOWS\Temp\win77.tmp - Deleted
C:\WINDOWS\Temp\win78.tmp - Deleted
C:\WINDOWS\Temp\win79.tmp - Deleted
C:\WINDOWS\Temp\win7A.tmp - Deleted
C:\WINDOWS\Temp\win7B.tmp - Deleted
C:\WINDOWS\Temp\win7C.tmp - Deleted
C:\WINDOWS\Temp\win7D.tmp - Deleted
C:\WINDOWS\Temp\win7E.tmp - Deleted
C:\WINDOWS\Temp\win7F.tmp - Deleted
C:\WINDOWS\Temp\win8.tmp - Deleted
C:\WINDOWS\Temp\win80.tmp - Deleted
C:\WINDOWS\Temp\win81.tmp - Deleted
C:\WINDOWS\Temp\win82.tmp - Deleted
C:\WINDOWS\Temp\win83.tmp - Deleted
C:\WINDOWS\Temp\win84.tmp - Deleted
C:\WINDOWS\Temp\win85.tmp - Deleted
C:\WINDOWS\Temp\win86.tmp - Deleted
C:\WINDOWS\Temp\win87.tmp - Deleted
C:\WINDOWS\Temp\win88.tmp - Deleted
C:\WINDOWS\Temp\win89.tmp - Deleted
C:\WINDOWS\Temp\win8A.tmp - Deleted
C:\WINDOWS\Temp\win8B.tmp - Deleted
C:\WINDOWS\Temp\win8C.tmp - Deleted
C:\WINDOWS\Temp\win8D.tmp - Deleted
C:\WINDOWS\Temp\win8E.tmp - Deleted
C:\WINDOWS\Temp\win8F.tmp - Deleted
C:\WINDOWS\Temp\win9.tmp - Deleted
C:\WINDOWS\Temp\win90.tmp - Deleted
C:\WINDOWS\Temp\win91.tmp - Deleted
C:\WINDOWS\Temp\win92.tmp - Deleted
C:\WINDOWS\Temp\win93.tmp - Deleted
C:\WINDOWS\Temp\win94.tmp - Deleted
C:\WINDOWS\Temp\win95.tmp - Deleted
C:\WINDOWS\Temp\win96.tmp - Deleted
C:\WINDOWS\Temp\win97.tmp - Deleted
C:\WINDOWS\Temp\win98.tmp - Deleted
C:\WINDOWS\Temp\win99.tmp - Deleted
C:\WINDOWS\Temp\win9A.tmp - Deleted
C:\WINDOWS\Temp\win9B.tmp - Deleted
C:\WINDOWS\Temp\win9C.tmp - Deleted
C:\WINDOWS\Temp\win9D.tmp - Deleted
C:\WINDOWS\Temp\win9E.tmp - Deleted
C:\WINDOWS\Temp\win9F.tmp - Deleted
C:\WINDOWS\Temp\winA.tmp - Deleted
C:\WINDOWS\Temp\winA0.tmp - Deleted
C:\WINDOWS\Temp\winA1.tmp - Deleted
C:\WINDOWS\Temp\winA2.tmp - Deleted
C:\WINDOWS\Temp\winA3.tmp - Deleted
C:\WINDOWS\Temp\winA4.tmp - Deleted
C:\WINDOWS\Temp\winA5.tmp - Deleted
C:\WINDOWS\Temp\winA6.tmp - Deleted
C:\WINDOWS\Temp\winA7.tmp - Deleted
C:\WINDOWS\Temp\winA8.tmp - Deleted
C:\WINDOWS\Temp\winA9.tmp - Deleted
C:\WINDOWS\Temp\winAA.tmp - Deleted
C:\WINDOWS\Temp\winAB.tmp - Deleted
C:\WINDOWS\Temp\winAC.tmp - Deleted
C:\WINDOWS\Temp\winAD.tmp - Deleted
C:\WINDOWS\Temp\winAE.tmp - Deleted
C:\WINDOWS\Temp\winAF.tmp - Deleted
C:\WINDOWS\Temp\winB.tmp - Deleted
C:\WINDOWS\Temp\winB0.tmp - Deleted
C:\WINDOWS\Temp\winB1.tmp - Deleted
C:\WINDOWS\Temp\winB2.tmp - Deleted
C:\WINDOWS\Temp\winB3.tmp - Deleted
C:\WINDOWS\Temp\winB4.tmp - Deleted
C:\WINDOWS\Temp\winB5.tmp - Deleted
C:\WINDOWS\Temp\winB6.tmp - Deleted
C:\WINDOWS\Temp\winB7.tmp - Deleted
C:\WINDOWS\Temp\winB8.tmp - Deleted
C:\WINDOWS\Temp\winB9.tmp - Deleted
C:\WINDOWS\Temp\winBA.tmp - Deleted
C:\WINDOWS\Temp\winBB.tmp - Deleted
C:\WINDOWS\Temp\winBC.tmp - Deleted
C:\WINDOWS\Temp\winBD.tmp - Deleted
C:\WINDOWS\Temp\winBE.tmp - Deleted
C:\WINDOWS\Temp\winBF.tmp - Deleted
C:\WINDOWS\Temp\winC.tmp - Deleted
C:\WINDOWS\Temp\winC0.tmp - Deleted
C:\WINDOWS\Temp\winC1.tmp - Deleted
C:\WINDOWS\Temp\winC2.tmp - Deleted
C:\WINDOWS\Temp\winC3.tmp - Deleted
C:\WINDOWS\Temp\winC4.tmp - Deleted
C:\WINDOWS\Temp\winC5.tmp - Deleted
C:\WINDOWS\Temp\winC6.tmp - Deleted
C:\WINDOWS\Temp\winC7.tmp - Deleted
C:\WINDOWS\Temp\winC8.tmp - Deleted
C:\WINDOWS\Temp\winC9.tmp - Deleted
C:\WINDOWS\Temp\winCA.tmp - Deleted
C:\WINDOWS\Temp\winCB.tmp - Deleted
C:\WINDOWS\Temp\winCC.tmp - Deleted
C:\WINDOWS\Temp\winCD.tmp - Deleted
C:\WINDOWS\Temp\winCE.tmp - Deleted
C:\WINDOWS\Temp\winCF.tmp - Deleted
C:\WINDOWS\Temp\winD.tmp - Deleted
C:\WINDOWS\Temp\winD0.tmp - Deleted
C:\WINDOWS\Temp\winD1.tmp - Deleted
C:\WINDOWS\Temp\winD2.tmp - Deleted
C:\WINDOWS\Temp\winD3.tmp - Deleted
C:\WINDOWS\Temp\winD4.tmp - Deleted
C:\WINDOWS\Temp\winD5.tmp - Deleted
C:\WINDOWS\Temp\winD6.tmp - Deleted
C:\WINDOWS\Temp\winD7.tmp - Deleted
C:\WINDOWS\Temp\winD8.tmp - Deleted
C:\WINDOWS\Temp\winD9.tmp - Deleted
C:\WINDOWS\Temp\winDA.tmp - Deleted
C:\WINDOWS\Temp\winDB.tmp - Deleted
C:\WINDOWS\Temp\winDC.tmp - Deleted
C:\WINDOWS\Temp\winDD.tmp - Deleted
C:\WINDOWS\Temp\winDE.tmp - Deleted
C:\WINDOWS\Temp\winDF.tmp - Deleted
C:\WINDOWS\Temp\winE.tmp - Deleted
C:\WINDOWS\Temp\winE0.tmp - Deleted
C:\WINDOWS\Temp\winE1.tmp - Deleted
C:\WINDOWS\Temp\winE2.tmp - Deleted
C:\WINDOWS\Temp\winE3.tmp - Deleted
C:\WINDOWS\Temp\winE4.tmp - Deleted
C:\WINDOWS\Temp\winE5.tmp - Deleted
C:\WINDOWS\Temp\winE6.tmp - Deleted
C:\WINDOWS\Temp\winE7.tmp - Deleted
C:\WINDOWS\Temp\winE8.tmp - Deleted
C:\WINDOWS\Temp\winE9.tmp - Deleted
C:\WINDOWS\Temp\winEA.tmp - Deleted
C:\WINDOWS\Temp\winEB.tmp - Deleted
C:\WINDOWS\Temp\winEC.tmp - Deleted
C:\WINDOWS\Temp\winED.tmp - Deleted
C:\WINDOWS\Temp\winEE.tmp - Deleted
C:\WINDOWS\Temp\winEF.tmp - Deleted
C:\WINDOWS\Temp\winF.tmp - Deleted
C:\WINDOWS\Temp\winF0.tmp - Deleted
C:\WINDOWS\Temp\winF1.tmp - Deleted
C:\WINDOWS\Temp\winF2.tmp - Deleted
C:\WINDOWS\Temp\winF3.tmp - Deleted
C:\WINDOWS\Temp\winF4.tmp - Deleted
C:\WINDOWS\Temp\winF5.tmp - Deleted
C:\WINDOWS\Temp\winF6.tmp - Deleted
C:\WINDOWS\Temp\winF7.tmp - Deleted
C:\WINDOWS\Temp\winF8.tmp - Deleted
C:\WINDOWS\Temp\winF9.tmp - Deleted
C:\WINDOWS\Temp\winFA.tmp - Deleted
C:\WINDOWS\Temp\winFB.tmp - Deleted
C:\WINDOWS\Temp\winFC.tmp - Deleted
C:\WINDOWS\Temp\winFD.tmp - Deleted
C:\WINDOWS\Temp\winFE.tmp - Deleted
C:\WINDOWS\Temp\winFF.tmp - Deleted



Alternate Stream Check:

C:\WINDOWS\system32
No streams found.
Final Check:

Remaining Services:
------------------


Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\DC++\\DCPlusPlus.exe"="C:\\Program Files\\DC++\\DCPlusPlus.exe:*:Enabled:DC++"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Trillian\\trillian.exe"="C:\\Program Files\\Trillian\\trillian.exe:*:Enabled:Trillian"
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"="C:\\Program Files\\BitTornado\\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip

Listing Files with hidden attributes:

C:\NTDETECT.COM
C:\Program Files\Common Files\svchost.exe
C:\WINDOWS\system32\cdplayer.exe.manifest
C:\WINDOWS\system32\logonui.exe.manifest
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\0c096b9a042a9952f5fab6ff1bd528f3\BIT13.tmp

Finished


Logfile of HijackThis v1.99.1
Scan saved at 3:28:43 PM, on 1/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Alex Kremer\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {59CD7310-98A4-48BF-BE77-C12032C98D31} - C:\WINDOWS\system32\qommnom.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - Winlogon Notify: winrnt32 - C:\WINDOWS\SYSTEM32\winrnt32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

#5 Shaba

Shaba

    Koutsi


  • Malware Response Team
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:07:10 AM

Posted 17 January 2007 - 11:28 AM

Hi

No worries, we try another tool

1. Download this file - combofix.exe
and save it to your desktop.

2. Go to start -> run.
type this in box and click ok

"%userprofile%\desktop\combofix.exe" /v qommnom

3. When finished, it shall produce a log for you. Post that log in your next reply

4. Reboot

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Send:

- a fresh HijackThis log
- combofix report
Microsoft MVP Consumer Security
Posted Image

Posted Image

#6 Alex Kremer

Alex Kremer
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 17 January 2007 - 01:00 PM

"Alex Kremer" - 07-01-17 12:36:54 Service Pack 2
ComboFix 07-01-16.2 - Running from: "C:\Documents and Settings\Alex Kremer\desktop"
Command switches used :: /v qommnom

(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\qommnom.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\unsvchosts.lzma
C:\WINDOWS\svchost.exe
C:\Program Files\Common Files\{34027~1
C:\Program Files\Common Files\{A4027~1
C:\Program Files\Common Files\{A4027~2
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\WINDOWS\YSTEM~1


((((((((((((((((((((((((((((((( Files Created from 2006-12-17 to 2007-01-17 ))))))))))))))))))))))))))))))))))


2007-01-17 12:41 <DIR> d-------- C:\WINDOWS\erdnt
2007-01-16 15:29 22,029 ---hs---- C:\WINDOWS\system32\ddcdcbc.dll
2007-01-16 15:17 <DIR> d-------- C:\SDFix
2007-01-16 14:57 <DIR> d-------- C:\VundoFix Backups
2007-01-16 10:44 155,648 ---h----- C:\Program Files\Common Files\svchost.exe
2007-01-16 00:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-01-15 17:51 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-01-15 17:23 <DIR> d-------- C:\Program Files\Trend Micro
2007-01-15 00:30 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\Webroot
2007-01-14 18:56 2 --a------ C:\WINDOWS\system32\wapiit.exe
2007-01-14 18:24 <DIR> d-------- C:\DOCUME~1\ALEXKR~1\Application Data\Help
2007-01-14 17:57 <DIR> d-------- C:\Program Files\BitPim
2007-01-14 17:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Bluetooth
2007-01-14 17:44 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2007-01-14 17:43 53,760 --a------ C:\WINDOWS\system32\drivers\vfwwdm32.dll
2007-01-14 17:42 82,148 --a------ C:\WINDOWS\system32\drivers\VcommMgr.sys
2007-01-14 17:42 77,824 -ra------ C:\WINDOWS\system32\drivers\SioUi2k.dll
2007-01-14 17:42 7,680 --a------ C:\WINDOWS\system32\btinstall.dll
2007-01-14 17:42 63,488 -ra------ C:\WINDOWS\system32\drivers\wssbtr1f.sys
2007-01-14 17:42 61,312 --a------ C:\WINDOWS\system32\drivers\VComm.sys
2007-01-14 17:42 51,169 -ra------ C:\WINDOWS\system32\drivers\OXSER.SYS
2007-01-14 17:42 49,152 --a------ C:\WINDOWS\system32\btfunc.dll
2007-01-14 17:42 48,556 -ra------ C:\WINDOWS\system32\drivers\SktBt2k.sys
2007-01-14 17:42 48,076 -ra------ C:\WINDOWS\system32\drivers\Sio9502k.sys
2007-01-14 17:42 40,960 -ra------ C:\WINDOWS\system32\drivers\SCTray.exe
2007-01-14 17:42 28,271 --a------ C:\WINDOWS\system32\drivers\BTHidMgr.sys
2007-01-14 17:42 23,000 --a------ C:\WINDOWS\system32\drivers\btcusb.sys
2007-01-14 17:42 20,480 --a------ C:\WINDOWS\system32\drivers\blueletaudio.sys
2007-01-14 17:42 148,830 --a------ C:\WINDOWS\system32\drivers\bcbthub.sys
2007-01-14 17:42 13,304 --a------ C:\WINDOWS\system32\drivers\BTNetFilter.sys
2007-01-14 17:42 116,021 --a------ C:\WINDOWS\system32\drivers\fw203x.sys
2007-01-14 17:42 11,860 --a------ C:\WINDOWS\system32\drivers\vbtenum.sys
2007-01-14 17:42 11,736 --a------ C:\WINDOWS\system32\drivers\VHIDMini.sys
2007-01-14 17:42 10,804 --a------ C:\WINDOWS\system32\drivers\BtNetDrv.sys
2007-01-14 17:42 <DIR> d-------- C:\Program Files\IVT Corporation
2007-01-14 16:58 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-01-14 16:57 <DIR> d-------- C:\Psfonts
2007-01-14 16:57 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-01-14 16:56 <DIR> d-------- C:\Program Files\Finale 2006
2007-01-14 15:12 17,920 --a------ C:\WINDOWS\system32\winrnt32.dll
2007-01-14 15:12 <DIR> dr-h----- C:\$VAULT$.AVG
2007-01-14 15:08 <DIR> d-------- C:\Program Files\Sibelius Software
2007-01-14 14:58 5,248 --a------ C:\WINDOWS\system32\drivers\Vax347s.sys
2007-01-14 14:58 159,616 --a------ C:\WINDOWS\system32\drivers\Vax347b.sys
2007-01-14 14:39 <DIR> d-------- C:\Program Files\Alcohol Soft
2007-01-12 00:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-12 00:42 <DIR> d-------- C:\Program Files\rFactor
2007-01-09 22:48 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-01-09 22:40 81,921 --a------ C:\WINDOWS\system32\drivers\MPIXVID.SYS
2007-01-09 22:40 25,575 --a------ C:\WINDOWS\system32\drivers\USBCamAT.sys
2007-01-09 22:40 <DIR> d-------- C:\Program Files\V3780s Digital Camera
2007-01-06 12:51 935,632 --a------ C:\WINDOWS\system\VB40016.DLL
2007-01-06 12:51 83,936 --a------ C:\WINDOWS\system\ZSUNZIP.DLL
2007-01-06 12:51 63,598 --a------ C:\WINDOWS\system\ZIPDIR.DLL
2007-01-06 12:51 593,424 --a------ C:\WINDOWS\petu.EXE
2007-01-06 12:51 57,328 --a------ C:\WINDOWS\system\OLE2CONV.DLL
2007-01-06 12:51 536,048 --a------ C:\WINDOWS\system\OC25.DLL
2007-01-06 12:51 51,712 --a------ C:\WINDOWS\system\OLE2PROX.DLL
2007-01-06 12:51 5,120 --a------ C:\WINDOWS\system\STKIT416.DLL
2007-01-06 12:51 40,320 --a------ C:\WINDOWS\system\COMPRESS.DLL
2007-01-06 12:51 398,416 --a------ C:\WINDOWS\system\VBRUN300.DLL
2007-01-06 12:51 31,744 --a------ C:\WINDOWS\system\MSAFINX.DLL
2007-01-06 12:51 304,640 --a------ C:\WINDOWS\system\OLE2.DLL
2007-01-06 12:51 3,776 --a------ C:\WINDOWS\system\CALL32.DLL
2007-01-06 12:51 28,113 --a------ C:\WINDOWS\system\OLE2.REG
2007-01-06 12:51 26,992 --a------ C:\WINDOWS\system\CTL3DV2.DLL
2007-01-06 12:51 236,774 --a------ C:\WINDOWS\system\ZIPSRV.DLL
2007-01-06 12:51 21,906 --a------ C:\WINDOWS\system\ZIPADAT.DLL
2007-01-06 12:51 177,824 --a------ C:\WINDOWS\system\TYPELIB.DLL
2007-01-06 12:51 164,960 --a------ C:\WINDOWS\system\OLE2DISP.DLL
2007-01-06 12:51 157,696 --a------ C:\WINDOWS\system\STORAGE.DLL
2007-01-06 12:51 152,976 --a------ C:\WINDOWS\system\OLE2NLS.DLL
2007-01-06 12:51 12,976 --a------ C:\WINDOWS\system\SCP.DLL
2007-01-06 12:51 109,056 --a------ C:\WINDOWS\system\COMPOBJ.DLL
2007-01-06 12:51 <DIR> d-------- C:\WINDOWS\OLESVR
2007-01-06 12:50 <DIR> d-------- C:\PET_PROG
2007-01-06 12:48 <DIR> d-------- C:\PET_ROOT
2007-01-06 12:45 348,160 --a------ C:\WINDOWS\system\lexhdl5.dll
2007-01-02 23:50 <DIR> d-------- C:\Program Files\BitTornado
2007-01-02 23:50 <DIR> d-------- C:\DOCUME~1\ALEXKR~1\Application Data\.BitTornado
2006-12-18 20:11 86,016 -r------- C:\WINDOWS\UPSCR.Scr
2006-12-18 20:11 <DIR> d-------- C:\Program Files\Ulead Systems
2006-12-18 20:10 89,600 --a------ C:\WINDOWS\system32\lfjbg12n.dll
2006-12-18 20:10 73,216 --a------ C:\WINDOWS\system32\lffax12n.dll
2006-12-18 20:10 388,608 --a------ C:\WINDOWS\system32\ltkrn12n.dll
2006-12-18 20:10 341,504 --a------ C:\WINDOWS\system32\LFCMP12n.DLL
2006-12-18 20:10 32,256 --a------ C:\WINDOWS\system32\lflmb12n.dll
2006-12-18 20:10 306,688 --a------ C:\WINDOWS\IsUninst.exe
2006-12-18 20:10 30,720 --a------ C:\WINDOWS\system32\lfbmp12n.dll
2006-12-18 20:10 26,624 --a------ C:\WINDOWS\system32\lfpcx12n.dll
2006-12-18 20:10 258,560 --a------ C:\WINDOWS\system32\LTDIS12n.dll
2006-12-18 20:10 212,480 --a------ C:\WINDOWS\system32\Pcdlib32.dll
2006-12-18 20:10 176,128 --a------ C:\WINDOWS\system32\PuzzSaver.scr
2006-12-18 20:10 172,032 --a------ C:\WINDOWS\system32\SpotSaver.scr
2006-12-18 20:10 141,824 --a------ C:\WINDOWS\system32\lftif12n.dll
2006-12-18 20:10 135,168 --a------ C:\WINDOWS\system32\ParaSaver.scr
2006-12-18 20:10 131,072 --a------ C:\WINDOWS\system32\Sp5x_32.dll
2006-12-18 20:10 130,048 --a------ C:\WINDOWS\system32\ltfil12n.DLL
2006-12-18 20:09 110,592 --a------ C:\WINDOWS\system32\MKCoInstaller.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-17 01:03 -------- d-------- C:\Program Files\dc++
2007-01-16 15:17 -------- d-------- C:\Program Files\trillian
2007-01-15 15:26 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\dvdcss
2007-01-14 18:24 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\help
2007-01-14 17:42 -------- d--h----- C:\Program Files\installshield installation information
2007-01-14 14:35 639224 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-01-02 23:50 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\.bittornado
2006-12-22 00:27 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\ahead
2006-12-19 02:34 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\adobeum
2006-12-19 02:33 -------- d-------- C:\Program Files\Common Files\adobe
2006-12-19 02:32 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\adobe
2006-12-13 14:42 -------- d-------- C:\Program Files\intel
2006-12-13 14:24 -------- d-------- C:\Program Files\difx
2006-12-13 14:19 -------- d-------- C:\Program Files\dell
2006-12-13 10:06 -------- d-------- C:\Program Files\mtv networks
2006-12-13 10:04 -------- d-------- C:\Program Files\windows media connect 2
2006-12-12 21:36 -------- d-------- C:\Program Files\viewpoint
2006-12-09 12:27 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\macromedia
2006-12-06 14:17 -------- d-------- C:\Program Files\pulse master
2006-12-06 14:11 -------- d-------- C:\Program Files\roni music
2006-12-06 14:02 -------- d---s---- C:\Documents and Settings\Alex Kremer\Application Data\microsoft
2006-12-06 14:01 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\roni music
2006-12-04 22:11 -------- d-------- C:\Program Files\Common Files\ahead
2006-12-04 22:05 -------- d-------- C:\Program Files\nero
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-10-19 08:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-19 08:30 2732032 --a------ C:\WINDOWS\system32\netw2r32.dll
2006-10-19 08:29 557056 --a------ C:\WINDOWS\system32\netw2c32.dll
2006-10-18 21:58 8704 --------- C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 --------- C:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\wmnetmgr.dll
2006-10-18 21:47 8231936 --a------ C:\WINDOWS\system32\wmploc.dll
2006-10-18 21:47 767488 --------- C:\WINDOWS\system32\wmvsencd.dll
2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-10-18 21:47 656896 --------- C:\WINDOWS\system32\wmvxencd.dll
2006-10-18 21:47 63488 --------- C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 --------- C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\wmspdmod.dll
2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 429056 --------- C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mpg4dmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mp4sdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mp43dmod.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wmvadve.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wmvadvd.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 38400 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 --------- C:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 --------- C:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 --------- C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 317440 --------- C:\WINDOWS\system32\mp4sdecd.dll
2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284160 --------- C:\WINDOWS\system32\portabledeviceapi.dll
2006-10-18 21:47 276992 --------- C:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2603008 --------- C:\WINDOWS\system32\wpdshext.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mpg4decd.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mp43decd.dll
2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 212992 --------- C:\WINDOWS\system32\mfplat.dll
2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 --------- C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 199168 --------- C:\WINDOWS\system32\portabledevicewmdrm.dll
2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 166912 --------- C:\WINDOWS\system32\portabledevicetypes.dll
2006-10-18 21:47 1661440 --------- C:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 1574912 --------- C:\WINDOWS\system32\wmvencod.dll
2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 --------- C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1543680 --------- C:\WINDOWS\system32\wmvdecod.dll
2006-10-18 21:47 1382912 --------- C:\WINDOWS\system32\wmvsdecd.dll
2006-10-18 21:47 133632 --------- C:\WINDOWS\system32\wpdshserviceobj.dll
2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\wmspdmoe.dll
2006-10-18 21:47 132096 --------- C:\WINDOWS\system32\portabledevicewiacompat.dll
2006-10-18 21:47 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\laprxy.dll
2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\wmadmoe.dll
2006-10-18 21:47 101888 --------- C:\WINDOWS\system32\portabledeviceclassextension.dll
2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe
2006-10-18 20:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
2006-10-15 14:04 62 --ahs---- C:\Documents and Settings\Alex Kremer\Application Data\desktop.ini


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"AWMON"="\"C:\\Program Files\\Lavasoft\\Ad-Aware SE Professional\\Ad-Watch.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"IntelWireless"="\"C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe\" /tf Intel PROSet/Wireless"
"IntelZeroConfig"="\"C:\\Program Files\\Intel\\Wireless\\bin\\ZCfgSvc.exe\""
"Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{1C9678E2-77AC-4CAD-89EA-9E3F980C73C4}"=""

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"svchost.exe"="C:\\WINDOWS\\svchost.exe"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcdcbc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrnt32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

Completion time: 07-01-17 12:57:15










Logfile of HijackThis v1.99.1
Scan saved at 12:58:41 PM, on 1/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Alex Kremer\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1C9678E2-77AC-4CAD-89EA-9E3F980C73C4} - C:\WINDOWS\system32\ddcdcbc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - Winlogon Notify: ddcdcbc - C:\WINDOWS\SYSTEM32\ddcdcbc.dll
O20 - Winlogon Notify: winrnt32 - C:\WINDOWS\SYSTEM32\winrnt32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

#7 Alex Kremer

Alex Kremer
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 17 January 2007 - 01:17 PM

Also, when I run Spybot I'm still getting:
Smitfraud-C. Toolbar
TagASaurus
YazzleSudoku

Thanks in advance.

#8 Shaba

Shaba

    Koutsi


  • Malware Response Team
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:07:10 AM

Posted 17 January 2007 - 01:18 PM

Hi

One dll left and another came back.

First we'll need to backup registry:

Start -> Run -> regedit -> ok. Then File -> Export. Give it a name and press Save.

Save text below as fix.reg on Notepad (save it as all files (*.*)) on Desktop

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"svchost.exe"=-

It should look like this -> Posted Image

Doubleclick fix.reg, press Yes and ok.

(In case you are unsure how to create a reg file, take a look here with screenshots.)

1. Go to start -> run.
type this in box and click ok

"%userprofile%\desktop\combofix.exe" /v ddcdcbc

2. When finished, it shall produce a log for you. Post that log in your next reply

3. Reboot

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Send:

- a fresh HijackThis log
- combofix report
Microsoft MVP Consumer Security
Posted Image

Posted Image

#9 Alex Kremer

Alex Kremer
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 18 January 2007 - 12:41 AM

"Alex Kremer" - 07-01-18 0:31:38 Service Pack 2
ComboFix 07-01-16.2 - Running from: "C:\Documents and Settings\Alex Kremer\desktop"
Command switches used :: /v ddcdcbc

(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\ddcdcbc.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\unsvchosts.lzma
C:\WINDOWS\svchost.exe
C:\Program Files\Common Files\{34027~1
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\WINDOWS\YSTEM~1


((((((((((((((((((((((((((((((( Files Created from 2006-12-18 to 2007-01-18 ))))))))))))))))))))))))))))))))))


2007-01-18 00:30 143 --a------ C:\DOCUME~1\ALEXKR~1\fix.reg
2007-01-18 00:29 57,618,316 --a------ C:\backup.reg
2007-01-17 13:00 22,029 ---hs---- C:\WINDOWS\system32\vtussrs.dll
2007-01-17 12:41 <DIR> d-------- C:\WINDOWS\erdnt
2007-01-16 15:17 <DIR> d-------- C:\SDFix
2007-01-16 14:57 <DIR> d-------- C:\VundoFix Backups
2007-01-16 10:44 155,648 ---h----- C:\Program Files\Common Files\svchost.exe
2007-01-16 00:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-01-15 17:51 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-01-15 17:23 <DIR> d-------- C:\Program Files\Trend Micro
2007-01-15 00:30 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\Webroot
2007-01-14 18:56 2 --a------ C:\WINDOWS\system32\wapiit.exe
2007-01-14 18:24 <DIR> d-------- C:\DOCUME~1\ALEXKR~1\Application Data\Help
2007-01-14 17:57 <DIR> d-------- C:\Program Files\BitPim
2007-01-14 17:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Bluetooth
2007-01-14 17:44 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2007-01-14 17:43 53,760 --a------ C:\WINDOWS\system32\drivers\vfwwdm32.dll
2007-01-14 17:42 82,148 --a------ C:\WINDOWS\system32\drivers\VcommMgr.sys
2007-01-14 17:42 77,824 -ra------ C:\WINDOWS\system32\drivers\SioUi2k.dll
2007-01-14 17:42 7,680 --a------ C:\WINDOWS\system32\btinstall.dll
2007-01-14 17:42 63,488 -ra------ C:\WINDOWS\system32\drivers\wssbtr1f.sys
2007-01-14 17:42 61,312 --a------ C:\WINDOWS\system32\drivers\VComm.sys
2007-01-14 17:42 51,169 -ra------ C:\WINDOWS\system32\drivers\OXSER.SYS
2007-01-14 17:42 49,152 --a------ C:\WINDOWS\system32\btfunc.dll
2007-01-14 17:42 48,556 -ra------ C:\WINDOWS\system32\drivers\SktBt2k.sys
2007-01-14 17:42 48,076 -ra------ C:\WINDOWS\system32\drivers\Sio9502k.sys
2007-01-14 17:42 40,960 -ra------ C:\WINDOWS\system32\drivers\SCTray.exe
2007-01-14 17:42 28,271 --a------ C:\WINDOWS\system32\drivers\BTHidMgr.sys
2007-01-14 17:42 23,000 --a------ C:\WINDOWS\system32\drivers\btcusb.sys
2007-01-14 17:42 20,480 --a------ C:\WINDOWS\system32\drivers\blueletaudio.sys
2007-01-14 17:42 148,830 --a------ C:\WINDOWS\system32\drivers\bcbthub.sys
2007-01-14 17:42 13,304 --a------ C:\WINDOWS\system32\drivers\BTNetFilter.sys
2007-01-14 17:42 116,021 --a------ C:\WINDOWS\system32\drivers\fw203x.sys
2007-01-14 17:42 11,860 --a------ C:\WINDOWS\system32\drivers\vbtenum.sys
2007-01-14 17:42 11,736 --a------ C:\WINDOWS\system32\drivers\VHIDMini.sys
2007-01-14 17:42 10,804 --a------ C:\WINDOWS\system32\drivers\BtNetDrv.sys
2007-01-14 17:42 <DIR> d-------- C:\Program Files\IVT Corporation
2007-01-14 16:58 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-01-14 16:57 <DIR> d-------- C:\Psfonts
2007-01-14 16:57 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-01-14 16:56 <DIR> d-------- C:\Program Files\Finale 2006
2007-01-14 15:12 17,920 --a------ C:\WINDOWS\system32\winrnt32.dll
2007-01-14 15:12 <DIR> dr-h----- C:\$VAULT$.AVG
2007-01-14 15:08 <DIR> d-------- C:\Program Files\Sibelius Software
2007-01-14 14:58 5,248 --a------ C:\WINDOWS\system32\drivers\Vax347s.sys
2007-01-14 14:58 159,616 --a------ C:\WINDOWS\system32\drivers\Vax347b.sys
2007-01-14 14:39 <DIR> d-------- C:\Program Files\Alcohol Soft
2007-01-12 00:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-12 00:42 <DIR> d-------- C:\Program Files\rFactor
2007-01-09 22:48 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-01-09 22:40 81,921 --a------ C:\WINDOWS\system32\drivers\MPIXVID.SYS
2007-01-09 22:40 25,575 --a------ C:\WINDOWS\system32\drivers\USBCamAT.sys
2007-01-09 22:40 <DIR> d-------- C:\Program Files\V3780s Digital Camera
2007-01-06 12:51 935,632 --a------ C:\WINDOWS\system\VB40016.DLL
2007-01-06 12:51 83,936 --a------ C:\WINDOWS\system\ZSUNZIP.DLL
2007-01-06 12:51 63,598 --a------ C:\WINDOWS\system\ZIPDIR.DLL
2007-01-06 12:51 593,424 --a------ C:\WINDOWS\petu.EXE
2007-01-06 12:51 57,328 --a------ C:\WINDOWS\system\OLE2CONV.DLL
2007-01-06 12:51 536,048 --a------ C:\WINDOWS\system\OC25.DLL
2007-01-06 12:51 51,712 --a------ C:\WINDOWS\system\OLE2PROX.DLL
2007-01-06 12:51 5,120 --a------ C:\WINDOWS\system\STKIT416.DLL
2007-01-06 12:51 40,320 --a------ C:\WINDOWS\system\COMPRESS.DLL
2007-01-06 12:51 398,416 --a------ C:\WINDOWS\system\VBRUN300.DLL
2007-01-06 12:51 31,744 --a------ C:\WINDOWS\system\MSAFINX.DLL
2007-01-06 12:51 304,640 --a------ C:\WINDOWS\system\OLE2.DLL
2007-01-06 12:51 3,776 --a------ C:\WINDOWS\system\CALL32.DLL
2007-01-06 12:51 28,113 --a------ C:\WINDOWS\system\OLE2.REG
2007-01-06 12:51 26,992 --a------ C:\WINDOWS\system\CTL3DV2.DLL
2007-01-06 12:51 236,774 --a------ C:\WINDOWS\system\ZIPSRV.DLL
2007-01-06 12:51 21,906 --a------ C:\WINDOWS\system\ZIPADAT.DLL
2007-01-06 12:51 177,824 --a------ C:\WINDOWS\system\TYPELIB.DLL
2007-01-06 12:51 164,960 --a------ C:\WINDOWS\system\OLE2DISP.DLL
2007-01-06 12:51 157,696 --a------ C:\WINDOWS\system\STORAGE.DLL
2007-01-06 12:51 152,976 --a------ C:\WINDOWS\system\OLE2NLS.DLL
2007-01-06 12:51 12,976 --a------ C:\WINDOWS\system\SCP.DLL
2007-01-06 12:51 109,056 --a------ C:\WINDOWS\system\COMPOBJ.DLL
2007-01-06 12:51 <DIR> d-------- C:\WINDOWS\OLESVR
2007-01-06 12:50 <DIR> d-------- C:\PET_PROG
2007-01-06 12:48 <DIR> d-------- C:\PET_ROOT
2007-01-06 12:45 348,160 --a------ C:\WINDOWS\system\lexhdl5.dll
2007-01-02 23:50 <DIR> d-------- C:\Program Files\BitTornado
2007-01-02 23:50 <DIR> d-------- C:\DOCUME~1\ALEXKR~1\Application Data\.BitTornado
2006-12-18 20:11 86,016 -r------- C:\WINDOWS\UPSCR.Scr
2006-12-18 20:11 <DIR> d-------- C:\Program Files\Ulead Systems
2006-12-18 20:10 89,600 --a------ C:\WINDOWS\system32\lfjbg12n.dll
2006-12-18 20:10 73,216 --a------ C:\WINDOWS\system32\lffax12n.dll
2006-12-18 20:10 388,608 --a------ C:\WINDOWS\system32\ltkrn12n.dll
2006-12-18 20:10 341,504 --a------ C:\WINDOWS\system32\LFCMP12n.DLL
2006-12-18 20:10 32,256 --a------ C:\WINDOWS\system32\lflmb12n.dll
2006-12-18 20:10 306,688 --a------ C:\WINDOWS\IsUninst.exe
2006-12-18 20:10 30,720 --a------ C:\WINDOWS\system32\lfbmp12n.dll
2006-12-18 20:10 26,624 --a------ C:\WINDOWS\system32\lfpcx12n.dll
2006-12-18 20:10 258,560 --a------ C:\WINDOWS\system32\LTDIS12n.dll
2006-12-18 20:10 212,480 --a------ C:\WINDOWS\system32\Pcdlib32.dll
2006-12-18 20:10 176,128 --a------ C:\WINDOWS\system32\PuzzSaver.scr
2006-12-18 20:10 172,032 --a------ C:\WINDOWS\system32\SpotSaver.scr
2006-12-18 20:10 141,824 --a------ C:\WINDOWS\system32\lftif12n.dll
2006-12-18 20:10 135,168 --a------ C:\WINDOWS\system32\ParaSaver.scr
2006-12-18 20:10 131,072 --a------ C:\WINDOWS\system32\Sp5x_32.dll
2006-12-18 20:10 130,048 --a------ C:\WINDOWS\system32\ltfil12n.DLL
2006-12-18 20:09 110,592 --a------ C:\WINDOWS\system32\MKCoInstaller.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-17 01:03 -------- d-------- C:\Program Files\dc++
2007-01-16 15:17 -------- d-------- C:\Program Files\trillian
2007-01-15 15:26 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\dvdcss
2007-01-14 18:24 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\help
2007-01-14 17:42 -------- d--h----- C:\Program Files\installshield installation information
2007-01-14 14:35 639224 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-01-02 23:50 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\.bittornado
2006-12-22 00:27 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\ahead
2006-12-19 02:34 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\adobeum
2006-12-19 02:33 -------- d-------- C:\Program Files\Common Files\adobe
2006-12-19 02:32 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\adobe
2006-12-13 14:42 -------- d-------- C:\Program Files\intel
2006-12-13 14:24 -------- d-------- C:\Program Files\difx
2006-12-13 14:19 -------- d-------- C:\Program Files\dell
2006-12-13 10:06 -------- d-------- C:\Program Files\mtv networks
2006-12-13 10:04 -------- d-------- C:\Program Files\windows media connect 2
2006-12-12 21:36 -------- d-------- C:\Program Files\viewpoint
2006-12-09 12:27 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\macromedia
2006-12-06 14:17 -------- d-------- C:\Program Files\pulse master
2006-12-06 14:11 -------- d-------- C:\Program Files\roni music
2006-12-06 14:02 -------- d---s---- C:\Documents and Settings\Alex Kremer\Application Data\microsoft
2006-12-06 14:01 -------- d-------- C:\Documents and Settings\Alex Kremer\Application Data\roni music
2006-12-04 22:11 -------- d-------- C:\Program Files\Common Files\ahead
2006-12-04 22:05 -------- d-------- C:\Program Files\nero
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-10-19 08:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-19 08:30 2732032 --a------ C:\WINDOWS\system32\netw2r32.dll
2006-10-19 08:29 557056 --a------ C:\WINDOWS\system32\netw2c32.dll
2006-10-18 21:58 8704 --------- C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 --------- C:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\wmnetmgr.dll
2006-10-18 21:47 8231936 --a------ C:\WINDOWS\system32\wmploc.dll
2006-10-18 21:47 767488 --------- C:\WINDOWS\system32\wmvsencd.dll
2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-10-18 21:47 656896 --------- C:\WINDOWS\system32\wmvxencd.dll
2006-10-18 21:47 63488 --------- C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 --------- C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\wmspdmod.dll
2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 429056 --------- C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mpg4dmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mp4sdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mp43dmod.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wmvadve.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wmvadvd.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 38400 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 --------- C:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 --------- C:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 --------- C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 317440 --------- C:\WINDOWS\system32\mp4sdecd.dll
2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284160 --------- C:\WINDOWS\system32\portabledeviceapi.dll
2006-10-18 21:47 276992 --------- C:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2603008 --------- C:\WINDOWS\system32\wpdshext.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mpg4decd.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mp43decd.dll
2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 212992 --------- C:\WINDOWS\system32\mfplat.dll
2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 --------- C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 199168 --------- C:\WINDOWS\system32\portabledevicewmdrm.dll
2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 166912 --------- C:\WINDOWS\system32\portabledevicetypes.dll
2006-10-18 21:47 1661440 --------- C:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 1574912 --------- C:\WINDOWS\system32\wmvencod.dll
2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 --------- C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1543680 --------- C:\WINDOWS\system32\wmvdecod.dll
2006-10-18 21:47 1382912 --------- C:\WINDOWS\system32\wmvsdecd.dll
2006-10-18 21:47 133632 --------- C:\WINDOWS\system32\wpdshserviceobj.dll
2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\wmspdmoe.dll
2006-10-18 21:47 132096 --------- C:\WINDOWS\system32\portabledevicewiacompat.dll
2006-10-18 21:47 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\laprxy.dll
2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\wmadmoe.dll
2006-10-18 21:47 101888 --------- C:\WINDOWS\system32\portabledeviceclassextension.dll
2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe
2006-10-18 20:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
2006-10-15 14:04 62 --ahs---- C:\Documents and Settings\Alex Kremer\Application Data\desktop.ini


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"AWMON"="\"C:\\Program Files\\Lavasoft\\Ad-Aware SE Professional\\Ad-Watch.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"IntelWireless"="\"C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe\" /tf Intel PROSet/Wireless"
"IntelZeroConfig"="\"C:\\Program Files\\Intel\\Wireless\\bin\\ZCfgSvc.exe\""
"Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrnt32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

Completion time: 07-01-18 0:38:45
C:\ComboFix2.txt ... 07-01-17 12:57










Logfile of HijackThis v1.99.1
Scan saved at 12:39:26 AM, on 1/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Alex Kremer\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sbc.yahoo.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - Winlogon Notify: winrnt32 - C:\WINDOWS\SYSTEM32\winrnt32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

#10 Shaba

Shaba

    Koutsi


  • Malware Response Team
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:07:10 AM

Posted 18 January 2007 - 03:14 AM

Hi

Download KillBox from here:

KillBox

Unzip the folder to your desktop.

* Start Killbox.exe
* Select the Delete on Reboot option.
* Click on the All Files button.
* Copy the complete text in bold below to the clipboard by highlighting the filepaths and pressing Control + C:

C:\WINDOWS\system32\vtussrs.dll
C:\WINDOWS\system32\wapiit.exe
C:\WINDOWS\SYSTEM32\winrnt32.dll


* Go to the File menu of Killbox, and choose Paste from Clipboard.
NOTE: You must use the file File menu--pasting by right-clicking the mouse will only enter one file.
* Click the Delete File button that is a red-and-white X. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Re-run combofix

Send:

- a fresh HijackThis log
- kaspersky report
- combofix report

Edited by Shaba, 18 January 2007 - 03:15 AM.

Microsoft MVP Consumer Security
Posted Image

Posted Image

#11 Alex Kremer

Alex Kremer
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 18 January 2007 - 02:55 PM

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, January 18, 2007 2:42:18 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 18/01/2007
Kaspersky Anti-Virus database records: 259689
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 102355
Number of viruses found: 5
Number of infected objects: 18 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:29:08

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Alex Kremer\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Alex Kremer\Application Data\Lavasoft\Ad-Aware\Logs\AWEVLOG.txt Object is locked skipped
C:\Documents and Settings\Alex Kremer\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Alex Kremer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Alex Kremer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Alex Kremer\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Alex Kremer\Local Settings\Temporary Internet Files\Content.IE5\BLXGBVTB\mulbin32[1].exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.dc skipped
C:\Documents and Settings\Alex Kremer\Local Settings\Temporary Internet Files\Content.IE5\BLXGBVTB\mulbin32[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Alex Kremer\Local Settings\Temporary Internet Files\Content.IE5\CHM305YF\antzom[1].exe Object is locked skipped
C:\Documents and Settings\Alex Kremer\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Alex Kremer\Local Settings\Temporary Internet Files\Content.IE5\TTC6FY7I\wlzip32[1].exe Infected: Trojan-Dropper.Win32.Agent.bbp skipped
C:\Documents and Settings\Alex Kremer\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Alex Kremer\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2007-01-18.12-49-35.log Object is locked skipped
C:\Program Files\Common Files\{34027B2F-063B-1033-0503-050503180001}\Bar888.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\SDFix\backups\backups.zip/backups/win70F.tmp.exe Infected: Trojan-Dropper.Win32.Agent.bbp skipped
C:\SDFix\backups\backups.zip/backups/win715.tmp.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.dc skipped
C:\SDFix\backups\backups.zip/backups/win715.tmp.exe Infected: Trojan-Downloader.Win32.PurityScan.dc skipped
C:\SDFix\backups\backups.zip ZIP: infected - 3 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP118\A0015368.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP119\A0016345.exe/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP119\A0016345.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP120\A0017876.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP121\A0017900.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP121\A0017902.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP121\A0017903.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP121\A0017917.dll Object is locked skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP122\A0019033.dll Object is locked skipped
C:\System Volume Information\_restore{1D00C9A4-82D1-4AC7-AD11-647333CE58C3}\RP122\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{F09E4C63-5251-4851-83F7-E56F0B0E19E8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\win11.tmp.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.dc skipped
C:\WINDOWS\TEMP\win11.tmp.exe NSIS: infected - 1 skipped
C:\WINDOWS\TEMP\winB.tmp.exe Infected: Trojan-Dropper.Win32.Agent.bbp skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.






"Alex Kremer" - 07-01-18 14:43:43 Service Pack 2
ComboFix 07-01-16.2 - Running from: "C:\Documents and Settings\Alex Kremer\desktop"
Command switches used :: /v ddcdcbc

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\unsvchosts.lzma
C:\WINDOWS\svchost.exe
C:\Program Files\Common Files\{34027~1
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\WINDOWS\YSTEM~1


((((((((((((((((((((((((((((((( Files Created from 2006-12-18 to 2007-01-18 ))))))))))))))))))))))))))))))))))


2007-01-18 12:54 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-01-18 12:54 <DIR> d-------- C:\WINDOWS\LastGood
2007-01-18 12:46 <DIR> d-------- C:\!KillBox
2007-01-18 01:17 22,029 ---hs---- C:\WINDOWS\system32\jkkifda.dll
2007-01-18 00:30 143 --a------ C:\DOCUME~1\ALEXKR~1\fix.reg
2007-01-18 00:29 57,618,316 --a------ C:\backup.reg
2007-01-17 12:41 <DIR> d-------- C:\WINDOWS\erdnt
2007-01-16 15:17 <DIR> d-------- C:\SDFix
2007-01-16 14:57 <DIR> d-------- C:\VundoFix Backups
2007-01-16 10:44 155,648 ---h----- C:\Program Files\Common Files\svchost.exe
2007-01-16 00:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-01-15 17:51 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-01-15 17:23 <DIR> d-------- C:\Program Files\Trend Micro
2007-01-15 00:30 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\Webroot
2007-01-14 18:24 <DIR> d-------- C:\DOCUME~1\ALEXKR~1\Application Data\Help
2007-01-14 17:57 <DIR> d-------- C:\Program Files\BitPim
2007-01-14 17:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Bluetooth
2007-01-14 17:44 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2007-01-14 17:43 53,760 --a------ C:\WINDOWS\system32\drivers\vfwwdm32.dll
2007-01-14 17:42 82,148 --a------ C:\WINDOWS\system32\drivers\VcommMgr.sys
2007-01-14 17:42 77,824 -ra------ C:\WINDOWS\system32\drivers\SioUi2k.dll
2007-01-14 17:42 7,680 --a------ C:\WINDOWS\system32\btinstall.dll
2007-01-14 17:42 63,488 -ra------ C:\WINDOWS\system32\drivers\wssbtr1f.sys
2007-01-14 17:42 61,312 --a------ C:\WINDOWS\system32\drivers\VComm.sys
2007-01-14 17:42 51,169 -ra------ C:\WINDOWS\system32\drivers\OXSER.SYS
2007-01-14 17:42 49,152 --a------ C:\WINDOWS\system32\btfunc.dll
2007-01-14 17:42 48,556 -ra------ C:\WINDOWS\system32\drivers\SktBt2k.sys
2007-01-14 17:42 48,076 -ra------ C:\WINDOWS\system32\drivers\Sio9502k.sys
2007-01-14 17:42 40,960 -ra------ C:\WINDOWS\system32\drivers\SCTray.exe
2007-01-14 17:42 28,271 --a------ C:\WINDOWS\system32\drivers\BTHidMgr.sys
2007-01-14 17:42 23,000 --a------ C:\WINDOWS\system32\drivers\btcusb.sys
2007-01-14 17:42 20,480 --a------ C:\WINDOWS\system32\drivers\blueletaudio.sys
2007-01-14 17:42 148,830 --a------ C:\WINDOWS\system32\drivers\bcbthub.sys
2007-01-14 17:42 13,304 --a------ C:\WINDOWS\system32\drivers\BTNetFilter.sys
2007-01-14 17:42 116,021 --a------ C:\WINDOWS\system32\drivers\fw203x.sys
2007-01-14 17:42 11,860 --a------ C:\WINDOWS\system32\drivers\vbtenum.sys
2007-01-14 17:42 11,736 --a------ C:\WINDOWS\system32\drivers\VHIDMini.sys
2007-01-14 17:42 10,804 --a------ C:\WINDOWS\system32\drivers\BtNetDrv.sys
2007-01-14 17:42 <DIR> d-------- C:\Program Files\IVT Corporation
2007-01-14 16:58 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-01-14 16:57 <DIR> d-------- C:\Psfonts
2007-01-14 16:57 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-01-14 16:56 <DIR> d-------- C:\Program Files\Finale 2006
2007-01-14 15:12 <DIR> dr-h----- C:\$VAULT$.AVG
2007-01-14 15:08 <DIR> d-------- C:\Program Files\Sibelius Software
2007-01-14 14:58 5,248 --a------ C:\WINDOWS\system32\drivers\Vax347s.sys
2007-01-14 14:58 159,616 --a------ C:\WINDOWS\system32\drivers\Vax347b.sys
2007-01-14 14:39 <DIR> d-------- C:\Program Files\Alcohol Soft
2007-01-12 00:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-12 00:42 <DIR> d-------- C:\Program Files\rFactor
2007-01-09 22:48 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-01-09 22:40 81,921 --a------ C:\WINDOWS\system32\drivers\MPIXVID.SYS
2007-01-09 22:40 25,575 --a------ C:\WINDOWS\system32\drivers\USBCamAT.sys
2007-01-09 22:40 <DIR> d-------- C:\Program Files\V3780s Digital Camera
2007-01-06 12:51 935,632 --a------ C:\WINDOWS\system\VB40016.DLL
2007-01-06 12:51 83,936 --a------ C:\WINDOWS\system\ZSUNZIP.DLL
2007-01-06 12:51 63,598 --a------ C:\WINDOWS\system\ZIPDIR.DLL
2007-01-06 12:51 593,424 --a------ C:\WINDOWS\petu.EXE
2007-01-06 12:51 57,328 --a------ C:\WINDOWS\system\OLE2CONV.DLL
2007-01-06 12:51 536,048 --a------ C:\WINDOWS\system\OC25.DLL
2007-01-06 12:51 51,712 --a------ C:\WINDOWS\system\OLE2PROX.DLL
2007-01-06 12:51 5,120 --a------ C:\WINDOWS\system\STKIT416.DLL
2007-01-06 12:51 40,320 --a------ C:\WINDOWS\system\COMPRESS.DLL
2007-01-06 12:51 398,416 --a------ C:\WINDOWS\system\VBRUN300.DLL
2007-01-06 12:51 31,744 --a------ C:\WINDOWS\system\MSAFINX.DLL
2007-01-06 12:51 304,640 --a------ C:\WINDOWS\system\OLE2.DLL
2007-01-06 12:51 3,776 --a------ C:\WINDOWS\system\CALL32.DLL
2007-01-06 12:51 28,113 --a------ C:\WINDOWS\system\OLE2.REG
2007-01-06 12:51 26,992 --a------ C:\WINDOWS\system\CTL3DV2.DLL
2007-01-06 12:51 236,774 --a------ C:\WINDOWS\system\ZIPSRV.DLL
2007-01-06 12:51 21,906 --a------ C:\WINDOWS\system\ZIPADAT.DLL
2007-01-06 12:51 177,824 --a------ C:\WINDOWS\system\TYPELIB.DLL
2007-01-06 12:51 164,960 --a------ C:\WINDOWS\system\OLE2DISP.DLL
2007-01-06 12:51 157,696 --a------ C:\WINDOWS\system\STORAGE.DLL
2007-01-06 12:51 152,976 --a------ C:\WINDOWS\system\OLE2NLS.DLL
2007-01-06 12:51 12,976 --a------ C:\WINDOWS\system\SCP.DLL
2007-01-06 12:51 109,056 --a------ C:\WINDOWS\system\COMPOBJ.DLL
2007-01-06 12:51 <DIR> d-------- C:\WINDOWS\OLESVR
2007-01-06 12:50 <DIR> d-------- C:\PET_PROG
2007-01-06 12:48 <DIR> d-------- C:\PET_ROOT
2007-01-06 12:45 348,160 --a------ C:\WINDOWS\system\lexhdl5.dll
2007-01-02 23:50 <DIR> d-------- C:\Program Files\BitTornado
2007-01-02 23:50 <DIR> d-------- C:\DOCUME~1\ALEXKR~1\Application Data\.BitTornado
2006-12-18 20:11 86,016 -r------- C:\WINDOWS\UPSCR.Scr
2006-12-18 20:11 <DIR> d-------- C:\Program Files\Ulead Systems
2006-12-18 20:10 89,600 --a------ C:\WINDOWS\system32\lfjbg12n.dll
2006-12-18 20:10 73,216 --a------ C:\WINDOWS\system32\lffax12n.dll
2006-12-18 20:10 388,608 --a------ C:\WINDOWS\system32\ltkrn12n.dll
2006-12-18 20:10 341,504 --a------ C:\WINDOWS\system32\LFCMP12n.DLL
2006-12-18 20:10 32,256 --a------ C:\WINDOWS\system32\lflmb12n.dll
2006-12-18 20:10 306,688 --a------ C:\WINDOWS\IsUninst.exe
2006-12-18 20:10 30,720 --a------ C:\WINDOWS\system32\lfbmp12n.dll
2006-12-18 20:10 26,624 --a------ C:\WINDOWS\system32\lfpcx12n.dll
2006-12-18 20:10 258,560 --a------ C:\WINDOWS\system32\LTDIS12n.dll
2006-12-18 20:10 212,480 --a------ C:\WINDOWS\system32\Pcdlib32.dll
2006-12-18 20:10 176,128 --a------ C:\WINDOWS\system32\PuzzSaver.scr
2006-12-18 20:10 172,032 --a------ C:\WINDOWS\system32\SpotSaver.scr
2006-12-18 20:10 141,824 --a------ C:\WINDOWS\system32\lftif12n.dll
2006-12-18 20:10 135,168 --a------ C:\WINDOWS\system32\ParaSaver.scr
2006-12-18 20:10 131,072 --a------ C:\WINDOWS\system32\Sp5x_32.dll
2006-12-18 20:10 130,048 --a------ C:\WINDOWS\system32\ltfil12n.DLL
2006-12-18 20:09 110,592 --a------ C:\WINDOWS\system32\MKCoInstaller.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-18 11:20 -------- d-------- C:\Program Files\dc++
2007-01-16 15:17 -------- d-------- C:\Program Files\trillian
2007-01-15 15:26 -------- d-------- C:\DOCUME~1\ALEXKR~1\Application Data\dvdcss
2007-01-14 17:42 -------- d--h----- C:\Program Files\installshield installation information
2007-01-14 14:35 639224 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-01-02 23:50 -------- d-------- C:\DOCUME~1\ALEXKR~1\Application Data\.bittornado
2006-12-22 00:27 -------- d-------- C:\DOCUME~1\ALEXKR~1\Application Data\ahead
2006-12-19 02:34 -------- d-------- C:\DOCUME~1\ALEXKR~1\Application Data\adobeum
2006-12-19 02:33 -------- d-------- C:\Program Files\Common Files\adobe
2006-12-19 02:32 -------- d-------- C:\DOCUME~1\ALEXKR~1\Application Data\adobe
2006-12-13 14:42 -------- d-------- C:\Program Files\intel
2006-12-13 14:24 -------- d-------- C:\Program Files\difx
2006-12-13 14:19 -------- d-------- C:\Program Files\dell
2006-12-13 10:06 -------- d-------- C:\Program Files\mtv networks
2006-12-13 10:04 -------- d-------- C:\Program Files\windows media connect 2
2006-12-12 21:36 -------- d-------- C:\Program Files\viewpoint
2006-12-09 12:27 -------- d-------- C:\DOCUME~1\ALEXKR~1\Application Data\macromedia
2006-12-06 14:17 -------- d-------- C:\Program Files\pulse master
2006-12-06 14:11 -------- d-------- C:\Program Files\roni music
2006-12-06 14:02 -------- d---s---- C:\DOCUME~1\ALEXKR~1\Application Data\microsoft
2006-12-06 14:01 -------- d-------- C:\DOCUME~1\ALEXKR~1\Application Data\roni music
2006-12-04 22:11 -------- d-------- C:\Program Files\Common Files\ahead
2006-12-04 22:05 -------- d-------- C:\Program Files\nero
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-10-19 08:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-19 08:30 2732032 --a------ C:\WINDOWS\system32\netw2r32.dll
2006-10-19 08:29 557056 --a------ C:\WINDOWS\system32\netw2c32.dll
2006-10-18 21:58 8704 --------- C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 --------- C:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\wmnetmgr.dll
2006-10-18 21:47 8231936 --a------ C:\WINDOWS\system32\wmploc.dll
2006-10-18 21:47 767488 --------- C:\WINDOWS\system32\wmvsencd.dll
2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-10-18 21:47 656896 --------- C:\WINDOWS\system32\wmvxencd.dll
2006-10-18 21:47 63488 --------- C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 --------- C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\wmspdmod.dll
2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 429056 --------- C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mpg4dmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mp4sdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mp43dmod.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wmvadve.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wmvadvd.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 38400 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 --------- C:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 --------- C:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 --------- C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 317440 --------- C:\WINDOWS\system32\mp4sdecd.dll
2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284160 --------- C:\WINDOWS\system32\portabledeviceapi.dll
2006-10-18 21:47 276992 --------- C:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2603008 --------- C:\WINDOWS\system32\wpdshext.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mpg4decd.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mp43decd.dll
2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 212992 --------- C:\WINDOWS\system32\mfplat.dll
2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 --------- C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 199168 --------- C:\WINDOWS\system32\portabledevicewmdrm.dll
2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 166912 --------- C:\WINDOWS\system32\portabledevicetypes.dll
2006-10-18 21:47 1661440 --------- C:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 1574912 --------- C:\WINDOWS\system32\wmvencod.dll
2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 --------- C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1543680 --------- C:\WINDOWS\system32\wmvdecod.dll
2006-10-18 21:47 1382912 --------- C:\WINDOWS\system32\wmvsdecd.dll
2006-10-18 21:47 133632 --------- C:\WINDOWS\system32\wpdshserviceobj.dll
2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\wmspdmoe.dll
2006-10-18 21:47 132096 --------- C:\WINDOWS\system32\portabledevicewiacompat.dll
2006-10-18 21:47 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\laprxy.dll
2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\wmadmoe.dll
2006-10-18 21:47 101888 --------- C:\WINDOWS\system32\portabledeviceclassextension.dll
2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe
2006-10-18 20:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
2006-10-15 14:04 62 --ahs---- C:\DOCUME~1\ALEXKR~1\Application Data\desktop.ini


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"AWMON"="\"C:\\Program Files\\Lavasoft\\Ad-Aware SE Professional\\Ad-Watch.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"IntelWireless"="\"C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe\" /tf Intel PROSet/Wireless"
"IntelZeroConfig"="\"C:\\Program Files\\Intel\\Wireless\\bin\\ZCfgSvc.exe\""
"Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57A62825-840C-4FFE-8717-80A308558154}"=""

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"svchost.exe"="C:\\Program Files\\Common Files\\svchost.exe"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkifda
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrnt32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

Completion time: 07-01-18 14:48:29
C:\ComboFix2.txt ... 07-01-18 00:38
C:\ComboFix3.txt ... 07-01-17 12:57




Logfile of HijackThis v1.99.1
Scan saved at 2:53:07 PM, on 1/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Documents and Settings\Alex Kremer\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {57A62825-840C-4FFE-8717-80A308558154} - C:\WINDOWS\system32\jkkifda.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O20 - Winlogon Notify: jkkifda - C:\WINDOWS\SYSTEM32\jkkifda.dll
O20 - Winlogon Notify: winrnt32 - winrnt32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

#12 Shaba

Shaba

    Koutsi


  • Malware Response Team
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:07:10 AM

Posted 19 January 2007 - 04:24 AM

Hi

Vundo came back second time :thumbsup:

Delete these:

C:\Program Files\Common Files\{34027B2F-063B-1033-0503-050503180001}
C:\SDFix\backups\

Empty this folder:

C:\WINDOWS\TEMP\

Empty Internet explorer temporary internet files.

1. Go to start -> run.
type this in box and click ok

"%userprofile%\desktop\combofix.exe" /v jkkifda

2. When finished, it shall produce a log for you. Post that log in your next reply

3. Reboot

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Re-run kaspersky

Send:

- a fresh HijackThis log
- combofix report
- kaspersky report
Microsoft MVP Consumer Security
Posted Image

Posted Image

#13 Alex Kremer

Alex Kremer
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 19 January 2007 - 11:14 AM

C:\Program Files\Common Files\{34027B2F-063B-1033-0503-050503180001} doesn't exist
C:\Windows\Temp was empty
In the temp internet files, it won't let me delete login?.htm

Going to run combofix now.

#14 Shaba

Shaba

    Koutsi


  • Malware Response Team
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:07:10 AM

Posted 19 January 2007 - 12:07 PM

Hi

Those do exist, they just might be hidden.

Make you hidden and system files visible -> http://www.xtra.co.nz/help/0,,4155-1916458,00.html and try again, please :thumbsup:
Microsoft MVP Consumer Security
Posted Image

Posted Image

#15 Alex Kremer

Alex Kremer
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:10 AM

Posted 19 January 2007 - 12:40 PM

Ran combofix and currently running Kaspersky.

All hidden files and system files are visible. Here is what shows up:
Posted Image

Edited by Alex Kremer, 19 January 2007 - 12:43 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users