Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

One more


  • Please log in to reply
5 replies to this topic

#1 frizzbee

frizzbee

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:00 PM

Posted 21 March 2005 - 01:10 PM

My original message seems to have vaporized. Here it is again:

I can see my story is hardly unique. My Windows 95 system has been hijacked by something that sets my home page to http://213.159.117.134/index.php and gives me endless pop-ups asking me to "Please select your country." I (naively) thought I could fix this myself by deleting a bunch of files, even removing Internet Explorer from my system.

I'm pretty sure I didn't do that correctly, though, since I couldn't delete it through the Start+Settings+Control Panel+Add/Remove Programs route. So I ended up removing as much evidence of IE (version 5.5) as I could through deleting individual program files on Windows Explorer.

That hasn't solved the problem, but at least now when the spyware tries to launch a new Internet Explorer window I just get an error message instead of a new IE browser window. In the meantime, I'm using Netscape, which does not appear to have been hijacked. But the bug has clearly slowed things down way too much, requiring more than a minute for my machine to load even the Google home page on a DSL line.

I also downloaded Spybot, with which I was able to delete another bug, Internet Optimizer. But it evidently isn't designed to kill this thing.

Here's the HJ log. I'm at your mercy. Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 12:06:30 AM, on 3/20/2005
Platform: Windows 95 B (Win9x 4.00.1111)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\VISUAL IP INSIGHT\TDS\ARUPLD32.EXE
C:\PROGRAM FILES\VISUAL IP INSIGHT\TDS\ARMON32A.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\PNPCHK.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\MOUSE\AMOUMAIN.EXE
C:\WINDOWS\SYSTEM\PAYTIME.EXE
C:\WINDOWS\SYSTEM\FFO.EXE
C:\WINDOWS\SYSTEM\LOADWC.EXE
C:\124491.EXE
C:\WINDOWS\RunDLL.EXE
C:\WINDOWS\SYSTEM\PAYTIME.EXE
C:\124491.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\NETSCAPE\NETSCAPE 6\NETSCP6.EXE
C:\124491.EXE
C:\124491.EXE
C:\124491.EXE
C:\124491.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>
R3 - URLSearchHook: (no name) - {30192F8D-0958-44E6-B54D-331FD39AC959} - (no file)
F1 - win.ini: run=C:\WINDOWS\PNPCHK.EXE
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\SYSTEM\DSMANA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe
O4 - HKLM\..\Run: [Asa] C:\WINDOWS\SYSTEM\Ffo.exe
O4 - HKLM\..\Run: [saap] c:\windows\saap.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [whebyt] C:\WINDOWS\whebyt.exe
O4 - HKLM\..\Run: [Taa] C:\WINDOWS\Kve.exe
O4 - HKLM\..\Run: [Dgb] C:\WINDOWS\SYSTEM\Kvq.exe
O4 - HKLM\..\Run: [Gbo] C:\WINDOWS\Ccv.exe
O4 - HKLM\..\Run: [Svt] C:\WINDOWS\Uva.exe
O4 - HKLM\..\Run: [Ktn] C:\WINDOWS\Kkj.exe
O4 - HKLM\..\Run: [Hvl] C:\WINDOWS\SYSTEM\Ije.exe
O4 - HKLM\..\Run: [Grm] C:\WINDOWS\SYSTEM\Oud.exe
O4 - HKLM\..\Run: [Vpb] C:\WINDOWS\SYSTEM\Ikm.exe
O4 - HKLM\..\Run: [Kkp] C:\WINDOWS\Klc.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [Alh] C:\WINDOWS\Abf.exe
O4 - HKLM\..\Run: [Hho] C:\WINDOWS\SYSTEM\Ftn.exe
O4 - HKLM\..\Run: [Cvp] C:\WINDOWS\Ptt.exe
O4 - HKLM\..\Run: [Smt] C:\WINDOWS\Vvf.exe
O4 - HKLM\..\Run: [Uak] C:\WINDOWS\SYSTEM\Pcu.exe
O4 - HKLM\..\Run: [Snm] C:\WINDOWS\Rbd.exe
O4 - HKLM\..\Run: [Mtp] C:\WINDOWS\Mjf.exe
O4 - HKLM\..\Run: [Eju] C:\WINDOWS\Sem.exe
O4 - HKLM\..\Run: [Icv] C:\WINDOWS\SYSTEM\Fva.exe
O4 - HKLM\..\Run: [Tdm] C:\WINDOWS\SYSTEM\Dst.exe
O4 - HKLM\..\Run: [Qmt] C:\WINDOWS\SYSTEM\Flu.exe
O4 - HKLM\..\Run: [Lqs] C:\WINDOWS\Klv.exe
O4 - HKLM\..\Run: [Hur] C:\WINDOWS\SYSTEM\Mvk.exe
O4 - HKLM\..\Run: [Drc] C:\WINDOWS\SYSTEM\Qee.exe
O4 - HKLM\..\Run: [Qsl] C:\WINDOWS\SYSTEM\Aon.exe
O4 - HKLM\..\Run: [Ogf] C:\WINDOWS\Ids.exe
O4 - HKLM\..\Run: [Vbm] C:\WINDOWS\Ggh.exe
O4 - HKLM\..\Run: [BrowserWebCheck] loadwc.exe
O4 - HKLM\..\Run: [Bvr] C:\WINDOWS\Akg.exe
O4 - HKLM\..\Run: [Oib] C:\WINDOWS\Gae.exe
O4 - HKLM\..\Run: [Uic] C:\WINDOWS\SYSTEM\Gsv.exe
O4 - HKLM\..\Run: [Irb] C:\WINDOWS\Akf.exe
O4 - HKLM\..\Run: [Ini] C:\WINDOWS\Hpt.exe
O4 - HKLM\..\Run: [Sjt] C:\WINDOWS\SYSTEM\Oao.exe
O4 - HKLM\..\Run: [Cmm] C:\WINDOWS\Lvo.exe
O4 - HKLM\..\Run: [Jkf] C:\WINDOWS\SYSTEM\Ikb.exe
O4 - HKLM\..\Run: [Vgs] C:\WINDOWS\Srq.exe
O4 - HKLM\..\Run: [Maq] C:\WINDOWS\SYSTEM\Bos.exe
O4 - HKLM\..\Run: [Tcv] C:\WINDOWS\Oku.exe
O4 - HKLM\..\Run: [Crr] C:\WINDOWS\SYSTEM\Smj.exe
O4 - HKLM\..\Run: [Fvo] C:\WINDOWS\Epo.exe
O4 - HKLM\..\Run: [Ndd] C:\WINDOWS\SYSTEM\Jef.exe
O4 - HKLM\..\Run: [Meu] C:\WINDOWS\Kti.exe
O4 - HKLM\..\Run: [Eor] C:\WINDOWS\Uqa.exe
O4 - HKLM\..\Run: [Fec] C:\WINDOWS\Ahc.exe
O4 - HKLM\..\Run: [Urj] C:\WINDOWS\Jcd.exe
O4 - HKLM\..\Run: [Iij] C:\WINDOWS\SYSTEM\Upo.exe
O4 - HKLM\..\Run: [Iil] C:\WINDOWS\SYSTEM\Jls.exe
O4 - HKLM\..\Run: [Llp] C:\WINDOWS\SYSTEM\Dai.exe
O4 - HKLM\..\RunServices: [AccessRampLAN 01] "C:\PROGRAM FILES\VISUAL IP INSIGHT\TDS\ARUpld32.exe" -l
O4 - HKLM\..\RunServices: [AccessRampMonitor 01] "C:\PROGRAM FILES\VISUAL IP INSIGHT\TDS\ARMon32a.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe
O4 - HKCU\..\Run: [Asa] C:\WINDOWS\SYSTEM\Ffo.exe
O4 - HKCU\..\Run: [Taa] C:\WINDOWS\Kve.exe
O4 - HKCU\..\Run: [Dgb] C:\WINDOWS\SYSTEM\Kvq.exe
O4 - HKCU\..\Run: [Gbo] C:\WINDOWS\Ccv.exe
O4 - HKCU\..\Run: [Svt] C:\WINDOWS\Uva.exe
O4 - HKCU\..\Run: [Ktn] C:\WINDOWS\Kkj.exe
O4 - HKCU\..\Run: [Hvl] C:\WINDOWS\SYSTEM\Ije.exe
O4 - HKCU\..\Run: [Grm] C:\WINDOWS\SYSTEM\Oud.exe
O4 - HKCU\..\Run: [Vpb] C:\WINDOWS\SYSTEM\Ikm.exe
O4 - HKCU\..\Run: [Kkp] C:\WINDOWS\Klc.exe
O4 - HKCU\..\Run: [Alh] C:\WINDOWS\Abf.exe
O4 - HKCU\..\Run: [Hho] C:\WINDOWS\SYSTEM\Ftn.exe
O4 - HKCU\..\Run: [Cvp] C:\WINDOWS\Ptt.exe
O4 - HKCU\..\Run: [Smt] C:\WINDOWS\Vvf.exe
O4 - HKCU\..\Run: [Uak] C:\WINDOWS\SYSTEM\Pcu.exe
O4 - HKCU\..\Run: [Snm] C:\WINDOWS\Rbd.exe
O4 - HKCU\..\Run: [Mtp] C:\WINDOWS\Mjf.exe
O4 - HKCU\..\Run: [Eju] C:\WINDOWS\Sem.exe
O4 - HKCU\..\Run: [Icv] C:\WINDOWS\SYSTEM\Fva.exe
O4 - HKCU\..\Run: [Tdm] C:\WINDOWS\SYSTEM\Dst.exe
O4 - HKCU\..\Run: [Qmt] C:\WINDOWS\SYSTEM\Flu.exe
O4 - HKCU\..\Run: [Lqs] C:\WINDOWS\Klv.exe
O4 - HKCU\..\Run: [Hur] C:\WINDOWS\SYSTEM\Mvk.exe
O4 - HKCU\..\Run: [Drc] C:\WINDOWS\SYSTEM\Qee.exe
O4 - HKCU\..\Run: [Qsl] C:\WINDOWS\SYSTEM\Aon.exe
O4 - HKCU\..\Run: [Ogf] C:\WINDOWS\Ids.exe
O4 - HKCU\..\Run: [Vbm] C:\WINDOWS\Ggh.exe
O4 - HKCU\..\Run: [Bvr] C:\WINDOWS\Akg.exe
O4 - HKCU\..\Run: [Oib] C:\WINDOWS\Gae.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uic] C:\WINDOWS\SYSTEM\Gsv.exe
O4 - HKCU\..\Run: [Irb] C:\WINDOWS\Akf.exe
O4 - HKCU\..\Run: [Ini] C:\WINDOWS\Hpt.exe
O4 - HKCU\..\Run: [Sjt] C:\WINDOWS\SYSTEM\Oao.exe
O4 - HKCU\..\Run: [Cmm] C:\WINDOWS\Lvo.exe
O4 - HKCU\..\Run: [Jkf] C:\WINDOWS\SYSTEM\Ikb.exe
O4 - HKCU\..\Run: [Vgs] C:\WINDOWS\Srq.exe
O4 - HKCU\..\Run: [Maq] C:\WINDOWS\SYSTEM\Bos.exe
O4 - HKCU\..\Run: [Tcv] C:\WINDOWS\Oku.exe
O4 - HKCU\..\Run: [Crr] C:\WINDOWS\SYSTEM\Smj.exe
O4 - HKCU\..\Run: [Fvo] C:\WINDOWS\Epo.exe
O4 - HKCU\..\Run: [Ndd] C:\WINDOWS\SYSTEM\Jef.exe
O4 - HKCU\..\Run: [Meu] C:\WINDOWS\Kti.exe
O4 - HKCU\..\Run: [Eor] C:\WINDOWS\Uqa.exe
O4 - HKCU\..\Run: [Fec] C:\WINDOWS\Ahc.exe
O4 - HKCU\..\Run: [Urj] C:\WINDOWS\Jcd.exe
O4 - HKCU\..\Run: [Iij] C:\WINDOWS\SYSTEM\Upo.exe
O4 - HKCU\..\Run: [Iil] C:\WINDOWS\SYSTEM\Jls.exe
O4 - HKCU\..\Run: [Llp] C:\WINDOWS\SYSTEM\Dai.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\Net2Phone\Net2fone.exe (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\Net2Phone\Net2fone.exe (file missing)
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O13 - WWW. Prefix: http://
O14 - IERESET.INF: SEARCH_PAGE_URL=http://home.microsoft.com/access/allinone.asp
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.iframedollars.biz
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - Trusted IP range: 213.159.117.202
O15 - Trusted IP range: 213.159.117.202 (HKLM)
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://iframedollars.biz/tb/loader2.ocx

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:00 PM

Posted 21 March 2005 - 03:08 PM

Do you know what this is?

O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe

If not submit the c:\windows\system\paytime.exe file to http://www.bleepingcomputer.com/submit-malware.php



Print out these instructions and then close all windows including Internet Explorer.

Reboot your computer into Safe Mode


Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://213.159.117.134/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://213.159.117.134/index.php
R3 - URLSearchHook: (no name) - {30192F8D-0958-44E6-B54D-331FD39AC959} - (no file)
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\SYSTEM\DSMANA~1.DLL
O3 - Toolbar: (no name) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe
O4 - HKLM\..\Run: [Asa] C:\WINDOWS\SYSTEM\Ffo.exe
O4 - HKLM\..\Run: [saap] c:\windows\saap.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [whebyt] C:\WINDOWS\whebyt.exe
O4 - HKLM\..\Run: [Taa] C:\WINDOWS\Kve.exe
O4 - HKLM\..\Run: [Dgb] C:\WINDOWS\SYSTEM\Kvq.exe
O4 - HKLM\..\Run: [Gbo] C:\WINDOWS\Ccv.exe
O4 - HKLM\..\Run: [Svt] C:\WINDOWS\Uva.exe
O4 - HKLM\..\Run: [Ktn] C:\WINDOWS\Kkj.exe
O4 - HKLM\..\Run: [Hvl] C:\WINDOWS\SYSTEM\Ije.exe
O4 - HKLM\..\Run: [Grm] C:\WINDOWS\SYSTEM\Oud.exe
O4 - HKLM\..\Run: [Vpb] C:\WINDOWS\SYSTEM\Ikm.exe
O4 - HKLM\..\Run: [Kkp] C:\WINDOWS\Klc.exe
O4 - HKLM\..\Run: [Alh] C:\WINDOWS\Abf.exe
O4 - HKLM\..\Run: [Hho] C:\WINDOWS\SYSTEM\Ftn.exe
O4 - HKLM\..\Run: [Cvp] C:\WINDOWS\Ptt.exe
O4 - HKLM\..\Run: [Smt] C:\WINDOWS\Vvf.exe
O4 - HKLM\..\Run: [Uak] C:\WINDOWS\SYSTEM\Pcu.exe
O4 - HKLM\..\Run: [Snm] C:\WINDOWS\Rbd.exe
O4 - HKLM\..\Run: [Mtp] C:\WINDOWS\Mjf.exe
O4 - HKLM\..\Run: [Eju] C:\WINDOWS\Sem.exe
O4 - HKLM\..\Run: [Icv] C:\WINDOWS\SYSTEM\Fva.exe
O4 - HKLM\..\Run: [Tdm] C:\WINDOWS\SYSTEM\Dst.exe
O4 - HKLM\..\Run: [Qmt] C:\WINDOWS\SYSTEM\Flu.exe
O4 - HKLM\..\Run: [Lqs] C:\WINDOWS\Klv.exe
O4 - HKLM\..\Run: [Hur] C:\WINDOWS\SYSTEM\Mvk.exe
O4 - HKLM\..\Run: [Drc] C:\WINDOWS\SYSTEM\Qee.exe
O4 - HKLM\..\Run: [Qsl] C:\WINDOWS\SYSTEM\Aon.exe
O4 - HKLM\..\Run: [Ogf] C:\WINDOWS\Ids.exe
O4 - HKLM\..\Run: [Vbm] C:\WINDOWS\Ggh.exe
O4 - HKLM\..\Run: [Bvr] C:\WINDOWS\Akg.exe
O4 - HKLM\..\Run: [Oib] C:\WINDOWS\Gae.exe
O4 - HKLM\..\Run: [Uic] C:\WINDOWS\SYSTEM\Gsv.exe
O4 - HKLM\..\Run: [Irb] C:\WINDOWS\Akf.exe
O4 - HKLM\..\Run: [Ini] C:\WINDOWS\Hpt.exe
O4 - HKLM\..\Run: [Sjt] C:\WINDOWS\SYSTEM\Oao.exe
O4 - HKLM\..\Run: [Cmm] C:\WINDOWS\Lvo.exe
O4 - HKLM\..\Run: [Jkf] C:\WINDOWS\SYSTEM\Ikb.exe
O4 - HKLM\..\Run: [Vgs] C:\WINDOWS\Srq.exe
O4 - HKLM\..\Run: [Maq] C:\WINDOWS\SYSTEM\Bos.exe
O4 - HKLM\..\Run: [Tcv] C:\WINDOWS\Oku.exe
O4 - HKLM\..\Run: [Crr] C:\WINDOWS\SYSTEM\Smj.exe
O4 - HKLM\..\Run: [Fvo] C:\WINDOWS\Epo.exe
O4 - HKLM\..\Run: [Ndd] C:\WINDOWS\SYSTEM\Jef.exe
O4 - HKLM\..\Run: [Meu] C:\WINDOWS\Kti.exe
O4 - HKLM\..\Run: [Eor] C:\WINDOWS\Uqa.exe
O4 - HKLM\..\Run: [Fec] C:\WINDOWS\Ahc.exe
O4 - HKLM\..\Run: [Urj] C:\WINDOWS\Jcd.exe
O4 - HKLM\..\Run: [Iij] C:\WINDOWS\SYSTEM\Upo.exe
O4 - HKLM\..\Run: [Iil] C:\WINDOWS\SYSTEM\Jls.exe
O4 - HKLM\..\Run: [Llp] C:\WINDOWS\SYSTEM\Dai.exe
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe
O4 - HKCU\..\Run: [Asa] C:\WINDOWS\SYSTEM\Ffo.exe
O4 - HKCU\..\Run: [Taa] C:\WINDOWS\Kve.exe
O4 - HKCU\..\Run: [Dgb] C:\WINDOWS\SYSTEM\Kvq.exe
O4 - HKCU\..\Run: [Gbo] C:\WINDOWS\Ccv.exe
O4 - HKCU\..\Run: [Svt] C:\WINDOWS\Uva.exe
O4 - HKCU\..\Run: [Ktn] C:\WINDOWS\Kkj.exe
O4 - HKCU\..\Run: [Hvl] C:\WINDOWS\SYSTEM\Ije.exe
O4 - HKCU\..\Run: [Grm] C:\WINDOWS\SYSTEM\Oud.exe
O4 - HKCU\..\Run: [Vpb] C:\WINDOWS\SYSTEM\Ikm.exe
O4 - HKCU\..\Run: [Kkp] C:\WINDOWS\Klc.exe
O4 - HKCU\..\Run: [Alh] C:\WINDOWS\Abf.exe
O4 - HKCU\..\Run: [Hho] C:\WINDOWS\SYSTEM\Ftn.exe
O4 - HKCU\..\Run: [Cvp] C:\WINDOWS\Ptt.exe
O4 - HKCU\..\Run: [Smt] C:\WINDOWS\Vvf.exe
O4 - HKCU\..\Run: [Uak] C:\WINDOWS\SYSTEM\Pcu.exe
O4 - HKCU\..\Run: [Snm] C:\WINDOWS\Rbd.exe
O4 - HKCU\..\Run: [Mtp] C:\WINDOWS\Mjf.exe
O4 - HKCU\..\Run: [Eju] C:\WINDOWS\Sem.exe
O4 - HKCU\..\Run: [Icv] C:\WINDOWS\SYSTEM\Fva.exe
O4 - HKCU\..\Run: [Tdm] C:\WINDOWS\SYSTEM\Dst.exe
O4 - HKCU\..\Run: [Qmt] C:\WINDOWS\SYSTEM\Flu.exe
O4 - HKCU\..\Run: [Lqs] C:\WINDOWS\Klv.exe
O4 - HKCU\..\Run: [Hur] C:\WINDOWS\SYSTEM\Mvk.exe
O4 - HKCU\..\Run: [Drc] C:\WINDOWS\SYSTEM\Qee.exe
O4 - HKCU\..\Run: [Qsl] C:\WINDOWS\SYSTEM\Aon.exe
O4 - HKCU\..\Run: [Ogf] C:\WINDOWS\Ids.exe
O4 - HKCU\..\Run: [Vbm] C:\WINDOWS\Ggh.exe
O4 - HKCU\..\Run: [Bvr] C:\WINDOWS\Akg.exe
O4 - HKCU\..\Run: [Oib] C:\WINDOWS\Gae.exe
O4 - HKCU\..\Run: [Uic] C:\WINDOWS\SYSTEM\Gsv.exe
O4 - HKCU\..\Run: [Irb] C:\WINDOWS\Akf.exe
O4 - HKCU\..\Run: [Ini] C:\WINDOWS\Hpt.exe
O4 - HKCU\..\Run: [Sjt] C:\WINDOWS\SYSTEM\Oao.exe
O4 - HKCU\..\Run: [Cmm] C:\WINDOWS\Lvo.exe
O4 - HKCU\..\Run: [Jkf] C:\WINDOWS\SYSTEM\Ikb.exe
O4 - HKCU\..\Run: [Vgs] C:\WINDOWS\Srq.exe
O4 - HKCU\..\Run: [Maq] C:\WINDOWS\SYSTEM\Bos.exe
O4 - HKCU\..\Run: [Tcv] C:\WINDOWS\Oku.exe
O4 - HKCU\..\Run: [Crr] C:\WINDOWS\SYSTEM\Smj.exe
O4 - HKCU\..\Run: [Fvo] C:\WINDOWS\Epo.exe
O4 - HKCU\..\Run: [Ndd] C:\WINDOWS\SYSTEM\Jef.exe
O4 - HKCU\..\Run: [Meu] C:\WINDOWS\Kti.exe
O4 - HKCU\..\Run: [Eor] C:\WINDOWS\Uqa.exe
O4 - HKCU\..\Run: [Fec] C:\WINDOWS\Ahc.exe
O4 - HKCU\..\Run: [Urj] C:\WINDOWS\Jcd.exe
O4 - HKCU\..\Run: [Iij] C:\WINDOWS\SYSTEM\Upo.exe
O4 - HKCU\..\Run: [Iil] C:\WINDOWS\SYSTEM\Jls.exe
O4 - HKCU\..\Run: [Llp] C:\WINDOWS\SYSTEM\Dai.exe
O13 - WWW. Prefix: http://
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.iframedollars.biz
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.iframedollars.biz (HKLM)
O15 - Trusted IP range: 213.159.117.202
O15 - Trusted IP range: 213.159.117.202 (HKLM)
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://iframedollars.biz/tb/loader2.ocx

Then delete these files or directories (Do not be concerned if they do not exist)

C:\WINDOWS\SYSTEM\DSMANA~1.DLL
C:\WINDOWS\SYSTEM\Ffo.exe
c:\windows\saap.exe
C:\Program Files\Internet Optimizer\
C:\WINDOWS\whebyt.exe
C:\WINDOWS\Kve.exe
C:\WINDOWS\SYSTEM\Kvq.exe
C:\WINDOWS\Ccv.exe
C:\WINDOWS\Uva.exe
C:\WINDOWS\Kkj.exe
C:\WINDOWS\SYSTEM\Ije.exe
C:\WINDOWS\SYSTEM\Oud.exe
C:\WINDOWS\SYSTEM\Ikm.exe
C:\WINDOWS\Klc.exe
C:\WINDOWS\Abf.exe
C:\WINDOWS\SYSTEM\Ftn.exe
C:\WINDOWS\Ptt.exe
C:\WINDOWS\Vvf.exe
C:\WINDOWS\SYSTEM\Pcu.exe
C:\WINDOWS\Rbd.exe
C:\WINDOWS\Mjf.exe
C:\WINDOWS\Sem.exe
C:\WINDOWS\SYSTEM\Fva.exe
C:\WINDOWS\SYSTEM\Dst.exe
C:\WINDOWS\SYSTEM\Flu.exe
C:\WINDOWS\Klv.exe
C:\WINDOWS\SYSTEM\Mvk.exe
C:\WINDOWS\SYSTEM\Qee.exe
C:\WINDOWS\SYSTEM\Aon.exe
C:\WINDOWS\Ids.exe
C:\WINDOWS\Ggh.exe
C:\WINDOWS\Akg.exe
C:\WINDOWS\Gae.exe
C:\WINDOWS\SYSTEM\Gsv.exe
C:\WINDOWS\Akf.exe
C:\WINDOWS\Hpt.exe
C:\WINDOWS\SYSTEM\Oao.exe
C:\WINDOWS\Lvo.exe
C:\WINDOWS\SYSTEM\Ikb.exe
C:\WINDOWS\Srq.exe
C:\WINDOWS\SYSTEM\Bos.exe
C:\WINDOWS\Oku.exe
C:\WINDOWS\SYSTEM\Smj.exe
C:\WINDOWS\Epo.exe
C:\WINDOWS\SYSTEM\Jef.exe
C:\WINDOWS\Kti.exe
C:\WINDOWS\Uqa.exe
C:\WINDOWS\Ahc.exe
C:\WINDOWS\Jcd.exe
C:\WINDOWS\SYSTEM\Upo.exe
C:\WINDOWS\SYSTEM\Jls.exe
C:\WINDOWS\SYSTEM\Dai.exe
C:\WINDOWS\SYSTEM\Ffo.exe
C:\WINDOWS\Kve.exe
C:\WINDOWS\SYSTEM\Kvq.exe
C:\WINDOWS\Ccv.exe
C:\WINDOWS\Uva.exe
C:\WINDOWS\Kkj.exe
C:\WINDOWS\SYSTEM\Ije.exe
C:\WINDOWS\SYSTEM\Oud.exe
C:\WINDOWS\SYSTEM\Ikm.exe
C:\WINDOWS\Klc.exe
C:\WINDOWS\Abf.exe
C:\WINDOWS\SYSTEM\Ftn.exe
C:\WINDOWS\Ptt.exe
C:\WINDOWS\Vvf.exe
C:\WINDOWS\SYSTEM\Pcu.exe
C:\WINDOWS\Rbd.exe
C:\WINDOWS\Mjf.exe
C:\WINDOWS\Sem.exe
C:\WINDOWS\SYSTEM\Fva.exe
C:\WINDOWS\SYSTEM\Dst.exe
C:\WINDOWS\SYSTEM\Flu.exe
C:\WINDOWS\Klv.exe
C:\WINDOWS\SYSTEM\Mvk.exe
C:\WINDOWS\SYSTEM\Qee.exe
C:\WINDOWS\SYSTEM\Aon.exe
C:\WINDOWS\Ids.exe
C:\WINDOWS\Ggh.exe
C:\WINDOWS\Akg.exe
C:\WINDOWS\Gae.exe
C:\WINDOWS\SYSTEM\Gsv.exe
C:\WINDOWS\Akf.exe
C:\WINDOWS\Hpt.exe
C:\WINDOWS\SYSTEM\Oao.exe
C:\WINDOWS\Lvo.exe
C:\WINDOWS\SYSTEM\Ikb.exe
C:\WINDOWS\Srq.exe
C:\WINDOWS\SYSTEM\Bos.exe
C:\WINDOWS\Oku.exe
C:\WINDOWS\SYSTEM\Smj.exe
C:\WINDOWS\Epo.exe
C:\WINDOWS\SYSTEM\Jef.exe
C:\WINDOWS\Kti.exe
C:\WINDOWS\Uqa.exe
C:\WINDOWS\Ahc.exe
C:\WINDOWS\Jcd.exe
C:\WINDOWS\SYSTEM\Upo.exe
C:\WINDOWS\SYSTEM\Jls.exe
C:\WINDOWS\SYSTEM\Dai.exe


Reboot your computer to go back to normal mode and post a new log.

#3 frizzbee

frizzbee
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:00 PM

Posted 21 March 2005 - 03:24 PM

Grinler,

Thanks a million for the suggestion; I'll try it when I get back to my sick computer later tonight. In response to your question: I don't know what this is:

O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\SYSTEM\paytime.exe

However, a quick Google search suggests that paytime.exe is some sort of Malware. Is there any harm in just checking that and fixing it?

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:00 PM

Posted 21 March 2005 - 03:36 PM

nope..i wouldnt mind a copy though

#5 frizzbee

frizzbee
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:00 PM

Posted 28 March 2005 - 11:41 AM

Forgot to find out what paytime.exe was before I deleted it; sorry.

Also, after I did the fix, there was one line I could not get to delete:

O15 - Trusted IP range: 213.159.117.202 (HKLM)

I tried finding any file containing that text; I found it and accidentally opened it when I had hoped to just go in and edit it. That re-infected my computer with a bunch more stuff. So I re-ran HijackThis again, fixed everything that I could find that had re-appeared from the last time, and this is the resulting log, again with the troublesome last line still there:

Logfile of HijackThis v1.99.1
Scan saved at 5:17:00 PM, on 3/26/2005
Platform: Windows 95 B (Win9x 4.00.1111)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\VISUAL IP INSIGHT\TDS\ARUPLD32.EXE
C:\PROGRAM FILES\VISUAL IP INSIGHT\TDS\ARMON32A.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\PNPCHK.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\MOUSE\AMOUMAIN.EXE
C:\WINDOWS\SYSTEM\LOADWC.EXE
C:\WINDOWS\DCP.EXE
C:\WINDOWS\RunDLL.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>
F1 - win.ini: run=C:\WINDOWS\PNPCHK.EXE
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - (no file)
O2 - BHO: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Search Bar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [WheelMouse] C:\Program Files\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [BrowserWebCheck] loadwc.exe
O4 - HKLM\..\Run: [Tgb] C:\WINDOWS\Dcp.exe
O4 - HKLM\..\Run: [Hpn] C:\WINDOWS\SYSTEM\Qch.exe
O4 - HKLM\..\Run: [Qpi] C:\WINDOWS\Uir.exe
O4 - HKLM\..\Run: [Ntp] C:\WINDOWS\Kda.exe
O4 - HKLM\..\Run: [Eks] C:\WINDOWS\SYSTEM\Dqj.exe
O4 - HKLM\..\Run: [Ind] C:\WINDOWS\SYSTEM\Qih.exe
O4 - HKLM\..\Run: [Tuc] C:\WINDOWS\SYSTEM\Jqi.exe
O4 - HKLM\..\Run: [Qni] C:\WINDOWS\SYSTEM\Dns.exe
O4 - HKLM\..\Run: [Jvk] C:\WINDOWS\SYSTEM\Gmo.exe
O4 - HKLM\..\Run: [Kmc] C:\WINDOWS\Amq.exe
O4 - HKLM\..\Run: [Ulv] C:\WINDOWS\SYSTEM\Dsi.exe
O4 - HKLM\..\Run: [Sms] C:\WINDOWS\Iuq.exe
O4 - HKLM\..\Run: [Kqs] C:\WINDOWS\SYSTEM\Uaq.exe
O4 - HKLM\..\Run: [Hvs] C:\WINDOWS\Qba.exe
O4 - HKLM\..\Run: [Imv] C:\WINDOWS\Lse.exe
O4 - HKLM\..\Run: [Djv] C:\WINDOWS\Suc.exe
O4 - HKLM\..\Run: [Fdq] C:\WINDOWS\SYSTEM\Kbb.exe
O4 - HKLM\..\Run: [Var] C:\WINDOWS\SYSTEM\Adc.exe
O4 - HKLM\..\Run: [Jqi] C:\WINDOWS\SYSTEM\Hjs.exe
O4 - HKLM\..\Run: [Vbb] C:\WINDOWS\SYSTEM\Egi.exe
O4 - HKLM\..\Run: [Smj] C:\WINDOWS\SYSTEM\Qar.exe
O4 - HKLM\..\Run: [Anl] C:\WINDOWS\Rde.exe
O4 - HKLM\..\Run: [Jnd] C:\WINDOWS\SYSTEM\Ueu.exe
O4 - HKLM\..\Run: [Trh] C:\WINDOWS\SYSTEM\Mfg.exe
O4 - HKLM\..\Run: [Jgq] C:\WINDOWS\SYSTEM\Jqt.exe
O4 - HKLM\..\Run: [Khq] C:\WINDOWS\SYSTEM\Hhb.exe
O4 - HKLM\..\Run: [Pbo] C:\WINDOWS\SYSTEM\Hat.exe
O4 - HKLM\..\Run: [Bnv] C:\WINDOWS\SYSTEM\Chb.exe
O4 - HKLM\..\Run: [Rpv] C:\WINDOWS\SYSTEM\Mop.exe
O4 - HKLM\..\Run: [Trt] C:\WINDOWS\SYSTEM\Ugd.exe
O4 - HKLM\..\Run: [Gep] C:\WINDOWS\SYSTEM\Pva.exe
O4 - HKLM\..\Run: [Jkb] C:\WINDOWS\SYSTEM\Sbb.exe
O4 - HKLM\..\Run: [Mnk] C:\WINDOWS\Rlu.exe
O4 - HKLM\..\Run: [Gpj] C:\WINDOWS\SYSTEM\Bbu.exe
O4 - HKLM\..\Run: [Qhp] C:\WINDOWS\SYSTEM\Uep.exe
O4 - HKLM\..\Run: [Ndb] C:\WINDOWS\SYSTEM\Pso.exe
O4 - HKLM\..\Run: [Ofq] C:\WINDOWS\SYSTEM\Gvs.exe
O4 - HKLM\..\Run: [Pla] C:\WINDOWS\SYSTEM\Vds.exe
O4 - HKLM\..\Run: [Itn] C:\WINDOWS\SYSTEM\Maq.exe
O4 - HKLM\..\Run: [Cvo] C:\WINDOWS\Kel.exe
O4 - HKLM\..\Run: [Nnh] C:\WINDOWS\Oso.exe
O4 - HKLM\..\Run: [Idt] C:\WINDOWS\Odr.exe
O4 - HKLM\..\Run: [Kaa] C:\WINDOWS\Vrn.exe
O4 - HKLM\..\Run: [Vab] C:\WINDOWS\Qvi.exe
O4 - HKLM\..\Run: [Rbd] C:\WINDOWS\Mpq.exe
O4 - HKLM\..\Run: [Qqt] C:\WINDOWS\SYSTEM\Kuj.exe
O4 - HKLM\..\Run: [Guf] C:\WINDOWS\SYSTEM\Cpl.exe
O4 - HKLM\..\Run: [Klt] C:\WINDOWS\Mjm.exe
O4 - HKLM\..\Run: [Ion] C:\WINDOWS\Toi.exe
O4 - HKLM\..\Run: [Hku] C:\WINDOWS\SYSTEM\Mue.exe
O4 - HKLM\..\Run: [Bjs] C:\WINDOWS\SYSTEM\Ehq.exe
O4 - HKLM\..\Run: [Hpu] C:\WINDOWS\Hjm.exe
O4 - HKLM\..\Run: [Iit] C:\WINDOWS\Leo.exe
O4 - HKLM\..\Run: [Ihs] C:\WINDOWS\SYSTEM\Sqc.exe
O4 - HKLM\..\Run: [Ait] C:\WINDOWS\SYSTEM\Qia.exe
O4 - HKLM\..\Run: [Nfn] C:\WINDOWS\Eso.exe
O4 - HKLM\..\Run: [Qct] C:\WINDOWS\Lvo.exe
O4 - HKLM\..\Run: [Jql] C:\WINDOWS\Bhr.exe
O4 - HKLM\..\Run: [Nuh] C:\WINDOWS\SYSTEM\Ktq.exe
O4 - HKLM\..\Run: [Mcd] C:\WINDOWS\Vqi.exe
O4 - HKLM\..\Run: [Oif] C:\WINDOWS\SYSTEM\Fej.exe
O4 - HKLM\..\Run: [Rap] C:\WINDOWS\Tim.exe
O4 - HKLM\..\Run: [Fba] C:\WINDOWS\Itb.exe
O4 - HKLM\..\Run: [Sng] C:\WINDOWS\SYSTEM\Qjj.exe
O4 - HKLM\..\Run: [Rns] C:\WINDOWS\SYSTEM\Gll.exe
O4 - HKLM\..\Run: [Mga] C:\WINDOWS\SYSTEM\Fpl.exe
O4 - HKLM\..\Run: [Hso] C:\WINDOWS\Tgq.exe
O4 - HKLM\..\Run: [Ite] C:\WINDOWS\Uta.exe
O4 - HKLM\..\Run: [Nmh] C:\WINDOWS\SYSTEM\Nki.exe
O4 - HKLM\..\Run: [Dhn] C:\WINDOWS\Msk.exe
O4 - HKLM\..\Run: [Enp] C:\WINDOWS\SYSTEM\Nks.exe
O4 - HKLM\..\Run: [Lvp] C:\WINDOWS\SYSTEM\Ahd.exe
O4 - HKLM\..\Run: [Iho] C:\WINDOWS\Ftf.exe
O4 - HKLM\..\Run: [Btc] C:\WINDOWS\SYSTEM\Omt.exe
O4 - HKLM\..\Run: [Esj] C:\WINDOWS\Ehh.exe
O4 - HKLM\..\Run: [Cgi] C:\WINDOWS\SYSTEM\Nog.exe
O4 - HKLM\..\Run: [Plc] C:\WINDOWS\SYSTEM\Oeo.exe
O4 - HKLM\..\Run: [Mti] C:\WINDOWS\SYSTEM\Gpm.exe
O4 - HKLM\..\Run: [Thf] C:\WINDOWS\Oom.exe
O4 - HKLM\..\Run: [Eff] C:\WINDOWS\SYSTEM\Qeq.exe
O4 - HKLM\..\Run: [Pqc] C:\WINDOWS\Spk.exe
O4 - HKLM\..\Run: [Stg] C:\WINDOWS\Kbp.exe
O4 - HKLM\..\Run: [Vgh] C:\WINDOWS\SYSTEM\Mge.exe
O4 - HKLM\..\Run: [Aib] C:\WINDOWS\SYSTEM\Vvi.exe
O4 - HKLM\..\Run: [Iol] C:\WINDOWS\Edk.exe
O4 - HKLM\..\Run: [Iqr] C:\WINDOWS\Evv.exe
O4 - HKLM\..\Run: [Amm] C:\WINDOWS\SYSTEM\Fvu.exe
O4 - HKLM\..\Run: [Fro] C:\WINDOWS\SYSTEM\Mku.exe
O4 - HKLM\..\Run: [Lve] C:\WINDOWS\Ugb.exe
O4 - HKLM\..\Run: [Kgs] C:\WINDOWS\Kln.exe
O4 - HKLM\..\Run: [Bqg] C:\WINDOWS\Sif.exe
O4 - HKLM\..\Run: [Mvh] C:\WINDOWS\Vbp.exe
O4 - HKLM\..\Run: [Ejg] C:\WINDOWS\SYSTEM\Cav.exe
O4 - HKLM\..\Run: [Lka] C:\WINDOWS\Erg.exe
O4 - HKLM\..\Run: [Jff] C:\WINDOWS\SYSTEM\Uvr.exe
O4 - HKLM\..\Run: [Okt] C:\WINDOWS\SYSTEM\Hue.exe
O4 - HKLM\..\Run: [Mnv] C:\WINDOWS\Eqn.exe
O4 - HKLM\..\Run: [Ser] C:\WINDOWS\Ork.exe
O4 - HKLM\..\Run: [Mie] C:\WINDOWS\SYSTEM\Bvj.exe
O4 - HKLM\..\Run: [Esg] C:\WINDOWS\SYSTEM\Tcc.exe
O4 - HKLM\..\Run: [Rib] C:\WINDOWS\Chc.exe
O4 - HKLM\..\Run: [Vjl] C:\WINDOWS\SYSTEM\Gek.exe
O4 - HKLM\..\Run: [Nvu] C:\WINDOWS\SYSTEM\Crh.exe
O4 - HKLM\..\Run: [Hek] C:\WINDOWS\SYSTEM\Eci.exe
O4 - HKLM\..\Run: [Tci] C:\WINDOWS\Djh.exe
O4 - HKLM\..\Run: [Ean] C:\WINDOWS\Qao.exe
O4 - HKLM\..\Run: [Adg] C:\WINDOWS\SYSTEM\Fje.exe
O4 - HKLM\..\Run: [Fur] C:\WINDOWS\Cai.exe
O4 - HKLM\..\Run: [Rtq] C:\WINDOWS\Cqe.exe
O4 - HKLM\..\Run: [Ksg] C:\WINDOWS\Iuj.exe
O4 - HKLM\..\Run: [Gdq] C:\WINDOWS\SYSTEM\Gdr.exe
O4 - HKLM\..\Run: [Pno] C:\WINDOWS\SYSTEM\Nel.exe
O4 - HKLM\..\Run: [Hpo] C:\WINDOWS\SYSTEM\Lki.exe
O4 - HKLM\..\Run: [Qrl] C:\WINDOWS\Fud.exe
O4 - HKLM\..\Run: [Bhf] C:\WINDOWS\Hlh.exe
O4 - HKLM\..\Run: [Kth] C:\WINDOWS\Ebg.exe
O4 - HKLM\..\Run: [Gtj] C:\WINDOWS\SYSTEM\Plj.exe
O4 - HKLM\..\Run: [Usp] C:\WINDOWS\SYSTEM\Blu.exe
O4 - HKLM\..\Run: [Ouf] C:\WINDOWS\Vtj.exe
O4 - HKLM\..\Run: [Hpc] C:\WINDOWS\Svk.exe
O4 - HKLM\..\Run: [Fua] C:\WINDOWS\Mni.exe
O4 - HKLM\..\Run: [Vjp] C:\WINDOWS\SYSTEM\Dbr.exe
O4 - HKLM\..\Run: [Kdr] C:\WINDOWS\Hkq.exe
O4 - HKLM\..\Run: [Fmq] C:\WINDOWS\Cmo.exe
O4 - HKLM\..\Run: [Lid] C:\WINDOWS\Eel.exe
O4 - HKLM\..\Run: [Lsf] C:\WINDOWS\Ukk.exe
O4 - HKLM\..\Run: [Vfq] C:\WINDOWS\Jbf.exe
O4 - HKLM\..\Run: [Sjq] C:\WINDOWS\SYSTEM\Afn.exe
O4 - HKLM\..\Run: [Vfr] C:\WINDOWS\Mjb.exe
O4 - HKLM\..\Run: [Mme] C:\WINDOWS\Pdf.exe
O4 - HKLM\..\Run: [Ujq] C:\WINDOWS\SYSTEM\Qfv.exe
O4 - HKLM\..\Run: [Unj] C:\WINDOWS\Sim.exe
O4 - HKLM\..\Run: [Lrk] C:\WINDOWS\Rqq.exe
O4 - HKLM\..\Run: [Gjv] C:\WINDOWS\Qvn.exe
O4 - HKLM\..\Run: [Ujp] C:\WINDOWS\Aqo.exe
O4 - HKLM\..\Run: [Riq] C:\WINDOWS\Vrq.exe
O4 - HKLM\..\Run: [Oop] C:\WINDOWS\Mei.exe
O4 - HKLM\..\Run: [Ivf] C:\WINDOWS\Tmk.exe
O4 - HKLM\..\Run: [Mdj] C:\WINDOWS\SYSTEM\Lho.exe
O4 - HKLM\..\Run: [Fbk] C:\WINDOWS\SYSTEM\Ltg.exe
O4 - HKLM\..\Run: [Bah] C:\WINDOWS\SYSTEM\Lrr.exe
O4 - HKLM\..\Run: [Don] C:\WINDOWS\Dog.exe
O4 - HKLM\..\Run: [Loe] C:\WINDOWS\SYSTEM\Kki.exe
O4 - HKLM\..\Run: [Lje] C:\WINDOWS\Knd.exe
O4 - HKLM\..\Run: [Dpr] C:\WINDOWS\SYSTEM\Hpv.exe
O4 - HKLM\..\Run: [Usd] C:\WINDOWS\SYSTEM\Ctv.exe
O4 - HKLM\..\Run: [Crp] C:\WINDOWS\SYSTEM\Dcl.exe
O4 - HKLM\..\Run: [Pdg] C:\WINDOWS\SYSTEM\Akm.exe
O4 - HKLM\..\Run: [Muo] C:\WINDOWS\Nis.exe
O4 - HKLM\..\Run: [Uqd] C:\WINDOWS\Mif.exe
O4 - HKLM\..\Run: [Boe] C:\WINDOWS\SYSTEM\Khn.exe
O4 - HKLM\..\Run: [Mhr] C:\WINDOWS\SYSTEM\Ofg.exe
O4 - HKLM\..\Run: [Eov] C:\WINDOWS\Bpo.exe
O4 - HKLM\..\Run: [Lgg] C:\WINDOWS\SYSTEM\Kbp.exe
O4 - HKLM\..\Run: [Umc] C:\WINDOWS\SYSTEM\Obv.exe
O4 - HKLM\..\Run: [Fre] C:\WINDOWS\SYSTEM\Kjj.exe
O4 - HKLM\..\Run: [Qba] C:\WINDOWS\Dml.exe
O4 - HKLM\..\Run: [Mjt] C:\WINDOWS\SYSTEM\Hkm.exe
O4 - HKLM\..\Run: [Icg] C:\WINDOWS\Gvl.exe
O4 - HKLM\..\Run: [Tts] C:\WINDOWS\SYSTEM\Ibj.exe
O4 - HKLM\..\Run: [Nfj] C:\WINDOWS\Our.exe
O4 - HKLM\..\Run: [Mpm] C:\WINDOWS\Ern.exe
O4 - HKLM\..\Run: [Fvo] C:\WINDOWS\Mfh.exe
O4 - HKLM\..\Run: [Nsu] C:\WINDOWS\SYSTEM\Ave.exe
O4 - HKLM\..\Run: [Luc] C:\WINDOWS\SYSTEM\Vfe.exe
O4 - HKLM\..\Run: [Jdf] C:\WINDOWS\Uhu.exe
O4 - HKLM\..\Run: [Ksj] C:\WINDOWS\Ofs.exe
O4 - HKLM\..\Run: [Qft] C:\WINDOWS\SYSTEM\Sfk.exe
O4 - HKLM\..\Run: [Jko] C:\WINDOWS\SYSTEM\Tav.exe
O4 - HKLM\..\Run: [Jdk] C:\WINDOWS\SYSTEM\Ufq.exe
O4 - HKLM\..\Run: [Jcl] C:\WINDOWS\SYSTEM\Lfc.exe
O4 - HKLM\..\Run: [Slm] C:\WINDOWS\SYSTEM\Rdf.exe
O4 - HKLM\..\Run: [Lra] C:\WINDOWS\SYSTEM\Abc.exe
O4 - HKLM\..\Run: [Nkf] C:\WINDOWS\SYSTEM\Lfu.exe
O4 - HKLM\..\Run: [Lrp] C:\WINDOWS\SYSTEM\Pba.exe
O4 - HKLM\..\Run: [Bgr] C:\WINDOWS\SYSTEM\Rhl.exe
O4 - HKLM\..\Run: [Ahm] C:\WINDOWS\SYSTEM\Vvh.exe
O4 - HKLM\..\Run: [Job] C:\WINDOWS\Jfq.exe
O4 - HKLM\..\Run: [Pgk] C:\WINDOWS\SYSTEM\Pqf.exe
O4 - HKLM\..\Run: [Koj] C:\WINDOWS\Svh.exe
O4 - HKLM\..\Run: [Oni] C:\WINDOWS\Vbr.exe
O4 - HKLM\..\Run: [Ljk] C:\WINDOWS\Dfb.exe
O4 - HKLM\..\Run: [Dal] C:\WINDOWS\SYSTEM\Vhk.exe
O4 - HKLM\..\Run: [Efh] C:\WINDOWS\Qln.exe
O4 - HKLM\..\Run: [Rrd] C:\WINDOWS\Kgu.exe
O4 - HKLM\..\Run: [Aqt] C:\WINDOWS\SYSTEM\Qif.exe
O4 - HKLM\..\Run: [Nul] C:\WINDOWS\SYSTEM\Iqc.exe
O4 - HKLM\..\Run: [Uvf] C:\WINDOWS\SYSTEM\Gvi.exe
O4 - HKLM\..\Run: [Djm] C:\WINDOWS\SYSTEM\Fbb.exe
O4 - HKLM\..\Run: [Uac] C:\WINDOWS\SYSTEM\Iel.exe
O4 - HKLM\..\Run: [Aep] C:\WINDOWS\SYSTEM\Rnd.exe
O4 - HKLM\..\Run: [Hvo] C:\WINDOWS\SYSTEM\Qqg.exe
O4 - HKLM\..\Run: [Eef] C:\WINDOWS\Ged.exe
O4 - HKLM\..\Run: [Cfa] C:\WINDOWS\Vuc.exe
O4 - HKLM\..\Run: [Oit] C:\WINDOWS\Niq.exe
O4 - HKLM\..\Run: [Tli] C:\WINDOWS\SYSTEM\Cdj.exe
O4 - HKLM\..\Run: [Vnb] C:\WINDOWS\Bor.exe
O4 - HKLM\..\Run: [Dih] C:\WINDOWS\SYSTEM\Uuc.exe
O4 - HKLM\..\Run: [Tob] C:\WINDOWS\Rdh.exe
O4 - HKLM\..\Run: [Uqh] C:\WINDOWS\SYSTEM\Vab.exe
O4 - HKLM\..\Run: [Lcj] C:\WINDOWS\Vej.exe
O4 - HKLM\..\Run: [Prk] C:\WINDOWS\SYSTEM\Tkv.exe
O4 - HKLM\..\Run: [Tbd] C:\WINDOWS\SYSTEM\Huo.exe
O4 - HKLM\..\Run: [Llo] C:\WINDOWS\Hpt.exe
O4 - HKLM\..\Run: [Bil] C:\WINDOWS\SYSTEM\Val.exe
O4 - HKLM\..\Run: [Apn] C:\WINDOWS\Lfl.exe
O4 - HKLM\..\Run: [Bqu] C:\WINDOWS\Drd.exe
O4 - HKLM\..\Run: [Att] C:\WINDOWS\Msl.exe
O4 - HKLM\..\Run: [Kkr] C:\WINDOWS\SYSTEM\Shp.exe
O4 - HKLM\..\Run: [Acr] C:\WINDOWS\SYSTEM\Fcj.exe
O4 - HKLM\..\Run: [Pku] C:\WINDOWS\SYSTEM\Aqm.exe
O4 - HKLM\..\Run: [Meb] C:\WINDOWS\Iau.exe
O4 - HKLM\..\Run: [Tgo] C:\WINDOWS\SYSTEM\Kbj.exe
O4 - HKLM\..\Run: [Gkt] C:\WINDOWS\Ptk.exe
O4 - HKLM\..\Run: [Gpf] C:\WINDOWS\SYSTEM\Fvd.exe
O4 - HKLM\..\Run: [Jri] C:\WINDOWS\Thq.exe
O4 - HKLM\..\Run: [Trv] C:\WINDOWS\Sfj.exe
O4 - HKLM\..\Run: [Aks] C:\WINDOWS\Met.exe
O4 - HKLM\..\Run: [Iju] C:\WINDOWS\SYSTEM\Krj.exe
O4 - HKLM\..\Run: [Hmt] C:\WINDOWS\Igq.exe
O4 - HKLM\..\Run: [Tlq] C:\WINDOWS\Ugu.exe
O4 - HKLM\..\Run: [Aag] C:\WINDOWS\Kjb.exe
O4 - HKLM\..\Run: [Oog] C:\WINDOWS\SYSTEM\Jne.exe
O4 - HKLM\..\Run: [Roc] C:\WINDOWS\Neu.exe
O4 - HKLM\..\Run: [Kbr] C:\WINDOWS\Dbu.exe
O4 - HKLM\..\Run: [Aoj] C:\WINDOWS\SYSTEM\Pqp.exe
O4 - HKLM\..\Run: [Gsu] C:\WINDOWS\Moo.exe
O4 - HKLM\..\Run: [Dms] C:\WINDOWS\SYSTEM\Num.exe
O4 - HKLM\..\Run: [Bdv] C:\WINDOWS\Knt.exe
O4 - HKLM\..\Run: [Fcr] C:\WINDOWS\Ear.exe
O4 - HKLM\..\Run: [Nve] C:\WINDOWS\SYSTEM\Bhp.exe
O4 - HKLM\..\Run: [Oar] C:\WINDOWS\SYSTEM\Lvq.exe
O4 - HKLM\..\Run: [Vkh] C:\WINDOWS\SYSTEM\Chu.exe
O4 - HKLM\..\Run: [Fga] C:\WINDOWS\Pap.exe
O4 - HKLM\..\Run: [Ggd] C:\WINDOWS\Avp.exe
O4 - HKLM\..\Run: [Dqq] C:\WINDOWS\Qtg.exe
O4 - HKLM\..\Run: [Ddv] C:\WINDOWS\Tpi.exe
O4 - HKLM\..\Run: [Cjl] C:\WINDOWS\SYSTEM\Thv.exe
O4 - HKLM\..\Run: [Eta] C:\WINDOWS\Mnl.exe
O4 - HKLM\..\Run: [Jln] C:\WINDOWS\Mmj.exe
O4 - HKLM\..\Run: [Gfa] C:\WINDOWS\Hoo.exe
O4 - HKLM\..\Run: [Uet] C:\WINDOWS\SYSTEM\Ima.exe
O4 - HKLM\..\Run: [Ehs] C:\WINDOWS\SYSTEM\Nch.exe
O4 - HKLM\..\Run: [Esr] C:\WINDOWS\Tfj.exe
O4 - HKLM\..\Run: [Gqv] C:\WINDOWS\SYSTEM\Vru.exe
O4 - HKLM\..\Run: [Bvb] C:\WINDOWS\Ocd.exe
O4 - HKLM\..\RunServices: [AccessRampLAN 01] "C:\PROGRAM FILES\VISUAL IP INSIGHT\TDS\ARUpld32.exe" -l
O4 - HKLM\..\RunServices: [AccessRampMonitor 01] "C:\PROGRAM FILES\VISUAL IP INSIGHT\TDS\ARMon32a.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Tgb] C:\WINDOWS\Dcp.exe
O4 - HKCU\..\Run: [Hpn] C:\WINDOWS\SYSTEM\Qch.exe
O4 - HKCU\..\Run: [Qpi] C:\WINDOWS\Uir.exe
O4 - HKCU\..\Run: [Ntp] C:\WINDOWS\Kda.exe
O4 - HKCU\..\Run: [Eks] C:\WINDOWS\SYSTEM\Dqj.exe
O4 - HKCU\..\Run: [Ind] C:\WINDOWS\SYSTEM\Qih.exe
O4 - HKCU\..\Run: [Tuc] C:\WINDOWS\SYSTEM\Jqi.exe
O4 - HKCU\..\Run: [Qni] C:\WINDOWS\SYSTEM\Dns.exe
O4 - HKCU\..\Run: [Jvk] C:\WINDOWS\SYSTEM\Gmo.exe
O4 - HKCU\..\Run: [Kmc] C:\WINDOWS\Amq.exe
O4 - HKCU\..\Run: [Ulv] C:\WINDOWS\SYSTEM\Dsi.exe
O4 - HKCU\..\Run: [Sms] C:\WINDOWS\Iuq.exe
O4 - HKCU\..\Run: [Kqs] C:\WINDOWS\SYSTEM\Uaq.exe
O4 - HKCU\..\Run: [Hvs] C:\WINDOWS\Qba.exe
O4 - HKCU\..\Run: [Imv] C:\WINDOWS\Lse.exe
O4 - HKCU\..\Run: [Djv] C:\WINDOWS\Suc.exe
O4 - HKCU\..\Run: [Fdq] C:\WINDOWS\SYSTEM\Kbb.exe
O4 - HKCU\..\Run: [Var] C:\WINDOWS\SYSTEM\Adc.exe
O4 - HKCU\..\Run: [Jqi] C:\WINDOWS\SYSTEM\Hjs.exe
O4 - HKCU\..\Run: [Vbb] C:\WINDOWS\SYSTEM\Egi.exe
O4 - HKCU\..\Run: [Smj] C:\WINDOWS\SYSTEM\Qar.exe
O4 - HKCU\..\Run: [Anl] C:\WINDOWS\Rde.exe
O4 - HKCU\..\Run: [Jnd] C:\WINDOWS\SYSTEM\Ueu.exe
O4 - HKCU\..\Run: [Trh] C:\WINDOWS\SYSTEM\Mfg.exe
O4 - HKCU\..\Run: [Jgq] C:\WINDOWS\SYSTEM\Jqt.exe
O4 - HKCU\..\Run: [Khq] C:\WINDOWS\SYSTEM\Hhb.exe
O4 - HKCU\..\Run: [Pbo] C:\WINDOWS\SYSTEM\Hat.exe
O4 - HKCU\..\Run: [Bnv] C:\WINDOWS\SYSTEM\Chb.exe
O4 - HKCU\..\Run: [Rpv] C:\WINDOWS\SYSTEM\Mop.exe
O4 - HKCU\..\Run: [Trt] C:\WINDOWS\SYSTEM\Ugd.exe
O4 - HKCU\..\Run: [Gep] C:\WINDOWS\SYSTEM\Pva.exe
O4 - HKCU\..\Run: [Jkb] C:\WINDOWS\SYSTEM\Sbb.exe
O4 - HKCU\..\Run: [Mnk] C:\WINDOWS\Rlu.exe
O4 - HKCU\..\Run: [Gpj] C:\WINDOWS\SYSTEM\Bbu.exe
O4 - HKCU\..\Run: [Qhp] C:\WINDOWS\SYSTEM\Uep.exe
O4 - HKCU\..\Run: [Ndb] C:\WINDOWS\SYSTEM\Pso.exe
O4 - HKCU\..\Run: [Ofq] C:\WINDOWS\SYSTEM\Gvs.exe
O4 - HKCU\..\Run: [Pla] C:\WINDOWS\SYSTEM\Vds.exe
O4 - HKCU\..\Run: [Itn] C:\WINDOWS\SYSTEM\Maq.exe
O4 - HKCU\..\Run: [Cvo] C:\WINDOWS\Kel.exe
O4 - HKCU\..\Run: [Nnh] C:\WINDOWS\Oso.exe
O4 - HKCU\..\Run: [Idt] C:\WINDOWS\Odr.exe
O4 - HKCU\..\Run: [Kaa] C:\WINDOWS\Vrn.exe
O4 - HKCU\..\Run: [Vab] C:\WINDOWS\Qvi.exe
O4 - HKCU\..\Run: [Rbd] C:\WINDOWS\Mpq.exe
O4 - HKCU\..\Run: [Qqt] C:\WINDOWS\SYSTEM\Kuj.exe
O4 - HKCU\..\Run: [Guf] C:\WINDOWS\SYSTEM\Cpl.exe
O4 - HKCU\..\Run: [Klt] C:\WINDOWS\Mjm.exe
O4 - HKCU\..\Run: [Ion] C:\WINDOWS\Toi.exe
O4 - HKCU\..\Run: [Hku] C:\WINDOWS\SYSTEM\Mue.exe
O4 - HKCU\..\Run: [Bjs] C:\WINDOWS\SYSTEM\Ehq.exe
O4 - HKCU\..\Run: [Hpu] C:\WINDOWS\Hjm.exe
O4 - HKCU\..\Run: [Iit] C:\WINDOWS\Leo.exe
O4 - HKCU\..\Run: [Ihs] C:\WINDOWS\SYSTEM\Sqc.exe
O4 - HKCU\..\Run: [Ait] C:\WINDOWS\SYSTEM\Qia.exe
O4 - HKCU\..\Run: [Nfn] C:\WINDOWS\Eso.exe
O4 - HKCU\..\Run: [Qct] C:\WINDOWS\Lvo.exe
O4 - HKCU\..\Run: [Jql] C:\WINDOWS\Bhr.exe
O4 - HKCU\..\Run: [Nuh] C:\WINDOWS\SYSTEM\Ktq.exe
O4 - HKCU\..\Run: [Mcd] C:\WINDOWS\Vqi.exe
O4 - HKCU\..\Run: [Oif] C:\WINDOWS\SYSTEM\Fej.exe
O4 - HKCU\..\Run: [Rap] C:\WINDOWS\Tim.exe
O4 - HKCU\..\Run: [Fba] C:\WINDOWS\Itb.exe
O4 - HKCU\..\Run: [Sng] C:\WINDOWS\SYSTEM\Qjj.exe
O4 - HKCU\..\Run: [Rns] C:\WINDOWS\SYSTEM\Gll.exe
O4 - HKCU\..\Run: [Mga] C:\WINDOWS\SYSTEM\Fpl.exe
O4 - HKCU\..\Run: [Hso] C:\WINDOWS\Tgq.exe
O4 - HKCU\..\Run: [Ite] C:\WINDOWS\Uta.exe
O4 - HKCU\..\Run: [Nmh] C:\WINDOWS\SYSTEM\Nki.exe
O4 - HKCU\..\Run: [Dhn] C:\WINDOWS\Msk.exe
O4 - HKCU\..\Run: [Enp] C:\WINDOWS\SYSTEM\Nks.exe
O4 - HKCU\..\Run: [Lvp] C:\WINDOWS\SYSTEM\Ahd.exe
O4 - HKCU\..\Run: [Iho] C:\WINDOWS\Ftf.exe
O4 - HKCU\..\Run: [Btc] C:\WINDOWS\SYSTEM\Omt.exe
O4 - HKCU\..\Run: [Esj] C:\WINDOWS\Ehh.exe
O4 - HKCU\..\Run: [Cgi] C:\WINDOWS\SYSTEM\Nog.exe
O4 - HKCU\..\Run: [Plc] C:\WINDOWS\SYSTEM\Oeo.exe
O4 - HKCU\..\Run: [Mti] C:\WINDOWS\SYSTEM\Gpm.exe
O4 - HKCU\..\Run: [Thf] C:\WINDOWS\Oom.exe
O4 - HKCU\..\Run: [Eff] C:\WINDOWS\SYSTEM\Qeq.exe
O4 - HKCU\..\Run: [Pqc] C:\WINDOWS\Spk.exe
O4 - HKCU\..\Run: [Stg] C:\WINDOWS\Kbp.exe
O4 - HKCU\..\Run: [Vgh] C:\WINDOWS\SYSTEM\Mge.exe
O4 - HKCU\..\Run: [Aib] C:\WINDOWS\SYSTEM\Vvi.exe
O4 - HKCU\..\Run: [Iol] C:\WINDOWS\Edk.exe
O4 - HKCU\..\Run: [Iqr] C:\WINDOWS\Evv.exe
O4 - HKCU\..\Run: [Amm] C:\WINDOWS\SYSTEM\Fvu.exe
O4 - HKCU\..\Run: [Fro] C:\WINDOWS\SYSTEM\Mku.exe
O4 - HKCU\..\Run: [Lve] C:\WINDOWS\Ugb.exe
O4 - HKCU\..\Run: [Kgs] C:\WINDOWS\Kln.exe
O4 - HKCU\..\Run: [Bqg] C:\WINDOWS\Sif.exe
O4 - HKCU\..\Run: [Mvh] C:\WINDOWS\Vbp.exe
O4 - HKCU\..\Run: [Ejg] C:\WINDOWS\SYSTEM\Cav.exe
O4 - HKCU\..\Run: [Lka] C:\WINDOWS\Erg.exe
O4 - HKCU\..\Run: [Jff] C:\WINDOWS\SYSTEM\Uvr.exe
O4 - HKCU\..\Run: [Okt] C:\WINDOWS\SYSTEM\Hue.exe
O4 - HKCU\..\Run: [Mnv] C:\WINDOWS\Eqn.exe
O4 - HKCU\..\Run: [Ser] C:\WINDOWS\Ork.exe
O4 - HKCU\..\Run: [Mie] C:\WINDOWS\SYSTEM\Bvj.exe
O4 - HKCU\..\Run: [Esg] C:\WINDOWS\SYSTEM\Tcc.exe
O4 - HKCU\..\Run: [Rib] C:\WINDOWS\Chc.exe
O4 - HKCU\..\Run: [Vjl] C:\WINDOWS\SYSTEM\Gek.exe
O4 - HKCU\..\Run: [Nvu] C:\WINDOWS\SYSTEM\Crh.exe
O4 - HKCU\..\Run: [Hek] C:\WINDOWS\SYSTEM\Eci.exe
O4 - HKCU\..\Run: [Tci] C:\WINDOWS\Djh.exe
O4 - HKCU\..\Run: [Ean] C:\WINDOWS\Qao.exe
O4 - HKCU\..\Run: [Adg] C:\WINDOWS\SYSTEM\Fje.exe
O4 - HKCU\..\Run: [Fur] C:\WINDOWS\Cai.exe
O4 - HKCU\..\Run: [Rtq] C:\WINDOWS\Cqe.exe
O4 - HKCU\..\Run: [Ksg] C:\WINDOWS\Iuj.exe
O4 - HKCU\..\Run: [Gdq] C:\WINDOWS\SYSTEM\Gdr.exe
O4 - HKCU\..\Run: [Pno] C:\WINDOWS\SYSTEM\Nel.exe
O4 - HKCU\..\Run: [Hpo] C:\WINDOWS\SYSTEM\Lki.exe
O4 - HKCU\..\Run: [Qrl] C:\WINDOWS\Fud.exe
O4 - HKCU\..\Run: [Bhf] C:\WINDOWS\Hlh.exe
O4 - HKCU\..\Run: [Kth] C:\WINDOWS\Ebg.exe
O4 - HKCU\..\Run: [Gtj] C:\WINDOWS\SYSTEM\Plj.exe
O4 - HKCU\..\Run: [Usp] C:\WINDOWS\SYSTEM\Blu.exe
O4 - HKCU\..\Run: [Ouf] C:\WINDOWS\Vtj.exe
O4 - HKCU\..\Run: [Hpc] C:\WINDOWS\Svk.exe
O4 - HKCU\..\Run: [Fua] C:\WINDOWS\Mni.exe
O4 - HKCU\..\Run: [Vjp] C:\WINDOWS\SYSTEM\Dbr.exe
O4 - HKCU\..\Run: [Kdr] C:\WINDOWS\Hkq.exe
O4 - HKCU\..\Run: [Fmq] C:\WINDOWS\Cmo.exe
O4 - HKCU\..\Run: [Lid] C:\WINDOWS\Eel.exe
O4 - HKCU\..\Run: [Lsf] C:\WINDOWS\Ukk.exe
O4 - HKCU\..\Run: [Vfq] C:\WINDOWS\Jbf.exe
O4 - HKCU\..\Run: [Sjq] C:\WINDOWS\SYSTEM\Afn.exe
O4 - HKCU\..\Run: [Vfr] C:\WINDOWS\Mjb.exe
O4 - HKCU\..\Run: [Mme] C:\WINDOWS\Pdf.exe
O4 - HKCU\..\Run: [Ujq] C:\WINDOWS\SYSTEM\Qfv.exe
O4 - HKCU\..\Run: [Unj] C:\WINDOWS\Sim.exe
O4 - HKCU\..\Run: [Lrk] C:\WINDOWS\Rqq.exe
O4 - HKCU\..\Run: [Gjv] C:\WINDOWS\Qvn.exe
O4 - HKCU\..\Run: [Ujp] C:\WINDOWS\Aqo.exe
O4 - HKCU\..\Run: [Riq] C:\WINDOWS\Vrq.exe
O4 - HKCU\..\Run: [Oop] C:\WINDOWS\Mei.exe
O4 - HKCU\..\Run: [Ivf] C:\WINDOWS\Tmk.exe
O4 - HKCU\..\Run: [Mdj] C:\WINDOWS\SYSTEM\Lho.exe
O4 - HKCU\..\Run: [Fbk] C:\WINDOWS\SYSTEM\Ltg.exe
O4 - HKCU\..\Run: [Bah] C:\WINDOWS\SYSTEM\Lrr.exe
O4 - HKCU\..\Run: [Don] C:\WINDOWS\Dog.exe
O4 - HKCU\..\Run: [Loe] C:\WINDOWS\SYSTEM\Kki.exe
O4 - HKCU\..\Run: [Lje] C:\WINDOWS\Knd.exe
O4 - HKCU\..\Run: [Dpr] C:\WINDOWS\SYSTEM\Hpv.exe
O4 - HKCU\..\Run: [Usd] C:\WINDOWS\SYSTEM\Ctv.exe
O4 - HKCU\..\Run: [Crp] C:\WINDOWS\SYSTEM\Dcl.exe
O4 - HKCU\..\Run: [Pdg] C:\WINDOWS\SYSTEM\Akm.exe
O4 - HKCU\..\Run: [Muo] C:\WINDOWS\Nis.exe
O4 - HKCU\..\Run: [Uqd] C:\WINDOWS\Mif.exe
O4 - HKCU\..\Run: [Boe] C:\WINDOWS\SYSTEM\Khn.exe
O4 - HKCU\..\Run: [Mhr] C:\WINDOWS\SYSTEM\Ofg.exe
O4 - HKCU\..\Run: [Eov] C:\WINDOWS\Bpo.exe
O4 - HKCU\..\Run: [Lgg] C:\WINDOWS\SYSTEM\Kbp.exe
O4 - HKCU\..\Run: [Umc] C:\WINDOWS\SYSTEM\Obv.exe
O4 - HKCU\..\Run: [Fre] C:\WINDOWS\SYSTEM\Kjj.exe
O4 - HKCU\..\Run: [Qba] C:\WINDOWS\Dml.exe
O4 - HKCU\..\Run: [Mjt] C:\WINDOWS\SYSTEM\Hkm.exe
O4 - HKCU\..\Run: [Icg] C:\WINDOWS\Gvl.exe
O4 - HKCU\..\Run: [Tts] C:\WINDOWS\SYSTEM\Ibj.exe
O4 - HKCU\..\Run: [Nfj] C:\WINDOWS\Our.exe
O4 - HKCU\..\Run: [Mpm] C:\WINDOWS\Ern.exe
O4 - HKCU\..\Run: [Fvo] C:\WINDOWS\Mfh.exe
O4 - HKCU\..\Run: [Nsu] C:\WINDOWS\SYSTEM\Ave.exe
O4 - HKCU\..\Run: [Luc] C:\WINDOWS\SYSTEM\Vfe.exe
O4 - HKCU\..\Run: [Jdf] C:\WINDOWS\Uhu.exe
O4 - HKCU\..\Run: [Ksj] C:\WINDOWS\Ofs.exe
O4 - HKCU\..\Run: [Qft] C:\WINDOWS\SYSTEM\Sfk.exe
O4 - HKCU\..\Run: [Jko] C:\WINDOWS\SYSTEM\Tav.exe
O4 - HKCU\..\Run: [Jdk] C:\WINDOWS\SYSTEM\Ufq.exe
O4 - HKCU\..\Run: [Jcl] C:\WINDOWS\SYSTEM\Lfc.exe
O4 - HKCU\..\Run: [Slm] C:\WINDOWS\SYSTEM\Rdf.exe
O4 - HKCU\..\Run: [Lra] C:\WINDOWS\SYSTEM\Abc.exe
O4 - HKCU\..\Run: [Nkf] C:\WINDOWS\SYSTEM\Lfu.exe
O4 - HKCU\..\Run: [Lrp] C:\WINDOWS\SYSTEM\Pba.exe
O4 - HKCU\..\Run: [Bgr] C:\WINDOWS\SYSTEM\Rhl.exe
O4 - HKCU\..\Run: [Ahm] C:\WINDOWS\SYSTEM\Vvh.exe
O4 - HKCU\..\Run: [Job] C:\WINDOWS\Jfq.exe
O4 - HKCU\..\Run: [Pgk] C:\WINDOWS\SYSTEM\Pqf.exe
O4 - HKCU\..\Run: [Koj] C:\WINDOWS\Svh.exe
O4 - HKCU\..\Run: [Oni] C:\WINDOWS\Vbr.exe
O4 - HKCU\..\Run: [Ljk] C:\WINDOWS\Dfb.exe
O4 - HKCU\..\Run: [Dal] C:\WINDOWS\SYSTEM\Vhk.exe
O4 - HKCU\..\Run: [Efh] C:\WINDOWS\Qln.exe
O4 - HKCU\..\Run: [Rrd] C:\WINDOWS\Kgu.exe
O4 - HKCU\..\Run: [Aqt] C:\WINDOWS\SYSTEM\Qif.exe
O4 - HKCU\..\Run: [Nul] C:\WINDOWS\SYSTEM\Iqc.exe
O4 - HKCU\..\Run: [Uvf] C:\WINDOWS\SYSTEM\Gvi.exe
O4 - HKCU\..\Run: [Djm] C:\WINDOWS\SYSTEM\Fbb.exe
O4 - HKCU\..\Run: [Uac] C:\WINDOWS\SYSTEM\Iel.exe
O4 - HKCU\..\Run: [Aep] C:\WINDOWS\SYSTEM\Rnd.exe
O4 - HKCU\..\Run: [Hvo] C:\WINDOWS\SYSTEM\Qqg.exe
O4 - HKCU\..\Run: [Eef] C:\WINDOWS\Ged.exe
O4 - HKCU\..\Run: [Cfa] C:\WINDOWS\Vuc.exe
O4 - HKCU\..\Run: [Oit] C:\WINDOWS\Niq.exe
O4 - HKCU\..\Run: [Tli] C:\WINDOWS\SYSTEM\Cdj.exe
O4 - HKCU\..\Run: [Vnb] C:\WINDOWS\Bor.exe
O4 - HKCU\..\Run: [Dih] C:\WINDOWS\SYSTEM\Uuc.exe
O4 - HKCU\..\Run: [Tob] C:\WINDOWS\Rdh.exe
O4 - HKCU\..\Run: [Uqh] C:\WINDOWS\SYSTEM\Vab.exe
O4 - HKCU\..\Run: [Lcj] C:\WINDOWS\Vej.exe
O4 - HKCU\..\Run: [Prk] C:\WINDOWS\SYSTEM\Tkv.exe
O4 - HKCU\..\Run: [Tbd] C:\WINDOWS\SYSTEM\Huo.exe
O4 - HKCU\..\Run: [Llo] C:\WINDOWS\Hpt.exe
O4 - HKCU\..\Run: [Bil] C:\WINDOWS\SYSTEM\Val.exe
O4 - HKCU\..\Run: [Apn] C:\WINDOWS\Lfl.exe
O4 - HKCU\..\Run: [Bqu] C:\WINDOWS\Drd.exe
O4 - HKCU\..\Run: [Att] C:\WINDOWS\Msl.exe
O4 - HKCU\..\Run: [Kkr] C:\WINDOWS\SYSTEM\Shp.exe
O4 - HKCU\..\Run: [Acr] C:\WINDOWS\SYSTEM\Fcj.exe
O4 - HKCU\..\Run: [Pku] C:\WINDOWS\SYSTEM\Aqm.exe
O4 - HKCU\..\Run: [Meb] C:\WINDOWS\Iau.exe
O4 - HKCU\..\Run: [Tgo] C:\WINDOWS\SYSTEM\Kbj.exe
O4 - HKCU\..\Run: [Gkt] C:\WINDOWS\Ptk.exe
O4 - HKCU\..\Run: [Gpf] C:\WINDOWS\SYSTEM\Fvd.exe
O4 - HKCU\..\Run: [Jri] C:\WINDOWS\Thq.exe
O4 - HKCU\..\Run: [Trv] C:\WINDOWS\Sfj.exe
O4 - HKCU\..\Run: [Aks] C:\WINDOWS\Met.exe
O4 - HKCU\..\Run: [Iju] C:\WINDOWS\SYSTEM\Krj.exe
O4 - HKCU\..\Run: [Hmt] C:\WINDOWS\Igq.exe
O4 - HKCU\..\Run: [Tlq] C:\WINDOWS\Ugu.exe
O4 - HKCU\..\Run: [Aag] C:\WINDOWS\Kjb.exe
O4 - HKCU\..\Run: [Oog] C:\WINDOWS\SYSTEM\Jne.exe
O4 - HKCU\..\Run: [Roc] C:\WINDOWS\Neu.exe
O4 - HKCU\..\Run: [Kbr] C:\WINDOWS\Dbu.exe
O4 - HKCU\..\Run: [Aoj] C:\WINDOWS\SYSTEM\Pqp.exe
O4 - HKCU\..\Run: [Gsu] C:\WINDOWS\Moo.exe
O4 - HKCU\..\Run: [Dms] C:\WINDOWS\SYSTEM\Num.exe
O4 - HKCU\..\Run: [Bdv] C:\WINDOWS\Knt.exe
O4 - HKCU\..\Run: [Fcr] C:\WINDOWS\Ear.exe
O4 - HKCU\..\Run: [Nve] C:\WINDOWS\SYSTEM\Bhp.exe
O4 - HKCU\..\Run: [Oar] C:\WINDOWS\SYSTEM\Lvq.exe
O4 - HKCU\..\Run: [Vkh] C:\WINDOWS\SYSTEM\Chu.exe
O4 - HKCU\..\Run: [Fga] C:\WINDOWS\Pap.exe
O4 - HKCU\..\Run: [Ggd] C:\WINDOWS\Avp.exe
O4 - HKCU\..\Run: [Dqq] C:\WINDOWS\Qtg.exe
O4 - HKCU\..\Run: [Ddv] C:\WINDOWS\Tpi.exe
O4 - HKCU\..\Run: [Cjl] C:\WINDOWS\SYSTEM\Thv.exe
O4 - HKCU\..\Run: [Eta] C:\WINDOWS\Mnl.exe
O4 - HKCU\..\Run: [Jln] C:\WINDOWS\Mmj.exe
O4 - HKCU\..\Run: [Gfa] C:\WINDOWS\Hoo.exe
O4 - HKCU\..\Run: [Uet] C:\WINDOWS\SYSTEM\Ima.exe
O4 - HKCU\..\Run: [Ehs] C:\WINDOWS\SYSTEM\Nch.exe
O4 - HKCU\..\Run: [Esr] C:\WINDOWS\Tfj.exe
O4 - HKCU\..\Run: [Gqv] C:\WINDOWS\SYSTEM\Vru.exe
O4 - HKCU\..\Run: [Bvb] C:\WINDOWS\Ocd.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\Net2Phone\Net2fone.exe (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - C:\Program Files\Net2Phone\Net2fone.exe (file missing)
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: SEARCH_PAGE_URL=http://home.microsoft.com/access/allinone.asp
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O15 - Trusted IP range: 213.159.117.202 (HKLM)

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:00 PM

Posted 28 March 2005 - 05:16 PM

Please visit this site and run the online scan. Let it fix what it can, and delete what it cant.

http://www.bitdefender.com/scan/




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users