Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Vundo Removal


  • This topic is locked This topic is locked
22 replies to this topic

#1 ccoia

ccoia

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:05:51 PM

Posted 12 February 2008 - 07:04 AM

Hi, I am running XP sp2 and have tried to remove a Vundo infection. Now I constantly get a notice that I have a vats infection and upon booting I get the error that:
windows cannot find c:\windows\system32\vtstq.exe. Make sure you typed the name correctly and try again.
cannot load or run c:\windows\system32\vtstq.exe specified in the registry. make sure the file exists on your computer.


Previous to contacting this forum I have run Adaware, Spybot and Stinger380.
Thanks for your help.

This is the log of the scan when the system is not in safe mode:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:42:45 AM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rnews.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtstq.exe
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [McRegWiz] /autorun
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

--
End of file - 3601 bytes

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:51 PM

Posted 14 February 2008 - 02:45 PM

Hello ccoia,

I am running XP sp2 and have tried to remove a Vundo infection.


How did you try to remove it?


Your hijackthis log is missing all the running processes. :thumbsup:
I need to see the running processes to find the infections.


The top portion of your log should look something like this:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:00:29, on 10/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe



Please reboot your computer to the Normal Mode, then post a fresh Hijackthis log. Make sure the running processes are there.

Edited by SifuMike, 14 February 2008 - 02:46 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 ccoia

ccoia
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:05:51 PM

Posted 14 February 2008 - 03:13 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:11:43 PM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
I ran vundofix and vundobegone.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rnews.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtstq.exe
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [McRegWiz] /autorun
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

--
End of file - 4939 bytes

Edited by ccoia, 14 February 2008 - 03:15 PM.


#4 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:51 PM

Posted 14 February 2008 - 05:41 PM

Hi ccoia,

We will run ComboFix.

You need to disable your McAfee Antivirus before running ComboFix, as it will prevent it from running.

To disable McAfee Virusscan:
Please navigate to the system tray on the bottom right hand corner and look for a Posted Image sign.
  • right-click it -> chose "Exit."
  • a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.
You succesfully disabled the McAfee Guard.




Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Be sure to install the Windows XP Recovery Console in case you have not installed it yet. <== IMPORTANT

Post the ComboFix log.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 ccoia

ccoia
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:05:51 PM

Posted 15 February 2008 - 07:26 AM

Had a hard time getting Mcafee to shut off. Exit was not an option when right clicking.


ComboFix 08-02-15.2 - Owner 2008-02-15 7:16:18.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.260 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\Vundo Fix\ComboFix.exe
* Created a new restore point

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\gffatpet.dll
C:\WINDOWS\system32\qtstv.ini
C:\WINDOWS\system32\qtstv.ini2
C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\vymtndgg.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.

2008-02-07 11:54 . 2008-02-07 11:57 <DIR> d-------- C:\HijackThis
2008-02-07 11:48 . 2008-02-07 11:48 20,328 --a------ C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2008-02-07 11:36 . 2008-02-07 11:36 376 --a------ C:\WINDOWS\ODBC.INI
2008-02-07 11:32 . 2008-02-07 11:32 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-02-07 11:29 . 2008-02-07 11:31 <DIR> d-------- C:\WINDOWS\ShellNew
2008-02-07 11:29 . 2008-02-07 11:29 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-02-07 07:30 . 2008-02-07 07:38 827 --a------ C:\reg.rtf
2008-02-06 12:44 . 2008-02-06 12:44 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-06 12:44 . 2008-02-06 12:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-06 12:44 . 2008-02-06 12:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-06 10:46 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-05 16:14 . 2008-02-14 14:58 1,968 --a------ C:\WINDOWS\system32\Config.MPF
2008-02-05 16:10 . 2008-02-05 16:10 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-02-05 16:10 . 2008-02-05 16:10 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-02-05 16:10 . 2008-02-05 16:10 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-02-05 16:09 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-02-05 16:07 . 2007-06-25 10:57 171,240 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-05 16:07 . 2007-06-25 10:57 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-05 16:07 . 2007-06-25 10:57 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-05 16:07 . 2007-06-25 10:57 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-05 16:06 . 2007-03-02 14:16 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-05 16:06 . 2007-06-25 14:54 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-05 16:05 . 2008-02-05 16:09 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-02-05 15:52 . 2008-02-05 15:52 <DIR> d-------- C:\Program Files\RcvSystem
2008-02-05 13:32 . 2008-02-07 06:54 774 --ahs---- C:\WINDOWS\system32\yegauytq.ini
2008-02-05 13:31 . 2008-02-05 13:31 90,688 --a------ C:\WINDOWS\system32\qtyuagey.dll
2008-02-04 15:18 . 2008-02-04 15:18 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Walgreens
2008-02-01 03:21 . 2008-02-01 03:21 245,408 --a------ C:\WINDOWS\system32\unicows.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 18:15 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe
2008-02-07 16:26 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
2008-02-07 14:41 --------- d-----w C:\Program Files\Yahoo!
2008-02-07 14:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Yahoo!
2008-02-07 14:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-06 18:42 --------- d-----w C:\Program Files\QuickTime
2008-02-06 00:12 --------- d-----w C:\Program Files\McAfee
2008-02-06 00:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-06 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-05 23:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-01-14 13:50 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-14 03:00 --------- d-----w C:\Program Files\McAfee.com
2008-01-14 02:59 --------- d-----w C:\Documents and Settings\Owner\Application Data\McAfee.com Personal Firewall
2008-01-14 02:45 --------- d-----w C:\Program Files\MySpace
2008-01-14 01:11 --------- d-----w C:\Program Files\Kodak
2008-01-14 01:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-01-14 01:10 --------- d-----w C:\Program Files\Common Files\Kodak
2008-01-14 01:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-05 03:03 --------- d-----w C:\Documents and Settings\Owner\Application Data\MySpace
2008-01-04 02:47 --------- d-----w C:\Program Files\Google
2008-01-04 02:20 --------- d-----w C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2008-01-04 01:18 --------- d-----w C:\Documents and Settings\Owner\Application Data\McAfee
2008-01-03 02:33 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-03 02:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-03 02:30 --------- d-----w C:\Program Files\Analog Devices
2008-01-03 02:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-03 02:24 --------- d-----w C:\Program Files\Citrix
2008-01-03 02:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Citrix
.
<pre>
----a-w		 1,404,928 2008-02-06 20:39:47  C:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w		   152,144 2008-02-06 20:39:47  C:\Program Files\McAfee\MSK\MskAgent .exe
----a-w			98,304 2008-02-05 21:25:33  C:\Program Files\McAfee\SpamKiller\MskAgent .exe
----a-w		   139,264 2008-02-06 21:00:22  C:\Program Files\McAfee.com\Agent\MC01A1~1 .EXE
----a-w		   139,264 2008-02-06 21:00:22  C:\Program Files\McAfee.com\Agent\MC01A1~2 .EXE
----a-w		   139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC01A1~3 .EXE
----a-w		   139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC01A1~4 .EXE
----a-w		   184,320 2008-02-04 17:50:31  C:\Program Files\McAfee.com\Agent\MC01FF~1 .EXE
----a-w		   139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC069F~1 .EXE
----a-w		   139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~2 .EXE
----a-w		   139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~3 .EXE
----a-w		   139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~4 .EXE
----a-w		   139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC099F~1 .EXE
----a-w		   139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~2 .EXE
----a-w		   139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~3 .EXE
----a-w		   139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~4 .EXE
----a-w		   139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC1E26~1 .EXE
----a-w		   139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~2 .EXE
----a-w		   139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~3 .EXE
----a-w		   139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~4 .EXE
----a-w		   184,320 2008-01-23 20:43:03  C:\Program Files\McAfee.com\Agent\MC2398~1	  .EXE
----a-w		   184,320 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC2398~1	 .EXE
----a-w		   184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1	.EXE
----a-w		   184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1   .EXE
----a-w		   184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1  .EXE
----a-w		   184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1 .EXE
----a-w		   184,320 2008-01-21 20:59:07  C:\Program Files\McAfee.com\Agent\MC2398~2 .EXE
----a-w		   184,320 2008-01-21 21:08:22  C:\Program Files\McAfee.com\Agent\MC2398~4 .EXE
----a-w		   184,320 2008-01-30 20:53:09  C:\Program Files\McAfee.com\Agent\MC3211~1 .EXE
----a-w		   184,320 2008-02-06 21:00:28  C:\Program Files\McAfee.com\Agent\MC3882~1 .EXE
----a-w		   184,320 2008-02-06 21:00:28  C:\Program Files\McAfee.com\Agent\MC3882~2 .EXE
----a-w		   184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3882~3 .EXE
----a-w		   184,320 2008-01-23 00:21:31  C:\Program Files\McAfee.com\Agent\MC3882~4 .EXE
----a-w		   184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3993~1 .EXE
----a-w		   184,320 2008-02-05 23:51:47  C:\Program Files\McAfee.com\Agent\MC3993~2 .EXE
----a-w		   184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3D5C~1 .EXE
----a-w		   184,320 2008-01-17 01:49:25  C:\Program Files\McAfee.com\Agent\MC3D5C~2 .EXE
----a-w		   184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~1  .EXE
----a-w		   184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~1 .EXE
----a-w		   184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~2	.EXE
----a-w		   184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~2   .EXE
----a-w		   184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~2  .EXE
----a-w		   184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~2 .EXE
----a-w		   184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~3 .EXE
----a-w		   184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~4 .EXE
----a-w		   184,320 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC54C0~1 .EXE
----a-w		   184,320 2008-01-25 18:10:45  C:\Program Files\McAfee.com\Agent\MC5EA7~1 .EXE
----a-w		   139,264 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC74AE~1 .EXE
----a-w		   139,264 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC74AE~2 .EXE
----a-w		   184,320 2008-01-30 00:17:40  C:\Program Files\McAfee.com\Agent\MC88A6~1 .EXE
----a-w		   184,320 2008-01-30 02:23:19  C:\Program Files\McAfee.com\Agent\MC88A8~1 .EXE
----a-w		   139,264 2008-02-06 21:00:33  C:\Program Files\McAfee.com\Agent\MC9C17~1 .EXE
----a-w		   139,264 2008-02-06 21:00:33  C:\Program Files\McAfee.com\Agent\MC9C17~2 .EXE
----a-w		   139,264 2008-02-06 21:00:34  C:\Program Files\McAfee.com\Agent\MC9C17~3 .EXE
----a-w		   139,264 2008-02-06 21:00:34  C:\Program Files\McAfee.com\Agent\MC9C17~4 .EXE
----a-w		   139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~1 .EXE
----a-w		   139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~2 .EXE
----a-w		   139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~3 .EXE
----a-w		   139,264 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MC9C99~4 .EXE
----a-w		   184,320 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MCA519~1 .EXE
----a-w		   184,320 2008-01-17 23:43:32  C:\Program Files\McAfee.com\Agent\MCA519~2 .EXE
----a-w		   139,264 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MCABBE~1 .EXE
----a-w		   139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~2 .EXE
----a-w		   139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~3 .EXE
----a-w		   139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~4 .EXE
----a-w		   245,760 2008-02-05 23:51:48  C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w		   184,320 2008-02-06 21:00:38  C:\Program Files\McAfee.com\Agent\MCBD81~1		   .EXE
----a-w		   184,320 2008-02-06 21:00:38  C:\Program Files\McAfee.com\Agent\MCBD81~1		  .EXE
----a-w		   184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1		 .EXE
----a-w		   184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1		.EXE
----a-w		   184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1	   .EXE
----a-w		   184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1	  .EXE
----a-w		   184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1	 .EXE
----a-w		   184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1	.EXE
----a-w		   184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1   .EXE
----a-w		   184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~1  .EXE
----a-w		   184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~1 .EXE
----a-w		   184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~2 .EXE
----a-w		   184,320 2008-02-01 21:10:09  C:\Program Files\McAfee.com\Agent\MCBD81~4 .EXE
----a-w		   184,320 2008-02-06 21:00:42  C:\Program Files\McAfee.com\Agent\MCC645~1 .EXE
----a-w		   184,320 2008-01-17 20:46:22  C:\Program Files\McAfee.com\Agent\MCDB2F~1 .EXE
----a-w		   184,320 2008-01-30 18:37:34  C:\Program Files\McAfee.com\Agent\MCF323~1 .EXE
----a-w		   139,264 2008-02-06 21:00:42  C:\Program Files\McAfee.com\Agent\mcregwiz .exe
----a-w		   139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~1 .EXE
----a-w		   139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~2 .EXE
----a-w		   139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~3 .EXE
----a-w		   139,264 2008-02-06 21:00:44  C:\Program Files\McAfee.com\Agent\MCREGW~4 .EXE
----a-w		   184,320 2008-02-06 21:00:44  C:\Program Files\McAfee.com\Agent\mcupdate		.exe
----a-w		   184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate	   .exe
----a-w		   184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate	  .exe
----a-w		   184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate	 .exe
----a-w		   184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate	.exe
----a-w		   184,320 2008-02-06 21:00:46  C:\Program Files\McAfee.com\Agent\mcupdate   .exe
----a-w		   184,320 2008-02-06 21:00:46  C:\Program Files\McAfee.com\Agent\mcupdate  .exe
----a-w		   184,320 2008-01-30 22:05:03  C:\Program Files\McAfee.com\Agent\mcupdate .exe
----a-w		   184,320 2008-01-15 00:39:00  C:\Program Files\McAfee.com\Agent\MCUPDA~1  .EXE
----a-w		   184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
----a-w		   184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~2 .EXE
----a-w		   184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~3 .EXE
----a-w		   225,280 2008-02-05 21:25:54  C:\Program Files\McAfee.com\MPS\mscifapp .exe
----a-w		 1,327,104 2008-02-05 21:25:54  C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
----a-w		   122,880 2008-02-05 23:45:11  C:\Program Files\McAfee.com\Shared\mcappins .exe
----a-w		   139,264 2008-02-05 23:45:39  C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
----a-w		   180,224 2008-02-05 23:45:32  C:\Program Files\McAfee.com\VSO\mcvsshld .exe
----a-w		 1,694,208 2008-02-06 20:39:56  C:\Program Files\Messenger\msmsgs .exe
----a-w			77,824 2008-02-06 18:48:46  C:\Program Files\QuickTime\qttask														   .exe
----a-w			77,824 2008-02-06 00:04:55  C:\Program Files\QuickTime\qttask														  .exe
----a-w			77,824 2008-02-06 21:00:57  C:\Program Files\QuickTime\qttask														 .exe
----a-w			77,824 2008-02-06 21:00:57  C:\Program Files\QuickTime\qttask														.exe
----a-w			77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask													   .exe
----a-w			77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask													  .exe
----a-w			77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask													 .exe
----a-w			77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask													.exe
----a-w			77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask												   .exe
----a-w			77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask												  .exe
----a-w			77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask												 .exe
----a-w			77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask												.exe
----a-w			77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask											   .exe
----a-w			77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask											  .exe
----a-w			77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask											 .exe
----a-w			77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask											.exe
----a-w			77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask										   .exe
----a-w			77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask										  .exe
----a-w			77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask										 .exe
----a-w			77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask										.exe
----a-w			77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask									   .exe
----a-w			77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask									  .exe
----a-w			77,824 2008-02-06 21:01:03  C:\Program Files\QuickTime\qttask									 .exe
----a-w			77,824 2008-02-06 21:01:04  C:\Program Files\QuickTime\qttask									.exe
----a-w			77,824 2008-02-06 21:01:04  C:\Program Files\QuickTime\qttask								   .exe
----a-w			77,824 2008-02-06 21:01:05  C:\Program Files\QuickTime\qttask								  .exe
----a-w			77,824 2008-02-06 21:01:05  C:\Program Files\QuickTime\qttask								 .exe
----a-w			77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask								.exe
----a-w			77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask							   .exe
----a-w			77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask							  .exe
----a-w			77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask							 .exe
----a-w			77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask							.exe
----a-w			77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask						   .exe
----a-w			77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask						  .exe
----a-w			77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask						 .exe
----a-w			77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask						.exe
----a-w			77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask					   .exe
----a-w			77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask					  .exe
----a-w			77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask					 .exe
----a-w			77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask					.exe
----a-w			77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask				   .exe
----a-w			77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask				  .exe
----a-w			77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask				 .exe
----a-w			77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask				.exe
----a-w			77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask			   .exe
----a-w			77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask			  .exe
----a-w			77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask			 .exe
----a-w			77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask			.exe
----a-w			77,824 2008-02-06 21:01:13  C:\Program Files\QuickTime\qttask		   .exe
----a-w			77,824 2008-02-06 21:01:13  C:\Program Files\QuickTime\qttask		  .exe
----a-w			77,824 2008-02-06 21:01:14  C:\Program Files\QuickTime\qttask		 .exe
----a-w			77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask		.exe
----a-w			77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask	   .exe
----a-w			77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask	  .exe
----a-w			77,824 2008-02-06 21:01:16  C:\Program Files\QuickTime\qttask	 .exe
----a-w			77,824 2008-02-06 21:01:16  C:\Program Files\QuickTime\qttask	.exe
----a-w			77,824 2008-02-06 21:01:17  C:\Program Files\QuickTime\qttask   .exe
----a-w			77,824 2008-02-06 21:01:17  C:\Program Files\QuickTime\qttask  .exe
----a-w			77,824 2008-02-06 21:01:18  C:\Program Files\QuickTime\qttask .exe
----a-w		 4,670,704 2008-01-14 02:33:45  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
----a-w		   158,208 2008-02-07 16:26:39  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
----a-w			77,824 2008-02-06 20:39:43  C:\WINDOWS\system32\hkcmd .exe
----a-w		   114,688 2008-02-06 20:39:43  C:\WINDOWS\system32\igfxpers .exe
----a-w			94,208 2008-02-06 20:39:39  C:\WINDOWS\system32\igfxtray .exe
</pre>


-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C44579A-F22C-4F41-891F-2D605391C1A1}]
C:\WINDOWS\system32\vtstq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e04e704f-02a3-4888-a8f4-a5f050134138}]
C:\WINDOWS\system32\gffatpet.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-11 10:16 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [ ]
"McRegWiz"=" /autorun" []
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"combofix"="C:\WINDOWS\system32\kmd.exe" [2004-08-04 02:00 388608]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnnkj]
pmnnnkj.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\80b61ec1]
--a------ 2008-02-05 13:31 90688 C:\WINDOWS\system32\qtyuagey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
--a------ 2008-02-07 08:26 158208 C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MskAgentexe]
C:\Program Files\McAfee\MSK\MskAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule11]
C:\Program Files\QdrModule\QdrModule11.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-06 10:48 77824 C:\Program Files\QuickTime\qttask .exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
--a------ 2008-02-06 10:56 36640 C:\Program Files\SiteAdvisor\6172\SiteAdv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)


.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 09:22:39 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-02-06 00:06:12 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-15 07:21:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-02-15 7:23:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-15 15:22:57
.
2008-01-16 23:50:30 --- E O F ---

#6 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:51 PM

Posted 15 February 2008 - 01:20 PM

Hi ccoia,

You win the prize for the most infections this week. :thumbsup:



Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

File:: 
C:\WINDOWS\system32\yegauytq.ini
C:\WINDOWS\system32\qtyuagey.dll
C:\WINDOWS\system32\pmnnnkj.dll
C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\gffatpet.dll
C:\WINDOWS\system32\qtyuagey.dll
C:\Program Files\QdrModule\QdrModule11.exe 

Registry:: 
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C44579A-F22C-4F41-891F-2D605391C1A1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e04e704f-02a3-4888-a8f4-a5f050134138}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnnkj]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\80b61ec1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule11]

RenV:: 
----a-w         1,404,928 2008-02-06 20:39:47  C:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w           152,144 2008-02-06 20:39:47  C:\Program Files\McAfee\MSK\MskAgent .exe
----a-w            98,304 2008-02-05 21:25:33  C:\Program Files\McAfee\SpamKiller\MskAgent .exe
----a-w           139,264 2008-02-06 21:00:22  C:\Program Files\McAfee.com\Agent\MC01A1~1 .EXE
----a-w           139,264 2008-02-06 21:00:22  C:\Program Files\McAfee.com\Agent\MC01A1~2 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC01A1~3 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC01A1~4 .EXE
----a-w           184,320 2008-02-04 17:50:31  C:\Program Files\McAfee.com\Agent\MC01FF~1 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC069F~1 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~2 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~3 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~4 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC099F~1 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~2 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~3 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~4 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC1E26~1 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~2 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~3 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~4 .EXE
----a-w           184,320 2008-01-23 20:43:03  C:\Program Files\McAfee.com\Agent\MC2398~1      .EXE
----a-w           184,320 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC2398~1     .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1    .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1   .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1  .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1 .EXE
----a-w           184,320 2008-01-21 20:59:07  C:\Program Files\McAfee.com\Agent\MC2398~2 .EXE
----a-w           184,320 2008-01-21 21:08:22  C:\Program Files\McAfee.com\Agent\MC2398~4 .EXE
----a-w           184,320 2008-01-30 20:53:09  C:\Program Files\McAfee.com\Agent\MC3211~1 .EXE
----a-w           184,320 2008-02-06 21:00:28  C:\Program Files\McAfee.com\Agent\MC3882~1 .EXE
----a-w           184,320 2008-02-06 21:00:28  C:\Program Files\McAfee.com\Agent\MC3882~2 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3882~3 .EXE
----a-w           184,320 2008-01-23 00:21:31  C:\Program Files\McAfee.com\Agent\MC3882~4 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3993~1 .EXE
----a-w           184,320 2008-02-05 23:51:47  C:\Program Files\McAfee.com\Agent\MC3993~2 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3D5C~1 .EXE
----a-w           184,320 2008-01-17 01:49:25  C:\Program Files\McAfee.com\Agent\MC3D5C~2 .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~1  .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~1 .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~2    .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~2   .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~2  .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~2 .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~3 .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~4 .EXE
----a-w           184,320 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC54C0~1 .EXE
----a-w           184,320 2008-01-25 18:10:45  C:\Program Files\McAfee.com\Agent\MC5EA7~1 .EXE
----a-w           139,264 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC74AE~1 .EXE
----a-w           139,264 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC74AE~2 .EXE
----a-w           184,320 2008-01-30 00:17:40  C:\Program Files\McAfee.com\Agent\MC88A6~1 .EXE
----a-w           184,320 2008-01-30 02:23:19  C:\Program Files\McAfee.com\Agent\MC88A8~1 .EXE
----a-w           139,264 2008-02-06 21:00:33  C:\Program Files\McAfee.com\Agent\MC9C17~1 .EXE
----a-w           139,264 2008-02-06 21:00:33  C:\Program Files\McAfee.com\Agent\MC9C17~2 .EXE
----a-w           139,264 2008-02-06 21:00:34  C:\Program Files\McAfee.com\Agent\MC9C17~3 .EXE
----a-w           139,264 2008-02-06 21:00:34  C:\Program Files\McAfee.com\Agent\MC9C17~4 .EXE
----a-w           139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~1 .EXE
----a-w           139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~2 .EXE
----a-w           139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~3 .EXE
----a-w           139,264 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MC9C99~4 .EXE
----a-w           184,320 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MCA519~1 .EXE
----a-w           184,320 2008-01-17 23:43:32  C:\Program Files\McAfee.com\Agent\MCA519~2 .EXE
----a-w           139,264 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MCABBE~1 .EXE
----a-w           139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~2 .EXE
----a-w           139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~3 .EXE
----a-w           139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~4 .EXE
----a-w           245,760 2008-02-05 23:51:48  C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w           184,320 2008-02-06 21:00:38  C:\Program Files\McAfee.com\Agent\MCBD81~1           .EXE
----a-w           184,320 2008-02-06 21:00:38  C:\Program Files\McAfee.com\Agent\MCBD81~1          .EXE
----a-w           184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1         .EXE
----a-w           184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1        .EXE
----a-w           184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1       .EXE
----a-w           184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1      .EXE
----a-w           184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1     .EXE
----a-w           184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1    .EXE
----a-w           184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1   .EXE
----a-w           184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~1  .EXE
----a-w           184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~1 .EXE
----a-w           184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~2 .EXE
----a-w           184,320 2008-02-01 21:10:09  C:\Program Files\McAfee.com\Agent\MCBD81~4 .EXE
----a-w           184,320 2008-02-06 21:00:42  C:\Program Files\McAfee.com\Agent\MCC645~1 .EXE
----a-w           184,320 2008-01-17 20:46:22  C:\Program Files\McAfee.com\Agent\MCDB2F~1 .EXE
----a-w           184,320 2008-01-30 18:37:34  C:\Program Files\McAfee.com\Agent\MCF323~1 .EXE
----a-w           139,264 2008-02-06 21:00:42  C:\Program Files\McAfee.com\Agent\mcregwiz .exe
----a-w           139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~1 .EXE
----a-w           139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~2 .EXE
----a-w           139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~3 .EXE
----a-w           139,264 2008-02-06 21:00:44  C:\Program Files\McAfee.com\Agent\MCREGW~4 .EXE
----a-w           184,320 2008-02-06 21:00:44  C:\Program Files\McAfee.com\Agent\mcupdate        .exe
----a-w           184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate       .exe
----a-w           184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate      .exe
----a-w           184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate     .exe
----a-w           184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate    .exe
----a-w           184,320 2008-02-06 21:00:46  C:\Program Files\McAfee.com\Agent\mcupdate   .exe
----a-w           184,320 2008-02-06 21:00:46  C:\Program Files\McAfee.com\Agent\mcupdate  .exe
----a-w           184,320 2008-01-30 22:05:03  C:\Program Files\McAfee.com\Agent\mcupdate .exe
----a-w           184,320 2008-01-15 00:39:00  C:\Program Files\McAfee.com\Agent\MCUPDA~1  .EXE
----a-w           184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
----a-w           184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~2 .EXE
----a-w           184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~3 .EXE
----a-w           225,280 2008-02-05 21:25:54  C:\Program Files\McAfee.com\MPS\mscifapp .exe
----a-w         1,327,104 2008-02-05 21:25:54  C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
----a-w           122,880 2008-02-05 23:45:11  C:\Program Files\McAfee.com\Shared\mcappins .exe
----a-w           139,264 2008-02-05 23:45:39  C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
----a-w           180,224 2008-02-05 23:45:32  C:\Program Files\McAfee.com\VSO\mcvsshld .exe
----a-w         1,694,208 2008-02-06 20:39:56  C:\Program Files\Messenger\msmsgs .exe
----a-w            77,824 2008-02-06 18:48:46  C:\Program Files\QuickTime\qttask                                                           .exe
----a-w            77,824 2008-02-06 00:04:55  C:\Program Files\QuickTime\qttask                                                          .exe
----a-w            77,824 2008-02-06 21:00:57  C:\Program Files\QuickTime\qttask                                                         .exe
----a-w            77,824 2008-02-06 21:00:57  C:\Program Files\QuickTime\qttask                                                        .exe
----a-w            77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask                                                       .exe
----a-w            77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask                                                      .exe
----a-w            77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask                                                     .exe
----a-w            77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask                                                    .exe
----a-w            77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask                                                   .exe
----a-w            77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask                                                  .exe
----a-w            77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask                                                 .exe
----a-w            77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask                                                .exe
----a-w            77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask                                               .exe
----a-w            77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask                                              .exe
----a-w            77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask                                             .exe
----a-w            77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask                                            .exe
----a-w            77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask                                           .exe
----a-w            77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask                                          .exe
----a-w            77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask                                         .exe
----a-w            77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask                                        .exe
----a-w            77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask                                       .exe
----a-w            77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask                                      .exe
----a-w            77,824 2008-02-06 21:01:03  C:\Program Files\QuickTime\qttask                                     .exe
----a-w            77,824 2008-02-06 21:01:04  C:\Program Files\QuickTime\qttask                                    .exe
----a-w            77,824 2008-02-06 21:01:04  C:\Program Files\QuickTime\qttask                                   .exe
----a-w            77,824 2008-02-06 21:01:05  C:\Program Files\QuickTime\qttask                                  .exe
----a-w            77,824 2008-02-06 21:01:05  C:\Program Files\QuickTime\qttask                                 .exe
----a-w            77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask                                .exe
----a-w            77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask                               .exe
----a-w            77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask                              .exe
----a-w            77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask                             .exe
----a-w            77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask                            .exe
----a-w            77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask                           .exe
----a-w            77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask                          .exe
----a-w            77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask                         .exe
----a-w            77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask                        .exe
----a-w            77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask                       .exe
----a-w            77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask                      .exe
----a-w            77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask                     .exe
----a-w            77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask                    .exe
----a-w            77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask                   .exe
----a-w            77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask                  .exe
----a-w            77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask                 .exe
----a-w            77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask                .exe
----a-w            77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask               .exe
----a-w            77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask              .exe
----a-w            77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask             .exe
----a-w            77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask            .exe
----a-w            77,824 2008-02-06 21:01:13  C:\Program Files\QuickTime\qttask           .exe
----a-w            77,824 2008-02-06 21:01:13  C:\Program Files\QuickTime\qttask          .exe
----a-w            77,824 2008-02-06 21:01:14  C:\Program Files\QuickTime\qttask         .exe
----a-w            77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask        .exe
----a-w            77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask       .exe
----a-w            77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask      .exe
----a-w            77,824 2008-02-06 21:01:16  C:\Program Files\QuickTime\qttask     .exe
----a-w            77,824 2008-02-06 21:01:16  C:\Program Files\QuickTime\qttask    .exe
----a-w            77,824 2008-02-06 21:01:17  C:\Program Files\QuickTime\qttask   .exe
----a-w            77,824 2008-02-06 21:01:17  C:\Program Files\QuickTime\qttask  .exe
----a-w            77,824 2008-02-06 21:01:18  C:\Program Files\QuickTime\qttask .exe
----a-w         4,670,704 2008-01-14 02:33:45  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
----a-w           158,208 2008-02-07 16:26:39  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
----a-w            77,824 2008-02-06 20:39:43  C:\WINDOWS\system32\hkcmd .exe
----a-w           114,688 2008-02-06 20:39:43  C:\WINDOWS\system32\igfxpers .exe
----a-w            94,208 2008-02-06 20:39:39  C:\WINDOWS\system32\igfxtray .exe


Name the Notepad file CFScript.txt and Save it to your desktop.

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Edited by SifuMike, 15 February 2008 - 01:21 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 ccoia

ccoia
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:05:51 PM

Posted 18 February 2008 - 09:27 AM

I want you to know I am out of town. Please don't close this due to inactivity. I will be back Wednesday. Thank you.

#8 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:51 PM

Posted 18 February 2008 - 11:57 AM

OK, I will keep it open until then. :thumbsup:
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 ccoia

ccoia
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:05:51 PM

Posted 22 February 2008 - 01:58 PM

Mike,

Thanks so much for keeping this open. I AM BACK!

Here is the combofix log.

ComboFix 08-02-15.2 - Owner 2008-02-22 13:45:20.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.266 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\Vundo Fix\ComboFix.exe
Command switches used :: F:\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Program Files\QdrModule\QdrModule11.exe
C:\WINDOWS\system32\gffatpet.dll
C:\WINDOWS\system32\pmnnnkj.dll
C:\WINDOWS\system32\qtyuagey.dll
C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\yegauytq.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\qtyuagey.dll
C:\WINDOWS\system32\yegauytq.ini

.
((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-16 10:04 . 2008-02-16 10:13 <DIR> d-------- C:\Program Files\dl_Cats
2008-02-16 10:00 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-16 10:00 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-16 09:59 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-16 09:59 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-15 14:33 . 2008-02-15 14:33 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-15 14:31 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-02-15 14:31 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-02-15 14:31 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-02-15 14:31 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-02-07 11:54 . 2008-02-07 11:57 <DIR> d-------- C:\HijackThis
2008-02-07 11:48 . 2008-02-07 11:48 20,328 --a------ C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2008-02-07 11:36 . 2008-02-07 11:36 376 --a------ C:\WINDOWS\ODBC.INI
2008-02-07 11:32 . 2008-02-07 11:32 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-02-07 11:29 . 2008-02-07 11:31 <DIR> d-------- C:\WINDOWS\ShellNew
2008-02-07 11:29 . 2008-02-07 11:29 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-02-07 07:30 . 2008-02-07 07:38 827 --a------ C:\reg.rtf
2008-02-06 12:44 . 2008-02-06 12:44 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-06 12:44 . 2008-02-06 12:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-06 12:44 . 2008-02-06 12:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-06 11:52 . 2008-02-07 08:26 158,208 --a--c--- C:\WINDOWS\system32\dllcache\msconfig.exe
2008-02-06 10:46 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-05 16:14 . 2008-02-22 13:46 4,332 --a------ C:\WINDOWS\system32\Config.MPF
2008-02-05 16:10 . 2008-02-18 06:08 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-02-05 16:10 . 2008-02-21 23:08 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-02-05 16:10 . 2008-02-16 09:59 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-02-05 16:09 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-02-05 16:07 . 2007-06-25 10:57 171,240 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-05 16:07 . 2007-06-25 10:57 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-05 16:07 . 2007-06-25 10:57 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-05 16:07 . 2007-06-25 10:57 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-05 16:06 . 2007-03-02 14:16 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-05 16:06 . 2007-06-25 14:54 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-05 16:05 . 2008-02-05 16:09 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-02-05 15:52 . 2008-02-05 15:52 <DIR> d-------- C:\Program Files\RcvSystem
2008-02-04 15:18 . 2008-02-04 15:18 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Walgreens
2008-02-01 03:21 . 2008-02-01 03:21 245,408 --a------ C:\WINDOWS\system32\unicows.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 21:45 --------- d-----w C:\Program Files\QuickTime
2008-02-22 21:33 --------- d-----w C:\Program Files\McAfee
2008-02-07 16:26 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe
2008-02-07 14:41 --------- d-----w C:\Program Files\Yahoo!
2008-02-07 14:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Yahoo!
2008-02-07 14:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-06 00:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-06 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-05 23:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-01-14 13:50 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-14 03:00 --------- d-----w C:\Program Files\McAfee.com
2008-01-14 02:59 --------- d-----w C:\Documents and Settings\Owner\Application Data\McAfee.com Personal Firewall
2008-01-14 02:45 --------- d-----w C:\Program Files\MySpace
2008-01-14 01:11 --------- d-----w C:\Program Files\Kodak
2008-01-14 01:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-01-14 01:10 --------- d-----w C:\Program Files\Common Files\Kodak
2008-01-14 01:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-05 03:03 --------- d-----w C:\Documents and Settings\Owner\Application Data\MySpace
2008-01-04 02:47 --------- d-----w C:\Program Files\Google
2008-01-04 02:20 --------- d-----w C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2008-01-04 01:18 --------- d-----w C:\Documents and Settings\Owner\Application Data\McAfee
2008-01-03 02:33 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-03 02:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-03 02:30 --------- d-----w C:\Program Files\Analog Devices
2008-01-03 02:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-03 02:24 --------- d-----w C:\Program Files\Citrix
2008-01-03 02:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Citrix
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-02-06 12:39 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-11 10:16 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2008-02-06 12:39 1404928]
"McRegWiz"=" /autorun" []
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-06 12:39 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-06 12:39 77824]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2008-02-06 12:39 152144]
"DLBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2007-02-22 09:26 73728]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2008-02-06 10:56 36640]
"combofix"="C:\WINDOWS\system32\kmd.exe" [2004-08-04 02:00 388608]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2007-01-05 16:22 390744]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\McAgent.exe" [2008-02-05 15:51 245760]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnnkj]
pmnnnkj.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\80b61ec1]
C:\WINDOWS\system32\qtyuagey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2008-02-06 12:39 114688 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MskAgentexe]
--a------ 2008-02-06 12:39 152144 C:\Program Files\McAfee\MSK\MskAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule11]
C:\Program Files\QdrModule\QdrModule11.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask .exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)


.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 09:22:39 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-02-06 00:06:12 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-22 13:50:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\dlbtcoms.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\cscript.exe
.
**************************************************************************
.
Completion time: 2008-02-22 13:51:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-22 21:51:51
ComboFix2.txt 2008-02-15 15:23:16
.
2008-02-17 11:01:20 --- E O F ---


Ccoia

#10 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:51 PM

Posted 22 February 2008 - 03:08 PM

Hi ccoia,

ComboFix 08-02-15.2 - Owner 2008-02-22 13:45:20.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.266 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\Vundo Fix\ComboFix.exe
Command switches used :: F:\CFScript.txt



You ran ComobFix incorreclty. :thumbsup:
Why did you run CFScript from the F drive? :blink:
It needs to run from the C drive, not the F drive.

Go back and run the last CFScript again and post the ComboFix log.

Edited by SifuMike, 22 February 2008 - 03:09 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 ccoia

ccoia
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:05:51 PM

Posted 22 February 2008 - 03:36 PM

I didn't realize if the script was on a removable drive and I dropped it on combofix it would run from the removable. Duh!

Here is a good copy.

ComboFix 08-02-15.2 - Owner 2008-02-22 15:32:40.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.255 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\Vundo Fix\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\Vundo Fix\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Program Files\QdrModule\QdrModule11.exe
C:\WINDOWS\system32\gffatpet.dll
C:\WINDOWS\system32\pmnnnkj.dll
C:\WINDOWS\system32\qtyuagey.dll
C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\yegauytq.ini
.

((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-16 10:04 . 2008-02-16 10:13 <DIR> d-------- C:\Program Files\dl_Cats
2008-02-16 10:00 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-16 10:00 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-16 09:59 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-16 09:59 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-15 14:33 . 2008-02-15 14:33 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-15 14:31 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-02-15 14:31 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-02-15 14:31 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-02-15 14:31 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-02-07 11:54 . 2008-02-07 11:57 <DIR> d-------- C:\HijackThis
2008-02-07 11:48 . 2008-02-07 11:48 20,328 --a------ C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2008-02-07 11:36 . 2008-02-07 11:36 376 --a------ C:\WINDOWS\ODBC.INI
2008-02-07 11:32 . 2008-02-07 11:32 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-02-07 11:29 . 2008-02-07 11:31 <DIR> d-------- C:\WINDOWS\ShellNew
2008-02-07 11:29 . 2008-02-07 11:29 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-02-07 07:30 . 2008-02-07 07:38 827 --a------ C:\reg.rtf
2008-02-06 12:44 . 2008-02-06 12:44 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-06 12:44 . 2008-02-06 12:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-06 12:44 . 2008-02-06 12:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-06 11:52 . 2008-02-07 08:26 158,208 --a--c--- C:\WINDOWS\system32\dllcache\msconfig.exe
2008-02-06 10:46 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-05 16:14 . 2008-02-22 15:21 4,332 --a------ C:\WINDOWS\system32\Config.MPF
2008-02-05 16:10 . 2008-02-18 06:08 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-02-05 16:10 . 2008-02-21 23:08 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-02-05 16:10 . 2008-02-16 09:59 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-02-05 16:09 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-02-05 16:07 . 2007-06-25 10:57 171,240 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-05 16:07 . 2007-06-25 10:57 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-05 16:07 . 2007-06-25 10:57 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-05 16:07 . 2007-06-25 10:57 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-05 16:06 . 2007-03-02 14:16 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-05 16:06 . 2007-06-25 14:54 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-05 16:05 . 2008-02-05 16:09 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-02-05 15:52 . 2008-02-05 15:52 <DIR> d-------- C:\Program Files\RcvSystem
2008-02-04 15:18 . 2008-02-04 15:18 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Walgreens
2008-02-01 03:21 . 2008-02-01 03:21 245,408 --a------ C:\WINDOWS\system32\unicows.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 21:45 --------- d-----w C:\Program Files\QuickTime
2008-02-22 21:33 --------- d-----w C:\Program Files\McAfee
2008-02-11 18:16 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2008-02-07 16:26 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe
2008-02-07 14:41 --------- d-----w C:\Program Files\Yahoo!
2008-02-07 14:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Yahoo!
2008-02-07 14:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-06 20:39 94,208 ----a-w C:\WINDOWS\system32\igfxtray.exe
2008-02-06 20:39 77,824 ----a-w C:\WINDOWS\system32\hkcmd.exe
2008-02-06 20:39 114,688 ----a-w C:\WINDOWS\system32\igfxpers.exe
2008-02-06 00:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-06 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-05 23:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-01-14 13:50 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-14 03:00 --------- d-----w C:\Program Files\McAfee.com
2008-01-14 02:59 --------- d-----w C:\Documents and Settings\Owner\Application Data\McAfee.com Personal Firewall
2008-01-14 02:45 --------- d-----w C:\Program Files\MySpace
2008-01-14 01:11 --------- d-----w C:\Program Files\Kodak
2008-01-14 01:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-01-14 01:10 --------- d-----w C:\Program Files\Common Files\Kodak
2008-01-14 01:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-05 03:03 --------- d-----w C:\Documents and Settings\Owner\Application Data\MySpace
2008-01-04 02:47 --------- d-----w C:\Program Files\Google
2008-01-04 02:20 --------- d-----w C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2008-01-04 01:18 --------- d-----w C:\Documents and Settings\Owner\Application Data\McAfee
2008-01-03 02:33 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-03 02:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-03 02:30 --------- d-----w C:\Program Files\Analog Devices
2008-01-03 02:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-03 02:24 --------- d-----w C:\Program Files\Citrix
2008-01-03 02:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Citrix
2007-12-14 19:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-07 01:07 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-02-06 12:39 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-11 10:16 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2008-02-06 12:39 1404928]
"McRegWiz"=" /autorun" []
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-06 12:39 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-06 12:39 77824]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2008-02-06 12:39 152144]
"DLBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2007-02-22 09:26 73728]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2008-02-06 10:56 36640]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2007-01-05 16:22 390744]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\McAgent.exe" [2008-02-05 15:51 245760]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2008-02-06 12:39 114688 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MskAgentexe]
--a------ 2008-02-06 12:39 152144 C:\Program Files\McAfee\MSK\MskAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask .exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)


.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 09:22:39 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-02-06 00:06:12 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-22 15:33:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-22 15:34:26
ComboFix-quarantined-files.txt 2008-02-22 23:34:17
ComboFix2.txt 2008-02-22 21:51:56
ComboFix3.txt 2008-02-15 15:23:16
.
2008-02-17 11:01:20 --- E O F ---

#12 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:51 PM

Posted 22 February 2008 - 04:51 PM

Hi ccoia,


Please perform this online scan: Kaspersky Webscan

Note that you need to run this scan with Internet Explorer for it to work correctly.

If you have any problem running the scan to completion, disable your Antivirus and/or firewall temporarily, just refrain from surfing around while the scan is running and be sure to re-enable when done.

To disable McAfee Virusscan:
Please navigate to the system tray on the bottom right hand corner and look for a Posted Image sign.
  • right-click it -> chose "Exit."
  • a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.
You succesfully disabled the McAfee Guard.




Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

1. Read the Requirements and Privacy statement, then select "Accept"
2. A dialogue box will appear asking "Do you want to install this software?" Name: kavwebscan_unicode.cab
NOTE: If you are running XP SP2, you may need to click on the Information Bar to allow the ActiveX to install and may need to repeat step 1.
3. Select "Install" to download the ActiveX controls that allows Kaspersky to run.
4. If running MSAS beta you may receive an alert that an IE ActiveX program requires your approval. Click "Allow"
5. Wait for the scanner to initialize and update its databases. When the download is complete it will say ready, click "Next"
6. Click "Scan Settings" and check the option to use the EXTENDED DATABASE,
Scan Options:
Scan Archives
Scan Mail Bases


then click "OK"
7. Select a target to scan: Click on "My Computer" and the scan will begin.
8. Once the scan is complete it will display if your system has been infected.
Now click on the Save Report As... button:
Under Save as type select Text file write name for the file and save it to your Desktop.
Locate the file at the Desktop, open it, then copy and paste that information in your next post.
9. Post the Kaspersky scan results in your next reply. If it is too bit to fit in the reply box, then attach the file.

Edited by SifuMike, 22 February 2008 - 04:52 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#13 ccoia

ccoia
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:05:51 PM

Posted 25 February 2008 - 12:38 PM

This was certainly more of a challenge to do than I expected. I had to shut down Mcaffee with Process Explorer. Then I tried several time to run the scan in normal mode but it would get to a certain point and ie wolud just close. I finally got it to run to completion in safe mode. Here are the results:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, February 25, 2008 12:35:03 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/02/2008
Kaspersky Anti-Virus database records: 580051
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 27920
Number of viruses found: 8
Number of infected objects: 315
Number of suspicious objects: 0
Duration of the scan process: 00:19:51

Infected Object Name / Virus Name / Last Action
C:\1F.tmp/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\1F.tmp/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.h skipped
C:\1F.tmp/stream/data0004 Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\1F.tmp/stream Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\1F.tmp NSIS: infected - 4 skipped
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\Vundo\OiUninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gr skipped
C:\Documents and Settings\Administrator\Desktop\Vundo\OiUninstaller.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012008022520080226\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.h skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream/data0004 Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir NSIS: infected - 4 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\qtyuagey.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-02-15_ 72108.20.zip/vtstq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-02-15_ 72108.20.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP13\A0000613.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP13\A0000648.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0000939.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0000980.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0000981.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0001979.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0001980.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002050.dll Infected: not-a-virus:AdWare.Win32.AdBand.h skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002139.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002468.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002470.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002514.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002531.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP15\A0002588.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP15\A0002589.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP15\A0002618.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP15\A0002620.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP16\A0002818.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP16\A0002819.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP16\A0002910.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP16\A0002911.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0003423.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0003424.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0003446.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0003449.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0004370.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0004371.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0004398.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0004399.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0005368.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0005369.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0005394.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0005396.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006368.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006369.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006394.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006395.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006437.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006441.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0007414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0007415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0007442.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0007443.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0008414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0008415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0008443.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0008444.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0009414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0009415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0009442.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0009443.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0010414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0010415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0010440.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0010441.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0010472.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0010473.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0010502.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0010503.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0011471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0011472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0011499.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0011500.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0012471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0012472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0012496.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0012498.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0013471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0013472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0013500.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0013501.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0014471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0014472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0014499.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0014500.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0015471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0015472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0015499.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0015500.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP20\A0016471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP20\A0016472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP20\A0016498.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP20\A0016499.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0016540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0016541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0016569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0016570.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0017540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0017541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0017566.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0017567.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0018540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0018541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0018563.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0018566.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0019540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0019541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0019567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0019569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0020540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0020541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0020566.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0020569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0021540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0021541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0021568.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0021569.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0022540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0022541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0022567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0022569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP25\A0023540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP25\A0023541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP25\A0023568.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP25\A0023569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0024543.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0024544.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0024564.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0024566.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0025540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0025542.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0025566.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0025567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0026540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0026541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0026566.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0026567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0027540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0027541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0027569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0027570.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0028540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0028541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0028568.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0028570.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0029540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0029541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0029568.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0029570.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0030540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0030541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0030569.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0030570.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0031539.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0031541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0031566.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0031567.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032564.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032612.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032613.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0033585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0033586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0033612.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0033614.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP28\A0034588.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP28\A0034589.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP28\A0034615.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP28\A0034617.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0035586.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0035587.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0035613.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0035616.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0036585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0036586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0036612.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0036613.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0037585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0037586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0037615.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0037616.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0038585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0038586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0038608.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0038612.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0039585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0039586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0039615.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0039616.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0040585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0040586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0040611.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0040613.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0041585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0041586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0041606.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0041607.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0041631.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0041632.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0041658.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0041659.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0042631.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0042632.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0042659.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0042661.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0043631.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0043632.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0043656.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0043657.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0044631.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0044632.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0044657.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0044658.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0044682.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0044683.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0044709.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0044711.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0045683.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0045684.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0045710.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0045711.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0046682.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0046683.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0046711.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0046712.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0047682.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0047683.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0047712.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0047713.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0048682.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0048683.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0048712.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0048713.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0048731.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0048732.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0048757.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0048758.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0049730.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0049732.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0049757.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0049758.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0050731.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0050732.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0050761.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0050762.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0050781.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0050782.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0050811.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0050812.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0051782.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0051783.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0051811.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0051812.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP34\A0051834.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP34\A0051835.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP34\A0051864.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP34\A0051865.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP35\A0051881.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP35\A0051882.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP36\A0051904.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP36\A0051905.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP37\A0051931.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP37\A0051933.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP37\A0051957.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP37\A0051959.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0051984.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0051985.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0052008.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0052010.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0052984.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0052985.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053011.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053012.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053245.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053246.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053263.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053264.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053308.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053309.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054306.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054307.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054396.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054397.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054435.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054436.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054449.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054541.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054542.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054543.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054647.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054649.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054649.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054649.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054650.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054651.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.h skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe/stream/data0004 Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe/stream Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054819.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP48\A0054882.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP48\A0054882.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP55\A0055261.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP57\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

Scan process completed.

#14 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:03:51 PM

Posted 25 February 2008 - 02:23 PM

Hi ccoia,

Most of what Kaspersky found was in the quarentine folder or in System Restore folder, and we will clean those later.

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\1F.tmp
    C:\Documents and Settings\Administrator\Desktop\Vundo\OiUninstaller.exe


  • Return to OTMoveIt2, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
  • Note : If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
    C:\_OTMoveIt2\MovedFiles\********_******.log
    (where "********_******" is the "date_time")
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Caution: Be careful of what you copy and paste with this tool. OTMoveIt2 is a powerful program, designed to move highly persistent files and folders. Not following the directions as instructed or using incorrectly could lead to disastrous problems with your operating system.



Perform the Kaspersky Webscan online scan (follow the directions posted previously) and post the Kaspersky scan log.

Edited by SifuMike, 25 February 2008 - 02:25 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#15 ccoia

ccoia
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:05:51 PM

Posted 25 February 2008 - 03:11 PM

From Move It log:

C:\1F.tmp moved successfully.
C:\Documents and Settings\Administrator\Desktop\Vundo\OiUninstaller.exe moved successfully.

OTMoveIt2 v1.0.20 log created on 02252008_144450



From Kasp:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, February 25, 2008 3:08:44 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/02/2008
Kaspersky Anti-Virus database records: 580494
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 27987
Number of viruses found: 8
Number of infected objects: 315
Number of suspicious objects: 0
Duration of the scan process: 00:19:49

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012008022520080226\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.h skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream/data0004 Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir NSIS: infected - 4 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\qtyuagey.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-02-15_ 72108.20.zip/vtstq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-02-15_ 72108.20.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP13\A0000613.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP13\A0000648.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0000939.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0000980.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0000981.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0001979.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0001980.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002050.dll Infected: not-a-virus:AdWare.Win32.AdBand.h skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002139.exe Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002468.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002470.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002514.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP14\A0002531.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP15\A0002588.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP15\A0002589.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP15\A0002618.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP15\A0002620.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP16\A0002818.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP16\A0002819.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP16\A0002910.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP16\A0002911.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0003423.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0003424.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0003446.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0003449.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0004370.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0004371.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0004398.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0004399.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0005368.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0005369.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0005394.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0005396.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006368.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006369.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006394.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006395.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006437.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0006441.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0007414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0007415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0007442.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0007443.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0008414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0008415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0008443.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0008444.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0009414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0009415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0009442.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0009443.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0010414.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0010415.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0010440.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP17\A0010441.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0010472.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0010473.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0010502.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0010503.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0011471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0011472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0011499.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP18\A0011500.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0012471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0012472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0012496.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0012498.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0013471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0013472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0013500.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0013501.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0014471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0014472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0014499.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0014500.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0015471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0015472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0015499.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP19\A0015500.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP20\A0016471.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP20\A0016472.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP20\A0016498.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP20\A0016499.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0016540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0016541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0016569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0016570.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0017540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0017541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0017566.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP23\A0017567.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0018540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0018541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0018563.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0018566.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0019540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0019541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0019567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0019569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0020540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0020541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0020566.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0020569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0021540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0021541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0021568.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0021569.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0022540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0022541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0022567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP24\A0022569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP25\A0023540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP25\A0023541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP25\A0023568.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP25\A0023569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0024543.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0024544.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0024564.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0024566.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0025540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0025542.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0025566.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0025567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0026540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0026541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0026566.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0026567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0027540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0027541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0027569.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0027570.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0028540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0028541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0028568.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0028570.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0029540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0029541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0029568.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0029570.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0030540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0030541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0030569.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0030570.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0031539.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0031541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0031566.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP26\A0031567.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032540.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032541.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032564.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032567.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032612.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0032613.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0033585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0033586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0033612.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP27\A0033614.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP28\A0034588.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP28\A0034589.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP28\A0034615.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP28\A0034617.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0035586.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0035587.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0035613.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0035616.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0036585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0036586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0036612.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0036613.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0037585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0037586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0037615.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0037616.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0038585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0038586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0038608.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0038612.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0039585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0039586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0039615.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0039616.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0040585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0040586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0040611.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0040613.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0041585.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0041586.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0041606.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP29\A0041607.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0041631.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0041632.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0041658.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0041659.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0042631.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0042632.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0042659.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0042661.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0043631.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0043632.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0043656.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0043657.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0044631.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0044632.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0044657.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP30\A0044658.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0044682.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0044683.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0044709.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0044711.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0045683.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0045684.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0045710.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0045711.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0046682.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0046683.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0046711.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0046712.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0047682.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0047683.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0047712.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0047713.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0048682.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0048683.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0048712.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP31\A0048713.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0048731.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0048732.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0048757.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0048758.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0049730.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0049732.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0049757.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0049758.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0050731.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0050732.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0050761.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP32\A0050762.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0050781.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0050782.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0050811.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0050812.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0051782.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0051783.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0051811.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP33\A0051812.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP34\A0051834.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP34\A0051835.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP34\A0051864.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP34\A0051865.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP35\A0051881.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP35\A0051882.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP36\A0051904.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP36\A0051905.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP37\A0051931.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP37\A0051933.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP37\A0051957.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP37\A0051959.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0051984.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0051985.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0052008.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0052010.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0052984.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0052985.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053011.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053012.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053245.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053246.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053263.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053264.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053308.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0053309.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054306.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054307.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054396.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054397.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054435.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054436.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP38\A0054449.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054541.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054542.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054543.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054647.exe Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054649.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054649.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054649.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054650.exe Infected: Trojan-Downloader.Win32.Agent.jjr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP39\A0054651.exe Infected: not-a-virus:AdWare.Win32.Agent.adm skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.h skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe/stream/data0004 Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe/stream Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054812.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP47\A0054819.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP48\A0054882.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gr skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP48\A0054882.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP55\A0055261.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{61AB1C25-F83F-4B80-B442-2404D127451A}\RP57\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\_OTMoveIt\MovedFiles\02252008_144450\1F.tmp/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\_OTMoveIt\MovedFiles\02252008_144450\1F.tmp/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.h skipped
C:\_OTMoveIt\MovedFiles\02252008_144450\1F.tmp/stream/data0004 Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\_OTMoveIt\MovedFiles\02252008_144450\1F.tmp/stream Infected: Trojan-Downloader.Win32.Agent.jjq skipped
C:\_OTMoveIt\MovedFiles\02252008_144450\1F.tmp NSIS: infected - 4 skipped
C:\_OTMoveIt\MovedFiles\02252008_144450\Documents and Settings\Administrator\Desktop\Vundo\OiUninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.gr skipped
C:\_OTMoveIt\MovedFiles\02252008_144450\Documents and Settings\Administrator\Desktop\Vundo\OiUninstaller.exe NSIS: infected - 1 skipped

Scan process completed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users