Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.| Important Announcement: We have a terrific contest still running on the site that I wanted all our members and guests to know about. The chance to win two Seagate FreeAgent external hard drives. More information about this contest can be found here. I suggest everyone submit an entry for them. - BleepingComputer Management |
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Jul 6 2008, 08:51 AM
Post
#31
|
|
|
Member ![]() ![]() Group: Members Posts: 36 Joined: 2-July 08 From: philippines Member No.: 219,978 |
And there's more important things to spend your time on. Yah you're right. I still have my other computer to fix. Okay, I just finished installing Avira and guess what? It detected a trojan horse. TR/Patched.AA.18 on C:\WINDOWS|system32\winlogon.exe I guess this topic will not be closed yet. |
|
|
|
Jul 6 2008, 08:55 AM
Post
#32
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 10,687 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Hmmm....
Let Avira disinfect whatever it finds. Then let's get another opinion. Download Dr.Web CureIt to the desktop: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Please post the contents of the log from DrWeb in your next reply. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ] [ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ] |
|
|
|
Jul 6 2008, 08:55 AM
Post
#33
|
|
|
Member ![]() ![]() Group: Members Posts: 36 Joined: 2-July 08 From: philippines Member No.: 219,978 |
hehe
what should I choose? >quarantine >delete >rename >deny access >ignore Im sure it's not rename. ignore nor delete. The tick was on deny access. im torn between quarantine and deny access. |
|
|
|
Jul 6 2008, 08:59 AM
Post
#34
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 10,687 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Go with quarantine
-------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ] [ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ] |
|
|
|
Jul 6 2008, 09:10 AM
Post
#35
|
|
|
Member ![]() ![]() Group: Members Posts: 36 Joined: 2-July 08 From: philippines Member No.: 219,978 |
Sorry, AVG didn't have as many choices hehe..Anyway, avira keeps on popping up the same message. I think I got 5 already...
|
|
|
|
Jul 6 2008, 09:14 AM
Post
#36
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 10,687 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Those are vital system files that it's detecting, so it probably will not be able to do anything with them unless it can disinfect them.
Dr. Web may do a better job with these files. Run it when your Avira scan is done. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ] [ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ] |
|
|
|
Jul 7 2008, 07:06 AM
Post
#37
|
|
|
Member ![]() ![]() Group: Members Posts: 36 Joined: 2-July 08 From: philippines Member No.: 219,978 |
Hi!
I've been running Dr WEb for like 4hours already and I guess it's still around 10%. Also, it moved SDFix.exe and ComboFix.exe...Is it fine? I also found Antivirus XP 2008 on START>ALL PROGRAMS. This post has been edited by hookedforever: Jul 7 2008, 07:09 AM |
|
|
|
Jul 7 2008, 08:31 AM
Post
#38
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 10,687 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Those tools are detected as false positives by many antivirus programs, so that's not surprising.
It shouldn't take that long to scan though. Has it found anything else that it's removed? -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ] [ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ] |
|
|
|
Jul 7 2008, 08:51 AM
Post
#39
|
|
|
Member ![]() ![]() Group: Members Posts: 36 Joined: 2-July 08 From: philippines Member No.: 219,978 |
|
|
|
|
Jul 7 2008, 10:49 AM
Post
#40
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 10,687 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
As long as it doesn't hang up and freeze, let it keep scanning.
Just post back with the log when it's done. -------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ] [ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ] |
|
|
|
Jul 8 2008, 01:58 AM
Post
#41
|
|
|
Member ![]() ![]() Group: Members Posts: 36 Joined: 2-July 08 From: philippines Member No.: 219,978 |
Dr Web suddenly closed last night. Don't know why. I'm running it again. express scan didn't find anything. I'm currently running a complete scan.
Be back with the log. |
|
|
|
Jul 8 2008, 10:19 AM
Post
#42
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 10,687 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
Ok. Just post back when you can.
-------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ] [ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ] |
|
|
|
Jul 8 2008, 07:21 PM
Post
#43
|
|
|
Member ![]() ![]() Group: Members Posts: 36 Joined: 2-July 08 From: philippines Member No.: 219,978 |
I left DrWeb running from 2pm yesterday until this morning but around 5am, it suddenly closed again (it was around 45% that time). I really don't know what happened. It has found around 8 items. I was so tired of having to repeat everything again so i just tried scanning C:\Windows\system32 since Avira found another Trojan horse there right after the reboot. After scanning system32, a .exe file was found and it was described as a HackTool so I tried curing it but it failed so I just deleted it.
What do I do next? Should I repeat the complete scan? This post has been edited by hookedforever: Jul 8 2008, 07:22 PM |
|
|
|
Jul 9 2008, 09:19 AM
Post
#44
|
|
|
Malware Expert ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 10,687 Joined: 23-December 04 From: Pickerington, Ohio Member No.: 7,762 |
No, let's not do that again. You can go ahead and uninstall DrWeb. It's not being much help for us.
Let's try an online scan and see what it picks up. Please run a free online scan with the ESET Online Scanner Note: You will need to use Internet Explorer for this scan
-------------------- If I have helped you in any way, please consider a donation to help me continue the fight against malware.[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ] [ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ] |
|
|
|
Jul 9 2008, 04:03 PM
Post
#45
|
|
|
Member ![]() ![]() Group: Members Posts: 36 Joined: 2-July 08 From: philippines Member No.: 219,978 |
Hi! I just finished the scan. Here's the log.
# version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=3255 (20080709) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.064 (20070717) # EOSSerial=a6439f81dc92ba4789873bc00433c033 # end=finished # remove_checked=true # unwanted_checked=true # utc_time=2008-07-10 10:37:14 # local_time=2008-07-10 03:37:14 (-0800, Pacific Daylight Time) # country="United States" # osver=5.1.2600 NT Service Pack 2 # scanned=277601 # found=73 # scan_time=11403 C:\Deckard\System Scanner\20080703005757\backup\DOCUME~1\ADMINI~1\LOCALS~1\Temp\removalfile.bat Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000 C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe multiple infiltrations (deleted) 00000000000000000000000000000000 C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »0.exe Win32/Agent.NXF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »1.exe Win32/Adware.SpyShredder application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »2.exe Win32/Adware.SpyShredder application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »3.exe Win32/Agent.NXF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »4.exe Win32/Agent.NXF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\QooBox\Quarantine\C\Documents and Settings\LocalService\Application Data\Microsoft\Internet Explorer\Desktop.htt.vir Win32/Hoax.Renos application (unable to clean - deleted) 00000000000000000000000000000000 C:\QooBox\Quarantine\C\Program Files\PCHealthCenter\1.exe.vir Win32/Adware.SpyShredder application (unable to clean - deleted) 00000000000000000000000000000000 C:\QooBox\Quarantine\C\Program Files\PCHealthCenter\2.exe.vir Win32/Adware.SpyShredder application (unable to clean - deleted) 00000000000000000000000000000000 C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\Vch40.sys.zip Win32/Wigon.CT trojan (deleted) 00000000000000000000000000000000 C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\Vch40.sys.zip »ZIP »Vch40.sys Win32/Wigon.CT trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\Winye05.sys.zip Win32/Wigon.CK trojan (deleted) 00000000000000000000000000000000 C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\Winye05.sys.zip »ZIP »Winye05.sys Win32/Wigon.CK trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip multiple infiltrations (deleted) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/.ttB1.tmp Win32/Nuwar.CX worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/1.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/1.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/2.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/2.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/5.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/5.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/6.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/6.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/7.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/7.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/back.exe.exe Win32/Nuwar.DC worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/CcEvtSvc.exe Win32/SpamTool.Agent.NAQ trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/desktop.html Win32/Hoax.Renos.CY virus (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/ftpdll.dll Win32/PSW.Agent.NHG trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/phcepbj0ev7g.bmp Win32/TrojanDownloader.FakeAlert.DJ trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/sysrest32.exe Win32/Nuwar.CX worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/v4xd3.ga2me Win32/TrojanDownloader.Small.IAW trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/v4xd6.gam5e Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/v5xd4.ga2me Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/v6xdt4.game Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/vx3dt2.game Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/winlogon.exe Win32/TrojanProxy.Small.NP trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\catchme.zip multiple infiltrations (deleted) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\catchme.zip »ZIP »sysrest.sys Win32/Nuwar.CX worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\SDFix\SDFix\backups\catchme.zip »ZIP »asc3550p.sys Win32/Nulprot.A worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\winspywareprotect.exe Win32/Adware.WinSpywareProtect application (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\BraveSentry.exe Win32/Adware.SpySheriff application (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\BraveSentry0.dll Win32/Adware.BraveSentry application (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\BraveSentry2.dll Win32/Adware.BraveSentry application (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\BraveSentry3.dll Win32/Adware.BraveSentry application (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\Uninstall.exe Win32/Adware.SpySheriff application (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\17PHolmes27.exe Win32/TrojanDownloader.Agent.BLS trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\xpupdate.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q1.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q2.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q5.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q6.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q7.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\djki397g.dll Win32/TrojanDownloader.Small.NTQ trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q1.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q2.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q5.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q6.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q7.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\hdxjd4g.dll Win32/TrojanDownloader.Small.NTQ trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\lphcepbj0ev7g.exe Win32/TrojanDownloader.FakeAlert.EH trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\maxpaynowti.exe Win32/Dialer.NAD trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxg4am1et2.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxg6ame4.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxga1me4t1.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxga4m1et4.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxga4me1.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxga5me3.exe Win32/TrojanDownloader.Small.IAW trojan (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004732\WINDOWS\msvecurity.exe Win32/Nuwar.DC worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004732\WINDOWS\system32\goht534.exe a variant of Win32/Nuwar.DA worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004732\WINDOWS\system32\goht701.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000 C:\_OTMoveIt\MovedFiles\07032008_004732\WINDOWS\system32\goht738.exe Win32/TrojanDownloader.Small.ODF trojan (unable to clean - deleted) 00000000000000000000000000000000 |
|
|
|
![]() ![]() |