Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

A Mix Of Loads Of Trojans, Viruses Etc.


  • Please log in to reply
15 replies to this topic

#1 Felthor

Felthor

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 24 July 2008 - 12:30 PM

As the topic said, my system is very infected at the moment, its hard to explain in a topic only.. but ill try to explain here.


It all started yesturday, i left my computer on when i went to work. At the time i had ESET nod 32 buissiness edition "guarding" my system. When i got home, i logged in, and i noticed there were about 50 IE windows open, with different popups and other bleep. There were a box that kept appearing and it said "If you are the legit owner of this computer enter *something random* in the box below" i dont think those are the exact words but something simmilar. Everything was blocked, taskmanager, regedit, my C hard drive was somehow hidden and my computer was really slow. I also think i was missing nearly everything on the start menu, couldnt access control panel, this computer, access programs or anything even CMD was blocked.

(I think that sums up my initial problems)

I tried to run Adaware 2008 pro first, but when scanning the registery it reboots the system (at the same point every time) tried 2 times or so. Then i knew i had to get into the C drive, and that took a long while, since i had to access this comp, access administrator tools etc.. but i found out how to, and i started Spybot Search and Destroy. Started scanning, and it found a LOT of stuff, mostly cool W W W search. and i tried to fix all the problems, but when i did, it took a few seconds and they were all back. Then i tried SUPERantispyware 4.15.1000 (07/23/08), and it managed to fix the taskmanager, regedit, and the popups.. But some problems still remained like the missing stuff on the startmenu, virus allert @ my clock and im not sure i dare log into something in case im still infected. Ive also run Bitdefender total security 2008, found a few problems but it didnt seem to fix a lot.

Im sorry about not saving any logs and stuff, could anyone help me? or tell me what information you need me to provide etc?

Many thanks in advance!


-- Felthor

BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:49 AM

Posted 24 July 2008 - 12:36 PM

If you're using Windows 2000/XP, please print out and follow the instructions for using SDFix in BC's self-help tutorial "How to use SDFix". This program is for Windows 2000/XP ONLY.
-- When using this tool, you must use the Administrator's account or an account with "Administrative rights"
-- Disconnect from the Internet and temporarily disable your anti-virus and any anti-malware real time protection before performing a scan.

When done, the SDFix report log will open in notepad and automatically be saved in the SDFix folder as Report.txt. Please copy and paste the contents of Report.txt in your next reply. Be sure to renable you anti-virus and and other security programs before connecting to the Internet.

To fix the policy restrictions created by this infection, please open the SDFix folder or download XP_CodecRepair.inf and save it to your desktop. <- for Windows XP ONLY.
  • Right-click on XP_CodecRepair.inf and select Install from the Context menu.
  • Note: To download the .inf file, go to File, choose "Save page as" All Files and save XP_CodecRepair.inf to your desktop.
  • Then log off or reboot to apply the changes.
Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself.
  • Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Reagardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 Felthor

Felthor
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 24 July 2008 - 01:08 PM

The first program is not working as intended at the moment, i will try fixing it.. tried Malwarebytes thought...

Here is the log!

I have to admit, i noticed something strange now, im really really sure that i downloaded service pack 3 a while ago, but the program tells me i have only service pack 2... My hard drive © came back after scanning with Malwarebytes.!



Malwarebytes' Anti-Malware 1.23
Databasversion: 986
Windows 5.1.2600 Service Pack 2

20:06:30 2008-07-24
mbam-log-7-24-2008 (20-06-30).txt

Skanningstyp: Snabb skanning
Antal skannade objekt: 44844
Förfluten tid: 5 minute(s), 55 second(s)

Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 4
Infekterade registervärden: 2
Infekterade registerdataposter: 13
Infekterade mappar: 1
Infekterade filer: 242

Infekterade minnesprocesser:
(Inga illasinnade poster hittades)

Infekterade minnesmoduler:
(Inga illasinnade poster hittades)

Infekterade registernycklar:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PlugPlayRPC (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fdkowvbp.bofm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\fdkowvbp.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Infekterade registervärden:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\eqvwamkl (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\wnslvxtf (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Infekterade registerdataposter:
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Homepage (Hijack.Homepage) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId (Trojan.FakeAlert) -> Bad: (VIRUS ALERT!) Good: (55713-OEM-0045401-15950) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat (Trojan.FakeAlert) -> Bad: (HH:mm: VIRUS ALERT!) Good: (HH:mm:ss) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowControlPanel (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowRun (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\uoyzsydz.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.

Infekterade mappar:
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc (Trojan.Agent) -> Delete on reboot.

Infekterade filer:
C:\WINDOWS\system32\msssqdeh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hedqsssm.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\eefp.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Drivers\ba25535e.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\!!Quick Search v1.04 serial by RP.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\!Easy Screen Saver Studio keygen by Mr_X.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\!Easy Screen Saver Studio keygen by Mr_X.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\!Tankz - Battle in the city v1.1 PalmOS keygen by TSRh.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\!Tankz - Battle in the city v1.1 PalmOS keygen by TSRh.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\#1 DVD Audio Ripper v1.0 keygen by FFF.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\#1 DVD Audio Ripper v1.0 keygen by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\#1 Media Fixer Pro v4.5 patch by TLG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\#1 Video Converter v1.1.0 patch by SnD.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Color7 Power 3GP iPod PSP Video Converter v8.0.5.22 crack by cRUDE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Color7 Power 3GP iPod PSP Video Converter v8.0.5.22 crack by cRUDE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ColorShade v2.0 crack by LifeWorK.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ColorShade v2.0 crack by LifeWorK.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ConvertXtoDVD v2.0.9.119 patch by TSRh.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CuteFTP by NCG.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CuteFTP by NCG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Cyberlink PowerDVD Deluxe CJL v6.0.0.2023 German keygen by CORE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CyberMedia UnInstaller v5.1 McAfee regfile by PC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CyberSitter 2002 v3.1.6 regfile.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Ad-aware Professional v6.0 Build 158 keygen by ROR.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ADG Panorama Professional v5.2.0.26 crack by NoPE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Adobe Audition 2 patch by CW2K.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Adobe Photoshop & ImageReady v7.0.1 Tryout Deutsch patch by Bidjan.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Adobe Photoshop & ImageReady v7.0.1 Tryout Deutsch patch by Bidjan.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Adobe Photoshop CS3 Extended keygen by Z.W.T.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Adobe Photoshop CS3 Extended keygen by Z.W.T.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Adobe Premiere Interface Improver v1.5.torrent (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Adobe Premiere Interface Improver v1.5.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Astraware Zuma Deluxe v1.0 crack by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Atomix Virtual DJ Home Edition 2006 v3.4.1 keygen by ACME.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Atomix Virtual DJ Home Edition 2006 v3.4.1 keygen by ACME.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Audiotool net Ease MIDI Converter v1.40 keygen by CFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AutoCAD 2006 SP1 crack by Gnux.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AutoCAD 2006 SP1 crack by Gnux.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\1Click DVD Backup v3.2.0.10 serial.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\3dBurst 2004 v1.0 for AutoCAD keygen by diGERATi.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\A-Z AVI DIVX XVID Converter v5.23 patch by SnD.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Acute Softwares Diary v5.0 build 858 crack by Black Magic.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Any Video Converter Professional v2.5.6 crack by REVENGE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AS-Ware Internet-Download Manager v2.95 serial by DBC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Avast! antivirus Pro v4.0 regfile by DBC.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\StatistXP v8.4b keygen by REVENGE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\StatistXP v8.4b keygen by REVENGE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Steganos Internet Privacy v2.06 keygen by CORE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\StyleXP All Version Full patch by ScorpLeX.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\StyleXP All Version Full patch by ScorpLeX.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\SWiSHmax 2004.08.12 Italian + english fixed crack by TSRh.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\SWiSHmax 2004.08.12 Italian + english fixed crack by TSRh.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Syntetic Aperture Color Finesse v1.5.1 For Ae Osx serial by APOGEE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Syntetic Aperture Color Finesse v1.5.1 For Ae Osx serial by APOGEE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\The Classified Connection v1.07 by PC.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\The Classified Connection v1.07 by PC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\The Sims 2 (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Medal of Honor keygen.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Microsoft Office Groove Data Bridge Server 2007 x64 serial by TBE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Microsoft Windows Vista Activation Timer Stop crack by offlinevista.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Mindjet MindManager Pro Admin v6.0.643 keygen by Z.W.T.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\MOBILedit Forensic v2.0.0.10 serial by YAG.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\MOBILedit Forensic v2.0.0.10 serial by YAG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\MusicMatch JukeBox v7.00.0133 and up All languages crack.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\MusicMatch JukeBox v7.00.0133 and up All languages crack.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\NCH Swift Sound WavePad Master Edition v2.00 serial by Swift.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Need for Speed Carbon Collectors Edition keygen by iNDUCT.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Neuxpower NXPowerLite v1.54 keygen by Z.W.T.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\1st Go Warkanoid II Total Edition v2.89 serial by LasH.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\1st Go Warkanoid II Total Edition v2.89 serial by LasH.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\2D3 SteadyMove Pro v1.2 for Adobe After Effects serial by SCOTCH.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\2D3 SteadyMove Pro v1.2 for Adobe After Effects serial by SCOTCH.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\3D Euchre Deluxe v1.6 keygen by ECLiPSE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\3D Euchre Deluxe v1.6 keygen by ECLiPSE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\3D Vista flash exporter keygen by ePSiLON.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\3D Vista flash exporter keygen by ePSiLON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\3DAliens Glu3D v1.1.47 for 3DSMAX 6 keygen by PARADOX.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\All Reflexive Arcade Games v1.0 crack by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\All Xilisoft DVD Toolss serial by AT4RE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\All Xilisoft DVD Toolss serial by AT4RE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Allok Video Joiner v1.5.2 keygen by EMBRACE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Antivirus Kaspersky Personal Pro v5.0.2 keyfile.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Antivirus Kaspersky Personal Pro v5.0.2 keyfile.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Anvsoft Flash Slideshow Maker Professional v4.00 patch by CFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Any Video Converter Professional v2.5.6 crack by REVENGE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Eset NOD32 Antivirus Administrator Edition v2.50.16 crack by DEVOTiON.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Eset NOD32 Antivirus Administrator Edition v2.50.16 crack by DEVOTiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ESET NOD32 Antivirus v2.70.39 French crack by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Eugene Roshal Winrar v3.1 serial by SnD.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Eugene Roshal Winrar v3.1 serial by SnD.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Folder Lock 5.9.0 Loader Installer By Under SEH Team.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\GamesHouse Candy Cruncher v1.52.00 Trial to Full crack by Great Elmo.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\GetDataBack FAT v1.02 keygen by DBC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Grand Theft Auto Vice City v1.x update fixe crack by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Handy Recovery v2.0 crack by FFF.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Handy Recovery v2.0 crack by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\4dvdtools Ease DVD TO VCD Ripper v1.00 keygen by CFF.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\4dvdtools Ease DVD TO VCD Ripper v1.00 keygen by CFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\5 Min Scrabble v1.3 keygen by CORE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\65Bit EasyCatalog CS2 v2.1.2 for Adobe Indesign CS2 patch by DEVOTiON.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\65Bit EasyCatalog CS2 v2.1.2 for Adobe Indesign CS2 patch by DEVOTiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\A Key Word Thing v1.01.01 regfile by LasH.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\A Key Word Thing v1.01.01 regfile by LasH.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\A-Z AVI DIVX XVID Converter v5.23 patch by SnD.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Prince Of Persia trainer by FAiRLiGHT.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\RealVNC Enterprise Linux v4.2.4 serial by ALiENS.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\RealVNC Enterprise Linux v4.2.4 serial by ALiENS.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Restore My Files Data Recovery v6.01 crack by HERETiC.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Restore My Files Data Recovery v6.01 crack by HERETiC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\s (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\SecureClean v3.0B2 keygen by dF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Babylon by PC.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Babylon by PC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Babylon Pro v3.2.46 keygen by ECLiPSE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Babylon Pro v3.2.46 keygen by ECLiPSE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Big Computers Inc Pocket Golf Pro NETv1.0.34 crack by COREPDA.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Big Computers Inc Pocket Golf Pro NETv1.0.34 crack by COREPDA.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Big Kahuna Reef 2 Chain Reaction v2.0.55 keygen by ECLiPSE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Bome Com Restorator 2006 v3.6.1535 keygen by Z.W.T.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\BSI TimeShift v1.0.2 crack by TSRh.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\BWMeter NFO FIX v1.4.3 serial by diGERATi.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\BWMeter NFO FIX v1.4.3 serial by diGERATi.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\HyperCam v1.1 by PC.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\HyperCam v1.1 by PC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Imagix4D v5.0 license by SSG.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Imagix4D v5.0 license by SSG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ImToo 3GP Converter v2.1.41.329b serial by XMA0D.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ImToo 3GP Converter v2.1.41.329b serial by XMA0D.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Intervideo WinDVD Creator Platinum v2.5B014.494C00 keygen by EMBRACE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\iPod Access for Windows v2.5 keygen by CORE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AB Sequest v2.5.0.67 keygen by CAFE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AB Sequest v2.5.0.67 keygen by CAFE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Abbyy FineReader 5 Pro (Try and Buy) - Windows XP.torrent (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AccessData Password Recovery Toolkit v5.21a crack by SSG.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AccessData Password Recovery Toolkit v5.21a crack by SSG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Ace Logix Registry TuneUp v1.3 Parisa crack by Bidjan.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Acrobat Reader 4 by PC.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Acrobat Reader 4 by PC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Acronis Partition Expert 2003 Build 275 keygen by ROR.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Acute Softwares Diary v5.0 build 858 crack by Black Magic.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Alchemy v1.2, Bejeweled v1.5, Seven Seas v1.01 regfile.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Alcohol 120 Percent v1.4.6.711 regcode by LUCiD.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Alcohol 120 Percent v1.4.6.711 regcode by LUCiD.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Alcohol 120 v1.9.6.4719 keygen by MASTER.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Alice any Video to DVD Converter v5.00 crack by EXPLOSiON.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Alice any Video to DVD Converter v5.00 crack by EXPLOSiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Alice DVD any Video to MP4 all Converter v5.00 crack by EXPLOSiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\1$ Password Recover Utility v1.1 crack by TSRh.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\1$ Password Recover Utility v1.1 crack by TSRh.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\1-Click Duplicate Delete for Outlook v1.09 serial by YAG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\12Ghosts Office Pro v2032 serial by DiSTiNCT.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\12Ghosts Office Pro v2032 serial by DiSTiNCT.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\18 Wheels Of Steel (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\18 Wheels Of Steel Pedal To The Metal crack by VengeancE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\18 Wheels Of Steel Pedal To The Metal crack by VengeancE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\18 WoS Pedal To The Metal v1.02B NoCD crack by PWZ.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\18 WoS Pedal To The Metal v1.02B NoCD crack by PWZ.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\1Click DVD Backup v3.2.0.10 serial.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\NewsLeecher v3.9 Beta 1 crack by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Ninja Surfing Hide IP v1.2.033.01 serial by TBE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Norton 2002-2003 LiveUpdate Subscription .zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Nuance ScanSoft PDF Converter Professional v4.0 serial by AGAiN.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Nuance ScanSoft PDF Converter Professional v4.0 serial by AGAiN.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Paessler PRTG Traffic Grapher Enterprise v6.0.5.451 serial by YAG.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Paessler PRTG Traffic Grapher Enterprise v6.0.5.451 serial by YAG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Paragon Bridge v1.2 keygen by CSC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Power AMR MP3 WAV WMA M4A AC3 Audio Converter v1.5 crack by iNFECTED.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\PowerDVD v7.0 MULTILANGUAGE crack TFT.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Powerpoint-PPT to AVI-GIF Converter v1.113 serial by REVENGE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Tweakmaster Pro 2 crack by Salty.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Tweakmaster Pro 2 crack by Salty.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\TypingMaster Pro 2005 v6.30 patch by BAKA.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\TypingMaster Pro 2005 v6.30 patch by BAKA.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\VideoGet v1.0 crack by iNFECTED.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Vista User Time Manager v4.1.1.1 crack by AT4RE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Vista User Time Manager v4.1.1.1 crack by AT4RE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CD Catalog Expert v9.00.061209 serial by cRUDE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CDDatabase Plugin for Total Commander v2.00 ALPHA crack by DEVOTiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CFosSpeed v1.06 serial by PARADOX.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CloneCD 4 CleanUp! v1.x crack by c4cu.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CloneCD 4 CleanUp! v1.x crack by c4cu.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CodeGear Delphi 2007 Enterprise German crack by Cygnus.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\CodeGear Delphi 2007 Enterprise German crack by Cygnus.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AnyDVD All versions keygen by TMG.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AnyDVD All versions keygen by TMG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Anyplace control v3.0 serial.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Anyplace control v3.0 serial.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Ardamax Keylogger v2.2 keygen by DUST.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ArtMoney Pro v7.08 Rus serial.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AS-Ware Internet-Download Manager v2.95 serial by DBC.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\DFX Audio Enhancer For J River MediaJukeBox v7.010 keygen by CORE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Divx Create Bundle v6.8 keygen by DEVOTiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Droppix ISO PowerPack v1.0.2 serial by TDK.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\DTgrafic Full Speed v1.0.0 regfile by DEVOTiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Dundas Chart For Share Point For MS Office SharePoint Server 2007 v1.0.0.315 serial by AGGRESSiON.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Dundas Chart For Share Point For MS Office SharePoint Server 2007 v1.0.0.315 serial by AGGRESSiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Easy CD & DVD Cover Creator v3.5 keygen by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\EasyBoot System UltraISO v6.56.693 crack by N-GeN.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\EMS MySQL Data Generator v1.1.0.7 crack by SSG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Advanced Audio Plugin for Nero 7 serial by Net Guru.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Advanced Audio Plugin for Nero 7 serial by Net Guru.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Age of Empires patch by DBC.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Age of Empires patch by DBC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Ahead Nero Burning Rom v6.0.0.28 Ultra Edition keygen by ORiON.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Ahead Nero Burning Rom v6.0.0.28 Ultra Edition keygen by ORiON.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Avast! antivirus Pro v4.0 regfile by DBC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Avernum crack by TNT.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Avernum crack by TNT.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Avex DVD to Mobile Video Suite v4.0 Build 05 regfile by CzW.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AVS Audio Editor v1.2.0.28 keygen by SSG.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AVS Audio Editor v1.2.0.28 keygen by SSG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AVS Video Converter v1.2 Build 26 patch by LasH.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\AVS Video Converter v1.2 Build 26 patch by LasH.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\IVT Corporation-BlueSoleil v2.3.0 patch by diGERATi.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Kaspersky Anti Hacker v1.8.180 patch by CHiCNCREAM.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Kaspersky Anti Hacker v1.8.180 patch by CHiCNCREAM.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Kaspersky Anti-Virus Keys Collection.torrent (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Kaspersky Internet Security 2006 v6.0.0.290 RC6 keyfile by FFF.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Kaspersky Internet Security 2006 v6.0.0.290 RC6 keyfile by FFF.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Kozmogames Warchess v1.1 keygen by N-GeN.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\WebcamXP Pro 2006 v2.25.040 crack by TE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\WebcamXP Pro 2006 v2.25.040 crack by TE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Xilisoft 3GP To Video Converter v2.1.59.0327b keygen by Lz0.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Xilisoft 3GP To Video Converter v2.1.59.0327b keygen by Lz0.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\SKTools v2.1.124 PocketPC crack by TSRh.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\SlySoft CloneCD v5.3.1.0 keygen by cRUDE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\SmartFTP Client v2.5 Build 1006 patch by AT4RE.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\SmartFTP Client v2.5 Build 1006 patch by AT4RE.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\SmartMovie Converter v3.10 for Symbian phones keygen by TLG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Speed Video Converter v2.1.1 patch by ICU.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Data Doctor Password Recovery v3.0.1.5 serial by YAG.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\HC Panda Future Connection v3.1 keygen by PGC.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\IVT Corporation-BlueSoleil v2.3.0 patch by diGERATi.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\NewsLeecher v3.9 Beta 1 crack by FFF.zip (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\ShadowStor ShadowUser Pro v2.5 keygen by EAT.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\Stardock WindowBlinds Enhanced v4.30 keygen by ROR.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Application Data\Microsoft\dtsc\TrepCAD St 3 v3.2.1 German crack by diGERATi.zip~ (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\BM1ba6201f.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM1ba6201f.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jens\Lokala inställningar\Temp\CmdLineExt02.dll (Trojan.Agent) -> Quarantined and deleted successfully.

Edited by Felthor, 24 July 2008 - 01:16 PM.


#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:49 AM

Posted 24 July 2008 - 01:35 PM

Did you reboot the computer after using MBAM? If it encounters a file that is difficult to remove, you need to restart the computer so the malware can be fully removed. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. Your log indicates some files will be deleted on reboot. If you have not rebooted, make sure you do this. When done, rescan again with MBAM, click the Logs tab and copy/paste the contents of the new report in your next reply. If you did reboot, the rescan again anyway and post a new log.

IMPORTANT NOTE: You have a heavily infected system. One or more of the identified infections was related to a rootkit component. Rootkits are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit was identified and removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because the rootkit has been removed the computer is now secure. Further, in some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:

"When should I re-format? How should I reinstall?"
"Help: I Got Hacked. Now What Do I Do?"
"Where to draw the line? When to recommend a format and reinstall?"
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#5 Felthor

Felthor
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 24 July 2008 - 01:43 PM

Well yeah, i have been considering to whipe the system and do a full reinstall since i got so badly infected, the problem is, i have 2 external hard drives connected to the pc, and i have a LOT of things that i wanna save, but i also think its prolly not safe to keep them..

And about my bank accounts, i checked them first thing today and everything seems fine.. for the moment anyway (my bank told me it was impossible to log into my account with another computer) and that made me relativley safe, but i still think if someone could get control over my system they could prolly tap in one way or the other.. Also, i havnt logged into any of the important stuff like bank accounts etc since i got so heavily infected.. cause i dont think its safe... a drive whipe is prolly the only way i will ever be able to trust my computer again..

#6 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:49 AM

Posted 24 July 2008 - 01:49 PM

Your decision as to what action to take should be made by reading and asking yourself the questions presented in the "When should I re-format?" and What Do I Do? links I previously provided. As I already said, in some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. Wiping your drive, reformatting, and performing a clean install of the OS removes everything and is the safest action but I cannot make that decision for you.

Should you decide not to follow that advice, we will do our best to help clean the computer of any infections but we cannot guarantee it to be trustworthy or that the removal will be successful. Let me know how you wish to proceed.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#7 Felthor

Felthor
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 24 July 2008 - 01:51 PM

I think you missed my point, basicly i asked if its safe to keep external hard drives that only contain music, movies and basicly nothing is instanned there, backups of some dvds and stuff is what i keep there.

And i think ive decided to whipe at least my main drive with my OS and all the programs, i can ofc whipe my external drives aswell, but im not sure how i should safley do that, since i cant whipe them all at the same time!

Edited by Felthor, 24 July 2008 - 01:59 PM.


#8 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:49 AM

Posted 24 July 2008 - 02:07 PM

If you decide to reformat, you should back up all your important documents, data files and photos. The safest practice is not to backup any .exe files because they may be infected. Some malware may disguise itself by adding and hiding its extension to the existing extension of other files so be sure you take a close look at the full name. After reformatting, as a precaution, make sure you scan these files with your anti-virus prior to copying them back to your hard drive.

If you need additional assistance with reformatting, backing up your data, etc you can start a new topic in the Windows XP Home and Professional forum.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#9 Felthor

Felthor
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 24 July 2008 - 02:19 PM

Now i have cleaned all my external hdds of anything with an exe file, and most of the rest aswell, i only have pictures, music, and dvd backups left, some text documents with other saved information that i might need.


Gonna try to format now, ill check back here later to tell you guys how it went :thumbsup:

#10 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:49 AM

Posted 24 July 2008 - 02:44 PM

Good luck.

Remember there is help if you need it.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#11 Criker

Criker

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 24 July 2008 - 03:16 PM

There is a bunch of online scanners you run. I would suggest booting into safemode with networking and running some of the online scanners. Or reformat=)


http://www.isecuritysource.com/tools/panda...-virus-scanner/
http://www.isecuritysource.com/tools/kaspe...ivirus-scanner/

Good luck!

#12 Felthor

Felthor
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 24 July 2008 - 04:02 PM

format done, trying to install xp but its fakking with me, it tells me i cant copy some files >_> dll files and such

Edited by Felthor, 24 July 2008 - 04:08 PM.


#13 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,595 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:02:49 AM

Posted 24 July 2008 - 04:27 PM

These links include step by step instructions:
"Clean Install Windows XP".
"Reformat & Clean Install Windows".
"XP Clean Install Interactive Setup".

If you need additional assistance with this, you can start a new topic in the Windows XP Home and Professional forum. We have technical Advisors members here who can walk you through the steps. Try to be as specific as you can in regards to the problem you are encountering.

If you don't get a reply, please send me a PM and I will get someone to take a look.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#14 Felthor

Felthor
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 25 July 2008 - 03:12 PM

Now im back posting here! i managed to install XP (the install was just kranky or something) and ive reinstalled most of my antivurus programs etc, and ive not had any new problems :D


So i think this was sucsessful! thank you for all your help.

#15 Wolfy87

Wolfy87

  • Members
  • 414 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:England
  • Local time:06:49 AM

Posted 25 July 2008 - 04:24 PM

I had almoast exactly the same problem (i just joined the webbie) i was siting at the desktop when WHAM! desktop shortcuts gone, admin stuff gone, no ctrl alt del! it sent my almoast brand new comp into a spiral of OW!'s and AH!'s lol but i used AVG (pile of bleep!) and Super anti spyware (getting better) and Spybot S & D (Annoying kept starting at boot) and then finally Malwarebites (It Pwned it!!!) and then it was gone after i went in to the .DLL's and got rid of "VIRUS ALERT!" from the time bar. But no probs now so far it looks clean and hopefully the dreaded verdo wont come back after 6 hrs to get rid of it now im gunna go play darts :flowers: :thumbsup:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users