Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.
MalwareByte's Anti-Malware Download

Important Announcement: We have a terrific contest still running on the site that I wanted all our members and guests to know about.

The chance to win two Seagate FreeAgent external hard drives. More information about this contest can be found here.

I suggest everyone submit an entry for them.

- BleepingComputer Management

> Forum Guidelines

Read this topic before posting a log.


DO NOT post a ComboFix log unless requested to.


Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.

4 Pages V  < 1 2 3 4 >  
Closed TopicStart new topic
> Fatal Error 0xc0000022 Then> Warning! Spyware Detected On Ur Computer., don't know what happened. did it get worse???
hookedforever
post Jul 6 2008, 08:51 AM
Post #31


Member
**

Group: Members
Posts: 36
Joined: 2-July 08
From: philippines
Member No.: 219,978



QUOTE(Buckeye_Sam @ Jul 6 2008, 09:38 PM) *
And there's more important things to spend your time on. smile.gif

Yah you're right. I still have my other computer to fix. sad.gif

Okay, I just finished installing Avira and guess what? It detected a trojan horse. TR/Patched.AA.18 on C:\WINDOWS|system32\winlogon.exe

I guess this topic will not be closed yet.
Go to the top of the page
 
+Quote Post
Buckeye_Sam
post Jul 6 2008, 08:55 AM
Post #32


Malware Expert
******

Group: HJT Team
Posts: 10,687
Joined: 23-December 04
From: Pickerington, Ohio
Member No.: 7,762



Hmmm.... mellow.gif

Let Avira disinfect whatever it finds.
Then let's get another opinion.


Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.


Please post the contents of the log from DrWeb in your next reply.


--------------------
If I have helped you in any way, please consider a donation to help me continue the fight against malware.
[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ]
[ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ]
Go to the top of the page
 
+Quote Post
hookedforever
post Jul 6 2008, 08:55 AM
Post #33


Member
**

Group: Members
Posts: 36
Joined: 2-July 08
From: philippines
Member No.: 219,978



hehe

what should I choose?

>quarantine
>delete
>rename
>deny access
>ignore

Im sure it's not rename. ignore nor delete. The tick was on deny access. im torn between quarantine and deny access.
Go to the top of the page
 
+Quote Post
Buckeye_Sam
post Jul 6 2008, 08:59 AM
Post #34


Malware Expert
******

Group: HJT Team
Posts: 10,687
Joined: 23-December 04
From: Pickerington, Ohio
Member No.: 7,762



Go with quarantine


--------------------
If I have helped you in any way, please consider a donation to help me continue the fight against malware.
[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ]
[ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ]
Go to the top of the page
 
+Quote Post
hookedforever
post Jul 6 2008, 09:10 AM
Post #35


Member
**

Group: Members
Posts: 36
Joined: 2-July 08
From: philippines
Member No.: 219,978



Sorry, AVG didn't have as many choices hehe..Anyway, avira keeps on popping up the same message. I think I got 5 already...
Go to the top of the page
 
+Quote Post
Buckeye_Sam
post Jul 6 2008, 09:14 AM
Post #36


Malware Expert
******

Group: HJT Team
Posts: 10,687
Joined: 23-December 04
From: Pickerington, Ohio
Member No.: 7,762



Those are vital system files that it's detecting, so it probably will not be able to do anything with them unless it can disinfect them.
Dr. Web may do a better job with these files. Run it when your Avira scan is done.


--------------------
If I have helped you in any way, please consider a donation to help me continue the fight against malware.
[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ]
[ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ]
Go to the top of the page
 
+Quote Post
hookedforever
post Jul 7 2008, 07:06 AM
Post #37


Member
**

Group: Members
Posts: 36
Joined: 2-July 08
From: philippines
Member No.: 219,978



Hi! smile.gif

I've been running Dr WEb for like 4hours already and I guess it's still around 10%. Also, it moved SDFix.exe and ComboFix.exe...Is it fine?

I also found Antivirus XP 2008 on START>ALL PROGRAMS.

This post has been edited by hookedforever: Jul 7 2008, 07:09 AM
Go to the top of the page
 
+Quote Post
Buckeye_Sam
post Jul 7 2008, 08:31 AM
Post #38


Malware Expert
******

Group: HJT Team
Posts: 10,687
Joined: 23-December 04
From: Pickerington, Ohio
Member No.: 7,762



Those tools are detected as false positives by many antivirus programs, so that's not surprising.
It shouldn't take that long to scan though. Has it found anything else that it's removed?


--------------------
If I have helped you in any way, please consider a donation to help me continue the fight against malware.
[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ]
[ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ]
Go to the top of the page
 
+Quote Post
hookedforever
post Jul 7 2008, 08:51 AM
Post #39


Member
**

Group: Members
Posts: 36
Joined: 2-July 08
From: philippines
Member No.: 219,978



around 6 were found during express scan.
here's a screen cap of it right now (complete scan):



This post has been edited by hookedforever: Jul 7 2008, 08:52 AM
Go to the top of the page
 
+Quote Post
Buckeye_Sam
post Jul 7 2008, 10:49 AM
Post #40


Malware Expert
******

Group: HJT Team
Posts: 10,687
Joined: 23-December 04
From: Pickerington, Ohio
Member No.: 7,762



As long as it doesn't hang up and freeze, let it keep scanning.
Just post back with the log when it's done.


--------------------
If I have helped you in any way, please consider a donation to help me continue the fight against malware.
[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ]
[ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ]
Go to the top of the page
 
+Quote Post
hookedforever
post Jul 8 2008, 01:58 AM
Post #41


Member
**

Group: Members
Posts: 36
Joined: 2-July 08
From: philippines
Member No.: 219,978



Dr Web suddenly closed last night. Don't know why. I'm running it again. express scan didn't find anything. I'm currently running a complete scan.
Be back with the log.
Go to the top of the page
 
+Quote Post
Buckeye_Sam
post Jul 8 2008, 10:19 AM
Post #42


Malware Expert
******

Group: HJT Team
Posts: 10,687
Joined: 23-December 04
From: Pickerington, Ohio
Member No.: 7,762



Ok. Just post back when you can. smile.gif


--------------------
If I have helped you in any way, please consider a donation to help me continue the fight against malware.
[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ]
[ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ]
Go to the top of the page
 
+Quote Post
hookedforever
post Jul 8 2008, 07:21 PM
Post #43


Member
**

Group: Members
Posts: 36
Joined: 2-July 08
From: philippines
Member No.: 219,978



I left DrWeb running from 2pm yesterday until this morning but around 5am, it suddenly closed again (it was around 45% that time). I really don't know what happened. It has found around 8 items. I was so tired of having to repeat everything again so i just tried scanning C:\Windows\system32 since Avira found another Trojan horse there right after the reboot. After scanning system32, a .exe file was found and it was described as a HackTool so I tried curing it but it failed so I just deleted it.

What do I do next? Should I repeat the complete scan?

This post has been edited by hookedforever: Jul 8 2008, 07:22 PM
Go to the top of the page
 
+Quote Post
Buckeye_Sam
post Jul 9 2008, 09:19 AM
Post #44


Malware Expert
******

Group: HJT Team
Posts: 10,687
Joined: 23-December 04
From: Pickerington, Ohio
Member No.: 7,762



No, let's not do that again. You can go ahead and uninstall DrWeb. It's not being much help for us.

Let's try an online scan and see what it picks up.

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


--------------------
If I have helped you in any way, please consider a donation to help me continue the fight against malware.
[ Start Here ] [ Adaware 2008 ] [ Spybot ] [ AVG Antivirus ] [ Superantispyware ] [ MalwareBytes ]
[ Spyware Blaster ] [ Windows Update ] [ How to install Windows XP Recovery Console ]
Go to the top of the page
 
+Quote Post
hookedforever
post Jul 9 2008, 04:03 PM
Post #45


Member
**

Group: Members
Posts: 36
Joined: 2-July 08
From: philippines
Member No.: 219,978



Hi! I just finished the scan. Here's the log.

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3255 (20080709)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=a6439f81dc92ba4789873bc00433c033
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-07-10 10:37:14
# local_time=2008-07-10 03:37:14 (-0800, Pacific Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=277601
# found=73
# scan_time=11403
C:\Deckard\System Scanner\20080703005757\backup\DOCUME~1\ADMINI~1\LOCALS~1\Temp\removalfile.bat Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe multiple infiltrations (deleted) 00000000000000000000000000000000
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »0.exe Win32/Agent.NXF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »1.exe Win32/Adware.SpyShredder application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »2.exe Win32/Adware.SpyShredder application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »3.exe Win32/Agent.NXF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\lowpower.exe »RAR »4.exe Win32/Agent.NXF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\Documents and Settings\LocalService\Application Data\Microsoft\Internet Explorer\Desktop.htt.vir Win32/Hoax.Renos application (unable to clean - deleted) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\Program Files\PCHealthCenter\1.exe.vir Win32/Adware.SpyShredder application (unable to clean - deleted) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\Program Files\PCHealthCenter\2.exe.vir Win32/Adware.SpyShredder application (unable to clean - deleted) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\Vch40.sys.zip Win32/Wigon.CT trojan (deleted) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\Vch40.sys.zip »ZIP »Vch40.sys Win32/Wigon.CT trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\Winye05.sys.zip Win32/Wigon.CK trojan (deleted) 00000000000000000000000000000000
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\Winye05.sys.zip »ZIP »Winye05.sys Win32/Wigon.CK trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip multiple infiltrations (deleted) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/.ttB1.tmp Win32/Nuwar.CX worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/1.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/1.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/2.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/2.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/5.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/5.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/6.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/6.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/7.dflb Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/7.dllb Win32/Nuwar.Gen worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/back.exe.exe Win32/Nuwar.DC worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/CcEvtSvc.exe Win32/SpamTool.Agent.NAQ trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/desktop.html Win32/Hoax.Renos.CY virus (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/ftpdll.dll Win32/PSW.Agent.NHG trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/phcepbj0ev7g.bmp Win32/TrojanDownloader.FakeAlert.DJ trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/sysrest32.exe Win32/Nuwar.CX worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/v4xd3.ga2me Win32/TrojanDownloader.Small.IAW trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/v4xd6.gam5e Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/v5xd4.ga2me Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/v6xdt4.game Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/vx3dt2.game Win32/Nuwar worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\backups.zip »ZIP »backups/winlogon.exe Win32/TrojanProxy.Small.NP trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\catchme.zip multiple infiltrations (deleted) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\catchme.zip »ZIP »sysrest.sys Win32/Nuwar.CX worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\SDFix\SDFix\backups\catchme.zip »ZIP »asc3550p.sys Win32/Nulprot.A worm (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\Documents and Settings\All Users\Application Data\ADSL Software Ltd\WinSpywareProtect\winspywareprotect.exe Win32/Adware.WinSpywareProtect application (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\BraveSentry.exe Win32/Adware.SpySheriff application (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\BraveSentry0.dll Win32/Adware.BraveSentry application (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\BraveSentry2.dll Win32/Adware.BraveSentry application (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\BraveSentry3.dll Win32/Adware.BraveSentry application (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\Program Files\BraveSentry\Uninstall.exe Win32/Adware.SpySheriff application (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\17PHolmes27.exe Win32/TrojanDownloader.Agent.BLS trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\xpupdate.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q1.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q2.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q5.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q6.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dflgh8jkd2q7.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\djki397g.dll Win32/TrojanDownloader.Small.NTQ trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q1.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q2.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q5.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q6.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\dllgh8jkd1q7.exe Win32/Nuwar.Gen worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\hdxjd4g.dll Win32/TrojanDownloader.Small.NTQ trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\lphcepbj0ev7g.exe Win32/TrojanDownloader.FakeAlert.EH trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\maxpaynowti.exe Win32/Dialer.NAD trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxg4am1et2.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxg6ame4.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxga1me4t1.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxga4m1et4.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxga4me1.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004456\WINDOWS\system32\vedxga5me3.exe Win32/TrojanDownloader.Small.IAW trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004732\WINDOWS\msvecurity.exe Win32/Nuwar.DC worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004732\WINDOWS\system32\goht534.exe a variant of Win32/Nuwar.DA worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004732\WINDOWS\system32\goht701.exe Win32/Nuwar worm (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\07032008_004732\WINDOWS\system32\goht738.exe Win32/TrojanDownloader.Small.ODF trojan (unable to clean - deleted) 00000000000000000000000000000000
Go to the top of the page
 
+Quote Post

4 Pages V  < 1 2 3 4 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members: