Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

XP lost admin rights


  • This topic is locked This topic is locked
12 replies to this topic

#1 legreen

legreen

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:12 AM

Posted 15 October 2009 - 04:43 PM

Over the last couple of weeks Kaspersky has been alerting me to trojans that it has told me it dealt with. This evening I got an alert again saying it had dealt with trojan.html.fraud.d. Windows also updated itself this evening.

My PC now seems to have lost admin rights (I only found this out when I went to try and use Nero and it told me I couldn't burn). I am set up as a computer administrator. The log in and shut down has also changed 'look'.

Can anyone please help me and determine if I am infected, how I can get my PC back working normally again and have admin rights!!

I am using XP Media Edition.

Thanks in advance.

BC AdBot (Login to Remove)

 


#2 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:10:12 PM

Posted 17 October 2009 - 07:03 PM

Lost Administrator rights.

http://www.jimmah.com/vista/Administration...t_of_admin.aspx
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#3 legreen

legreen
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:12 AM

Posted 18 October 2009 - 05:48 AM

Thank you for the reply. I don't believe this is the problem. I am set up as an administrator. I have also changed the rights and changed them back/created new accounts but the problem still exists.

On a nero forum is says:

Please scan your computer for viruses. This problem appears to be related to a possible virus/troyan in your computer.

#4 legreen

legreen
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:12 AM

Posted 18 October 2009 - 03:03 PM

Trojan.Win32.Patched.hs

win32.TDSS.z

Trojan-Downloader.wwin32.fraudload.wsuu

Trojan.win32.inject.ajra

The above have been identified by Kaspersky but I am not sure if it has got rid of them. Malwarebytes didn't detect anything.

Still can't burn with Nero.

#5 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:10:12 PM

Posted 18 October 2009 - 07:16 PM

:inlove:
Update mbam and run a FULL scan
Please post the results
====================

:flowers:

ATF
Please download ATF Cleaner by Atribune & save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main "Select Files to Delete" choose: Select All.
  • Click the Empty Selected button.
  • If you use Firefox browser click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • If you use Opera browser click Opera at the top and choose: Select All
  • Click the Empty Selected button.
    If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.
Note: On Vista, "Windows Temp" is disabled. To empty "Windows Temp" ATF-Cleaner must be "Run as an Administrator".

------------------------------------

:thumbsup:
SAS, may take a long time to scan
Please download and scan with SUPERAntiSpyware Free
  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen and exit the program.
  • Do not run a scan just yet.
    First
Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with SUPERAntiSpyware as follows:
  • Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
Note.. SAS doesn't open the registry hives for other user accounts on the system, so scans should be done from each user account.

==============================

:trumpet:

Please download Dr.Web CureIt, the free version & save it to your desktop. DO NOT perform a scan yet.

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on launch.exe to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the Virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All.
  • When complete, click Select All, then choose Cure > Move incurable.
    (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • Now put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and UNcheck "Heuristic analysis" under the "Scanning" tab, then click Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • When the scan is complete, a message will be displayed at the bottom indicating if any viruses were found.
  • Click "Yes to all" if asked to cure or move the file(s) and select "Move incurable".
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#6 legreen

legreen
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:12 AM

Posted 19 October 2009 - 01:42 PM

Have done 1 and 2 so far. Mbam results:

Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 3

19/10/2009 19:36:26
mbam-log-2009-10-19 (19-36-21).txt

Scan type: Full Scan (C:\|)
Objects scanned: 245692
Time elapsed: 56 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id (Malware.Trace) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#7 legreen

legreen
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:12 AM

Posted 19 October 2009 - 03:54 PM

Step 3:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/19/2009 at 09:34 PM

Application Version : 4.29.1004

Core Rules Database Version : 4174
Trace Rules Database Version: 2093

Scan type : Complete Scan
Total Scan Time : 01:41:20

Memory items scanned : 236
Memory threats detected : 0
Registry items scanned : 6328
Registry threats detected : 0
File items scanned : 99441
File threats detected : 2

Adware.Tracking Cookie
C:\WINDOWS\system32\config\systemprofile\Cookies\system@www.exerevenue[2].txt

Adware.CouponBar
C:\WINDOWS\SYSTEM32\CPNPRT2.CID

The final stages to follow tomorrow. Thank you.

#8 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:10:12 PM

Posted 19 October 2009 - 08:29 PM

You'd better add these to the scan list also

:flowers:

We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive (If you did not use the "Direct Download" mirror).
  • Open Posted Image on your desktop.
  • Click the Posted Image tab.
  • Click the Posted Image button.
  • Check all seven boxes: Posted Image
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the Posted Image button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

----------------------------------

Please note: If Rootrepeal fails to run, try this step: Click Settings - Options. Set the Disk Access slider to High

Also try: right-click on rootrepeal.exe and rename it to tatertot.scr

=====================

:thumbsup:
Vista users can refer to these instructions to open a command prompt.

Alternatively you can do this:

Please download peek.bat and save it to your Desktop. Double-click on peek.bat to run it. A black Command Prompt window will appear indicating the program is running. Once it is finished, copy and paste the entire contents of the Log.txt file it creates in your next reply.

If you encounter a problem downloading or getting peek.bat to run, go to Posted Image > Run..., and in the open box, type: Notepad
  • Click OK.
  • Copy and paste everything in the code box below into the Untitled - Notepad.
@ECHO OFF
DIR /a/s C:\WINDOWS\scecli.dll C:\WINDOWS\netlogon.dll C:\WINDOWS\eventlog.dll C:\Windows\cngaudit.dll >Log.txt
START Log.txt
DEL %0
  • Go to File > Save As, click the drop-down box to change the Save As Type to *All Files and save it as "peek.bat" on your desktop.
  • Double-click peek.bat to run the script.
  • A window will open and close quickly, this is normal.
  • A file called log.txt should be created on your Desktop.
  • Open that file and copy/paste the contents in your next reply.
-- Vista users, users can refer to these instructions to Run a Batch File as an Administrator.
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#9 legreen

legreen
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:12 AM

Posted 20 October 2009 - 04:16 PM

My computer crashed whilst in the middle of doing the Dr WebIt complete scan and before I could save the report. It had detected files which I think are in the text file that was saved in the program folder. There are no quarantined files though even though I clicked on move, the status showed eradicated or deleted. I will complete the complete scan tomorrow.

=============================================================================
Dr.Web Scanner for Windows v5.00.7 (5.00.7.09210)
© Doctor Web, Ltd., 1992-2009
Log generated on: 2009-10-20, 20:51:54 [LOUISESMAIN][SYSTEM]
Command line: "C:\Program Files\DrWeb\drweb32w.exe" /ss- /mw /ts /tb /ha /noreboot
Operating system: Windows XP Professional x86 (Build 2600), Service Pack 3
=============================================================================
DwShield started
Engine version: 5.00 (5.00.0.12182)
Engine API version: 2.02
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwtoday.vdb - 11444 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50047.vdb - 12425 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50046.vdb - 4903 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50045.vdb - 3476 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50044.vdb - 8537 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50043.vdb - 5741 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50042.vdb - 4308 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50041.vdb - 5456 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50040.vdb - 6848 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50039.vdb - 5479 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50038.vdb - 8526 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50037.vdb - 7640 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50036.vdb - 6071 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50035.vdb - 4983 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50034.vdb - 2139 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50033.vdb - 3732 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50032.vdb - 6424 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50031.vdb - 5242 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50030.vdb - 2770 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50029.vdb - 2685 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50028.vdb - 3327 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50027.vdb - 4697 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50026.vdb - 2792 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50025.vdb - 5841 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50024.vdb - 2260 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50023.vdb - 4796 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50022.vdb - 5098 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50021.vdb - 4891 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50020.vdb - 5033 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50019.vdb - 3254 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50018.vdb - 5206 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50017.vdb - 7585 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50016.vdb - 5298 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50015.vdb - 5947 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50014.vdb - 6039 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50013.vdb - 5309 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50012.vdb - 3511 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50011.vdb - 2495 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50010.vdb - 4565 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50009.vdb - 4467 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50008.vdb - 5196 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50007.vdb - 2359 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50006.vdb - 1938 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50005.vdb - 3335 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50004.vdb - 3185 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50003.vdb - 1468 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50002.vdb - 280 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50001.vdb - 567 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50000.vdb - 1194 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwebase.vdb - 423328 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwrtoday.vdb - 110 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50003.vdb - 508 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50002.vdb - 665 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50001.vdb - 626 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwntoday.vdb - 229 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50006.vdb - 597 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50005.vdb - 554 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50004.vdb - 680 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50003.vdb - 712 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50002.vdb - 925 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50001.vdb - 840 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwrisky.vdb - 3316 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwnasty.vdb - 19303 virus records
Total virus records: 683155
[Self-checking] C:\Program Files\DrWeb\drweb32w.exe
Key file: C:\Program Files\DrWeb\drwdemo.key
License key number: 1405302341
Registered to: Doctor Web trial user: Louise Green
License key activates on: 2009-10-20
License key expires on: 2009-11-19
[Memory scanning] Process in memory: C:\WINDOWS\system32\svchost.exe:152 infected with BackDoor.Tdss.565 - eradicated

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Scanned: 9
Infected: 1
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 0
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 0 Kb/s
Scan time: 00:00:07
-----------------------------------------------------------------------------

Scanning interrupted by user! - viruses found
=============================================================================
Total session statistics
=============================================================================
Scanned: 9
Infected: 1
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 0
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 0 Kb/s
Scan time: 00:00:07
=============================================================================

=============================================================================
Dr.Web Scanner for Windows v5.00.7 (5.00.7.09210)
© Doctor Web, Ltd., 1992-2009
Log generated on: 2009-10-20, 20:55:45 [LOUISESMAIN][Louise]
Command line: "C:\Program Files\DrWeb\DrWeb32w.exe"
Operating system: Windows XP Professional x86 (Build 2600), Service Pack 3
=============================================================================
DwShield started
Engine version: 5.00 (5.00.0.12182)
Engine API version: 2.02
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwtoday.vdb - 11444 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50047.vdb - 12425 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50046.vdb - 4903 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50045.vdb - 3476 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50044.vdb - 8537 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50043.vdb - 5741 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50042.vdb - 4308 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50041.vdb - 5456 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50040.vdb - 6848 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50039.vdb - 5479 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50038.vdb - 8526 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50037.vdb - 7640 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50036.vdb - 6071 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50035.vdb - 4983 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50034.vdb - 2139 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50033.vdb - 3732 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50032.vdb - 6424 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50031.vdb - 5242 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50030.vdb - 2770 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50029.vdb - 2685 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50028.vdb - 3327 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50027.vdb - 4697 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50026.vdb - 2792 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50025.vdb - 5841 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50024.vdb - 2260 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50023.vdb - 4796 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50022.vdb - 5098 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50021.vdb - 4891 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50020.vdb - 5033 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50019.vdb - 3254 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50018.vdb - 5206 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50017.vdb - 7585 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50016.vdb - 5298 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50015.vdb - 5947 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50014.vdb - 6039 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50013.vdb - 5309 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50012.vdb - 3511 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50011.vdb - 2495 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50010.vdb - 4565 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50009.vdb - 4467 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50008.vdb - 5196 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50007.vdb - 2359 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50006.vdb - 1938 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50005.vdb - 3335 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50004.vdb - 3185 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50003.vdb - 1468 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50002.vdb - 280 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50001.vdb - 567 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50000.vdb - 1194 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwebase.vdb - 423328 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwrtoday.vdb - 110 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50003.vdb - 508 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50002.vdb - 665 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50001.vdb - 626 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwntoday.vdb - 229 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50006.vdb - 597 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50005.vdb - 554 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50004.vdb - 680 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50003.vdb - 712 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50002.vdb - 925 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50001.vdb - 840 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwrisky.vdb - 3316 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwnasty.vdb - 19303 virus records
Total virus records: 683155
[Self-checking] C:\Program Files\DrWeb\DrWeb32w.exe
Key file: C:\Program Files\DrWeb\drwdemo.key
License key number: 1405302341
Registered to: Doctor Web trial user: Louise Green
License key activates on: 2009-10-20
License key expires on: 2009-11-19
[Memory scanning] Process in memory: C:\WINDOWS\system32\services.exe:312 infected with BackDoor.Tdss.565 - eradicated

[Scan path] c:\documents and settings\administrator\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\all users\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\default user\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\louise\local settings\temp\hgu8ynfx.dll
[Scan path] c:\documents and settings\louise\start menu\programs\startup\desktop.ini
[Scan path] c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
[Scan path] c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
[Scan path] c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe
[Scan path] c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
[Scan path] c:\program files\apple software update\softwareupdate.exe
[Scan path] c:\program files\ati technologies\ati control panel\atiptaxx.exe
[Scan path] c:\program files\bonjour\mdnsnsp.dll
[Scan path] c:\program files\bonjour\mdnsresponder.exe
[Scan path] c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
[Scan path] c:\program files\common files\apple\mobile device support\bin\applesyncnotifier.exe
[Scan path] c:\program files\common files\doctor web\scanning engine\dwengine.exe
[Scan path] c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
[Scan path] c:\program files\common files\microsoft shared\source engine\ose.exe
[Scan path] c:\program files\common files\microsoft shared\speech\sapi.cpl
[Scan path] c:\program files\common files\microsoft shared\web components\11\owc11.dll
[Scan path] c:\program files\common files\microsoft shared\web folders\msonsext.dll
[Scan path] c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
[Scan path] c:\program files\common files\real\update_ob\realsched.exe
[Scan path] c:\program files\common files\system\ole db\oledb32.dll
[Scan path] c:\program files\creative\audiocs\ctaudcs.cpl
[Scan path] c:\program files\creative\creative zen nano plus\zen nano plus media explorer\ctmvnsu.dll
[Scan path] c:\program files\digiguide tv guide\client.exe
[Scan path] c:\program files\drweb\drweb32w.exe
[Scan path] c:\program files\drweb\drwebsp.dll
[Scan path] c:\program files\drweb\drwebupw.exe
[Scan path] c:\program files\drweb\drwsxtn.dll
[Scan path] c:\program files\drweb\spider.sys
[Scan path] c:\program files\drweb\spideragent.exe
[Scan path] c:\program files\drweb\spiderml.exe
[Scan path] c:\program files\drweb\spidernt.exe
[Scan path] c:\program files\drweb\spiderui.exe
[Scan path] c:\program files\google\common\google updater\googleupdaterservice.exe
[Scan path] c:\program files\google\google toolbar\component\fastsearch_b7c5ac242193bb3e.dll
[Scan path] c:\program files\google\google toolbar\googletoolbar_32.dll
[Scan path] c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
[Scan path] c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
[Scan path] c:\program files\hp\digital imaging\bin\hpqcxs08.dll
[Scan path] c:\program files\hp\digital imaging\bin\hpqddsvc.dll
[Scan path] c:\program files\hp\digital imaging\bin\hpqtra08.exe
[Scan path] c:\program files\hp\hp software update\hpwuschd2.exe
[Scan path] c:\program files\internet explorer\plugins\npdocbox.dll
[Scan path] c:\program files\ipod\bin\ipodservice.exe
[Scan path] c:\program files\itunes\ituneshelper.exe
[Scan path] c:\program files\itunes\itunesminiplayer.dll
[Scan path] c:\program files\java\jre6\bin\jp2ssv.dll
[Scan path] c:\program files\java\jre6\bin\jqs.exe
[Scan path] c:\program files\java\jre6\bin\jusched.exe
[Scan path] c:\program files\java\jre6\bin\npjpi160_11.dll
[Scan path] c:\program files\java\jre6\bin\ssv.dll
[Scan path] c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
[Scan path] c:\program files\java\jre6\lib\deploy\jqs\jqs.conf
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\adialhk.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\kloehk.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\mzvkbd.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\mzvkbd3.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\scieplgn.dll
[Scan path] c:\program files\lavasoft\ad-aware\aawservice.exe
[Scan path] c:\program files\lavasoft\ad-aware\ceapi.dll
[Scan path] c:\program files\lavasoft\ad-aware\pkarchive85u.dll
[Scan path] c:\program files\messenger\msmsgs.exe
[Scan path] c:\program files\microsoft office\office11\mlshext.dll
[Scan path] c:\program files\microsoft office\office11\msohev.dll
[Scan path] c:\program files\microsoft office\office11\olkfstub.dll
[Scan path] c:\program files\outlook express\setup50.exe
[Scan path] c:\program files\outlook express\wabfind.dll
[Scan path] c:\program files\quicktime\qtplugin.ocx
[Scan path] c:\program files\quicktime\qtsystem\quicktime.cpl
[Scan path] c:\program files\quicktime\qttask.exe
[Scan path] c:\program files\real\realplayer\rpbrowserrecordplugin.dll
[Scan path] c:\program files\real\realplayer\rpshell.dll
[Scan path] c:\program files\superantispyware\sasdifsv.sys
[Scan path] c:\program files\superantispyware\sasenum.sys
[Scan path] c:\program files\superantispyware\saskutil.sys
[Scan path] c:\program files\superantispyware\sasseh.dll
[Scan path] c:\program files\superantispyware\saswinlo.dll
[Scan path] c:\program files\windows live\installer\wlsetupsvc.exe
[Scan path] c:\program files\windows live\messenger\fsshext.8.5.1302.1018.dll
[Scan path] c:\program files\windows live\messenger\msgrapp.8.5.1302.1018.dll
[Scan path] c:\program files\windows live\messenger\msnmsgr.exe
[Scan path] c:\program files\windows live\messenger\usnsvc.exe
[Scan path] c:\program files\windows media player\wmpnetwk.exe
[Scan path] c:\program files\winrar\rarext.dll
[Scan path] c:\windows\apppatch\acadproc.dll
[Scan path] c:\windows\apppatch\acgenral.dll
[Scan path] c:\windows\cthelper.exe
[Scan path] c:\windows\downloaded program files\accounttracking.dll
[Scan path] c:\windows\downloaded program files\as2stubie.dll
[Scan path] c:\windows\downloaded program files\downloadmanagerv2.ocx
[Scan path] c:\windows\downloaded program files\facebookphotouploader.ocx
[Scan path] c:\windows\downloaded program files\game_uno1.dll
[Scan path] c:\windows\downloaded program files\imageuploader3.ocx
[Scan path] c:\windows\downloaded program files\imageuploader4.ocx
[Scan path] c:\windows\downloaded program files\imageuploader4_5.ocx
[Scan path] c:\windows\downloaded program files\messengerstatspaclient.dll
[Scan path] c:\windows\downloaded program files\photouploader5.ocx
[Scan path] c:\windows\downloaded program files\photouploader55.ocx
[Scan path] c:\windows\downloaded program files\snapfishactivia1000.ocx
[Scan path] c:\windows\downloaded program files\uploader_uni.ocx
[Scan path] c:\windows\ehome\ehrecvr.exe
[Scan path] c:\windows\ehome\ehsched.exe
[Scan path] c:\windows\ehome\ehtray.exe
[Scan path] c:\windows\ehome\mcrdsvc.exe
[Scan path] c:\windows\explorer.exe
[Scan path] c:\windows\inf\easycdblock.inf
[Scan path] c:\windows\inf\mcdftreg.inf
[Scan path] c:\windows\inf\msmsgs.inf
[Scan path] c:\windows\inf\msnetmtg.inf
[Scan path] c:\windows\inf\unregmp2.exe
[Scan path] c:\windows\inf\wmp11.inf
[Scan path] c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe
[Scan path] c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
[Scan path] c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe
[Scan path] c:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe
[Scan path] c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
[Scan path] c:\windows\msagent\agentpsh.dll
[Scan path] c:\windows\network diagnostic\xpnetdiag.exe
[Scan path] c:\windows\pchealth\helpctr\binaries\pchsvc.dll
[Scan path] c:\windows\system32\advapi32.dll
[Scan path] c:\windows\system32\advpack.dll
[Scan path] c:\windows\system32\alg.exe
[Scan path] c:\windows\system32\alrsvc.dll
[Scan path] c:\windows\system32\apphelp.dll
[Scan path] c:\windows\system32\appmgmts.dll
[Scan path] c:\windows\system32\appwiz.cpl
[Scan path] c:\windows\system32\ati2evxx.exe
[Scan path] c:\windows\system32\ati2sgag.exe
[Scan path] c:\windows\system32\atl.dll
[Scan path] c:\windows\system32\audiodev.dll
[Scan path] c:\windows\system32\audiosrv.dll
[Scan path] c:\windows\system32\authz.dll
[Scan path] c:\windows\system32\autochk.exe
[Scan path] c:\windows\system32\basesrv.dll
[Scan path] c:\windows\system32\browser.dll
[Scan path] c:\windows\system32\browseui.dll
[Scan path] c:\windows\system32\cabview.dll
[Scan path] c:\windows\system32\certcli.dll
[Scan path] c:\windows\system32\cisvc.exe
[Scan path] c:\windows\system32\clbcatq.dll
[Scan path] c:\windows\system32\clipsrv.exe
[Scan path] c:\windows\system32\cnbjmon.dll
[Scan path] c:\windows\system32\comctl32.dll
[Scan path] c:\windows\system32\comdlg32.dll
[Scan path] c:\windows\system32\comres.dll
[Scan path] c:\windows\system32\config\systemprofile\start menu\programs\startup\desktop.ini
[Scan path] c:\windows\system32\credui.dll
[Scan path] c:\windows\system32\crypt32.dll
[Scan path] c:\windows\system32\cryptdll.dll
[Scan path] c:\windows\system32\cryptext.dll
[Scan path] c:\windows\system32\cryptnet.dll
[Scan path] c:\windows\system32\cryptsvc.dll
[Scan path] c:\windows\system32\cryptui.dll
[Scan path] c:\windows\system32\cscdll.dll
[Scan path] c:\windows\system32\cscui.dll
[Scan path] c:\windows\system32\csrsrv.dll
[Scan path] c:\windows\system32\csrss.exe
[Scan path] c:\windows\system32\ctfmon.exe
[Scan path] c:\windows\system32\ctsvccda.exe
[Scan path] c:\windows\system32\ctxfihlp.exe
[Scan path] c:\windows\system32\dciman32.dll
[Scan path] c:\windows\system32\ddraw.dll
[Scan path] c:\windows\system32\deskadp.dll
[Scan path] c:\windows\system32\deskmon.dll
[Scan path] c:\windows\system32\deskperf.dll
[Scan path] c:\windows\system32\dfshim.dll
[Scan path] c:\windows\system32\dfsshlex.dll
[Scan path] c:\windows\system32\dhcpcsvc.dll
[Scan path] c:\windows\system32\digest.dll
[Scan path] c:\windows\system32\dimsntfy.dll
[Scan path] c:\windows\system32\diskcopy.dll
[Scan path] c:\windows\system32\dllhost.exe
[Scan path] c:\windows\system32\dmadmin.exe
[Scan path] c:\windows\system32\dmserver.dll
[Scan path] c:\windows\system32\dnsapi.dll
[Scan path] c:\windows\system32\dnsrslvr.dll
[Scan path] c:\windows\system32\docprop.dll
[Scan path] c:\windows\system32\docprop2.dll
[Scan path] c:\windows\system32\dot3api.dll
[Scan path] c:\windows\system32\dot3dlg.dll
[Scan path] c:\windows\system32\dot3gpclnt.dll
[Scan path] c:\windows\system32\dot3svc.dll
[Scan path] c:\windows\system32\drivers\acpi.sys
[Scan path] c:\windows\system32\drivers\aec.sys
[Scan path] c:\windows\system32\drivers\afd.sys
[Scan path] c:\windows\system32\drivers\arp1394.sys
[Scan path] c:\windows\system32\drivers\asapiw2k.sys
[Scan path] c:\windows\system32\drivers\asyncmac.sys
[Scan path] c:\windows\system32\drivers\atapi.sys
[Scan path] c:\windows\system32\drivers\ati2mtag.sys
[Scan path] c:\windows\system32\drivers\atmarpc.sys
[Scan path] c:\windows\system32\drivers\audstub.sys
[Scan path] c:\windows\system32\drivers\avera800.sys
[Scan path] c:\windows\system32\drivers\beep.sys
[Scan path] c:\windows\system32\drivers\ccdecode.sys
[Scan path] c:\windows\system32\drivers\cdaudio.sys
[Scan path] c:\windows\system32\drivers\cdrom.sys
[Scan path] c:\windows\system32\drivers\cercsr6.sys
[Scan path] c:\windows\system32\drivers\ctac32k.sys
[Scan path] c:\windows\system32\drivers\ctaud2k.sys
[Scan path] c:\windows\system32\drivers\ctdvda2k.sys
[Scan path] c:\windows\system32\drivers\ctoss2k.sys
[Scan path] c:\windows\system32\drivers\ctprxy2k.sys
[Scan path] c:\windows\system32\drivers\ctsfm2k.sys
[Scan path] c:\windows\system32\drivers\disk.sys
[Scan path] c:\windows\system32\drivers\dmboot.sys
[Scan path] c:\windows\system32\drivers\dmio.sys
[Scan path] c:\windows\system32\drivers\dmload.sys
[Scan path] c:\windows\system32\drivers\dmusic.sys
[Scan path] c:\windows\system32\drivers\drmkaud.sys
[Scan path] c:\windows\system32\drivers\dwprot.sys
[Scan path] c:\windows\system32\drivers\e1e5132.sys
[Scan path] c:\windows\system32\drivers\emupia2k.sys
[Scan path] c:\windows\system32\drivers\fdc.sys
[Scan path] c:\windows\system32\drivers\fips.sys
[Scan path] c:\windows\system32\drivers\flpydisk.sys
[Scan path] c:\windows\system32\drivers\fltmgr.sys
[Scan path] c:\windows\system32\drivers\fs_rec.sys
[Scan path] c:\windows\system32\drivers\ftdisk.sys
[Scan path] c:\windows\system32\drivers\gasfkyrmuptnwm.sys
c:\windows\system32\drivers\gasfkyrmuptnwm.sys infected with BackDoor.Tdss.based.1

[Scan path] c:\windows\system32\drivers\gearaspiwdm.sys
[Scan path] c:\windows\system32\drivers\ha20x2k.sys
[Scan path] c:\windows\system32\drivers\hidusb.sys
[Scan path] c:\windows\system32\drivers\hsf_cnxt.sys
[Scan path] c:\windows\system32\drivers\hsf_dp.sys
[Scan path] c:\windows\system32\drivers\hsfhwbs2.sys
[Scan path] c:\windows\system32\drivers\http.sys
[Scan path] c:\windows\system32\drivers\i8042prt.sys
[Scan path] c:\windows\system32\drivers\iastor.sys
[Scan path] c:\windows\system32\drivers\imapi.sys
[Scan path] c:\windows\system32\drivers\intelppm.sys
[Scan path] c:\windows\system32\drivers\ip6fw.sys
[Scan path] c:\windows\system32\drivers\ipfltdrv.sys
[Scan path] c:\windows\system32\drivers\ipinip.sys
[Scan path] c:\windows\system32\drivers\ipnat.sys
[Scan path] c:\windows\system32\drivers\ipsec.sys
[Scan path] c:\windows\system32\drivers\irenum.sys
[Scan path] c:\windows\system32\drivers\isapnp.sys
[Scan path] c:\windows\system32\drivers\kbdclass.sys
[Scan path] c:\windows\system32\drivers\kbdhid.sys
[Scan path] c:\windows\system32\drivers\kl1.sys
[Scan path] c:\windows\system32\drivers\klbg.sys
[Scan path] c:\windows\system32\drivers\klfltdev.sys
[Scan path] c:\windows\system32\drivers\klif.sys
[Scan path] c:\windows\system32\drivers\klim5.sys
[Scan path] c:\windows\system32\drivers\kmixer.sys
[Scan path] c:\windows\system32\drivers\ksecdd.sys
[Scan path] c:\windows\system32\drivers\mdmxsdk.sys
[Scan path] c:\windows\system32\drivers\mhndrv.sys
[Scan path] c:\windows\system32\drivers\mnmdd.sys
[Scan path] c:\windows\system32\drivers\modemcsa.sys
[Scan path] c:\windows\system32\drivers\mouclass.sys
[Scan path] c:\windows\system32\drivers\mouhid.sys
[Scan path] c:\windows\system32\drivers\mountmgr.sys
[Scan path] c:\windows\system32\drivers\mpe.sys
[Scan path] c:\windows\system32\drivers\mrxdav.sys
[Scan path] c:\windows\system32\drivers\mrxsmb.sys
[Scan path] c:\windows\system32\drivers\msfs.sys
[Scan path] c:\windows\system32\drivers\msgpc.sys
[Scan path] c:\windows\system32\drivers\mskssrv.sys
[Scan path] c:\windows\system32\drivers\mspclock.sys
[Scan path] c:\windows\system32\drivers\mspqm.sys
[Scan path] c:\windows\system32\drivers\mssmbios.sys
[Scan path] c:\windows\system32\drivers\mstee.sys
[Scan path] c:\windows\system32\drivers\mup.sys
[Scan path] c:\windows\system32\drivers\nabtsfec.sys
[Scan path] c:\windows\system32\drivers\ndis.sys
[Scan path] c:\windows\system32\drivers\ndisip.sys
[Scan path] c:\windows\system32\drivers\ndistapi.sys
[Scan path] c:\windows\system32\drivers\ndisuio.sys
[Scan path] c:\windows\system32\drivers\ndiswan.sys
[Scan path] c:\windows\system32\drivers\netbios.sys
[Scan path] c:\windows\system32\drivers\netbt.sys
[Scan path] c:\windows\system32\drivers\nic1394.sys
[Scan path] c:\windows\system32\drivers\npfs.sys
[Scan path] c:\windows\system32\drivers\null.sys
[Scan path] c:\windows\system32\drivers\nwlnkflt.sys
[Scan path] c:\windows\system32\drivers\nwlnkfwd.sys
[Scan path] c:\windows\system32\drivers\ohci1394.sys
[Scan path] c:\windows\system32\drivers\partmgr.sys
[Scan path] c:\windows\system32\drivers\pavboot.sys
[Scan path] c:\windows\system32\drivers\pci.sys
[Scan path] c:\windows\system32\drivers\pciide.sys
[Scan path] c:\windows\system32\drivers\psched.sys
[Scan path] c:\windows\system32\drivers\ptilink.sys
[Scan path] c:\windows\system32\drivers\pxhelp20.sys
[Scan path] c:\windows\system32\drivers\rasacd.sys
[Scan path] c:\windows\system32\drivers\rasl2tp.sys
[Scan path] c:\windows\system32\drivers\raspppoe.sys
[Scan path] c:\windows\system32\drivers\raspptp.sys
[Scan path] c:\windows\system32\drivers\raspti.sys
[Scan path] c:\windows\system32\drivers\rdbss.sys
[Scan path] c:\windows\system32\drivers\rdpcdd.sys
[Scan path] c:\windows\system32\drivers\rdpdr.sys
[Scan path] c:\windows\system32\drivers\rdpwd.sys
[Scan path] c:\windows\system32\drivers\redbook.sys
[Scan path] c:\windows\system32\drivers\scsiport.sys
[Scan path] c:\windows\system32\drivers\secdrv.sys
[Scan path] c:\windows\system32\drivers\sfloppy.sys
[Scan path] c:\windows\system32\drivers\slip.sys
[Scan path] c:\windows\system32\drivers\splitter.sys
[Scan path] c:\windows\system32\drivers\sr.sys
[Scan path] c:\windows\system32\drivers\srv.sys
[Scan path] c:\windows\system32\drivers\streamip.sys
[Scan path] c:\windows\system32\drivers\swenum.sys
[Scan path] c:\windows\system32\drivers\swmidi.sys
[Scan path] c:\windows\system32\drivers\sysaudio.sys
[Scan path] c:\windows\system32\drivers\tcpip.sys
[Scan path] c:\windows\system32\drivers\tdpipe.sys
[Scan path] c:\windows\system32\drivers\tdtcp.sys
[Scan path] c:\windows\system32\drivers\termdd.sys
[Scan path] c:\windows\system32\drivers\update.sys
[Scan path] c:\windows\system32\drivers\usbccgp.sys
[Scan path] c:\windows\system32\drivers\usbehci.sys
[Scan path] c:\windows\system32\drivers\usbhub.sys
[Scan path] c:\windows\system32\drivers\usbprint.sys
[Scan path] c:\windows\system32\drivers\usbscan.sys
[Scan path] c:\windows\system32\drivers\usbsermpt.sys
[Scan path] c:\windows\system32\drivers\usbstor.sys
[Scan path] c:\windows\system32\drivers\usbuhci.sys
[Scan path] c:\windows\system32\drivers\vga.sys
[Scan path] c:\windows\system32\drivers\volsnap.sys
[Scan path] c:\windows\system32\drivers\wanarp.sys
[Scan path] c:\windows\system32\drivers\wdmaud.sys
[Scan path] c:\windows\system32\drivers\ws2ifsl.sys
[Scan path] c:\windows\system32\drivers\wstcodec.sys
[Scan path] c:\windows\system32\drivers\wudfpf.sys
[Scan path] c:\windows\system32\drivers\wudfrd.sys
[Scan path] c:\windows\system32\dskquota.dll
[Scan path] c:\windows\system32\dskquoui.dll
[Scan path] c:\windows\system32\dsquery.dll
[Scan path] c:\windows\system32\dssec.dll
[Scan path] c:\windows\system32\dsuiext.dll
[Scan path] c:\windows\system32\eappcfg.dll
[Scan path] c:\windows\system32\eappprxy.dll
[Scan path] c:\windows\system32\eapsvc.dll
[Scan path] c:\windows\system32\ebpmon24.dll
[Scan path] c:\windows\system32\ersvc.dll
[Scan path] c:\windows\system32\es.dll
[Scan path] c:\windows\system32\esent.dll
[Scan path] c:\windows\system32\eventlog.dll
[Scan path] c:\windows\system32\extmgr.dll
[Scan path] c:\windows\system32\fdeploy.dll
[Scan path] c:\windows\system32\firewall.cpl
[Scan path] c:\windows\system32\fontext.dll
[Scan path] c:\windows\system32\gdi32.dll
[Scan path] c:\windows\system32\glu32.dll
[Scan path] c:\windows\system32\gptext.dll
[Scan path] c:\windows\system32\hhctrl.ocx
[Scan path] c:\windows\system32\hidserv.dll
[Scan path] c:\windows\system32\hnetcfg.dll
[Scan path] c:\windows\system32\hpzll4v2.dll
[Scan path] c:\windows\system32\hticons.dll
[Scan path] c:\windows\system32\iac25_32.ax
[Scan path] c:\windows\system32\iccvid.dll
[Scan path] c:\windows\system32\icmui.dll
[Scan path] c:\windows\system32\ie4uinit.exe
[Scan path] c:\windows\system32\iedkcs32.dll
[Scan path] c:\windows\system32\ieframe.dll
[Scan path] c:\windows\system32\iertutil.dll
[Scan path] c:\windows\system32\ieudinit.exe
[Scan path] c:\windows\system32\imaadp32.acm
[Scan path] c:\windows\system32\imagehlp.dll
[Scan path] c:\windows\system32\imapi.exe
[Scan path] c:\windows\system32\imm32.dll
[Scan path] c:\windows\system32\inetcomm.dll
[Scan path] c:\windows\system32\iphlpapi.dll
[Scan path] c:\windows\system32\ipnathlp.dll
[Scan path] c:\windows\system32\ir32_32.dll
[Scan path] c:\windows\system32\ir41_32.ax
[Scan path] c:\windows\system32\ir50_32.dll
[Scan path] c:\windows\system32\itss.dll
[Scan path] c:\windows\system32\iyuv_32.dll
[Scan path] c:\windows\system32\kerberos.dll
[Scan path] c:\windows\system32\kernel32.dll
[Scan path] c:\windows\system32\klogon.dll
[Scan path] c:\windows\system32\kmsvc.dll
[Scan path] c:\windows\system32\l3codeca.acm
[Scan path] c:\windows\system32\linkinfo.dll
[Scan path] c:\windows\system32\lmhsvc.dll
[Scan path] c:\windows\system32\localspl.dll
[Scan path] c:\windows\system32\locator.exe
[Scan path] c:\windows\system32\logon.scr
[Scan path] c:\windows\system32\logonui.exe
[Scan path] c:\windows\system32\lsasrv.dll
[Scan path] c:\windows\system32\lsass.exe
[Scan path] c:\windows\system32\lz32.dll
[Scan path] c:\windows\system32\macromed\flash\flash10b.ocx
[Scan path] c:\windows\system32\mdimon.dll
[Scan path] c:\windows\system32\mhn.dll
[Scan path] c:\windows\system32\midimap.dll
[Scan path] c:\windows\system32\mlang.dll
[Scan path] c:\windows\system32\mmcshext.dll
[Scan path] c:\windows\system32\mmsys.cpl
[Scan path] c:\windows\system32\mnmsrvc.exe
[Scan path] c:\windows\system32\mpr.dll
[Scan path] c:\windows\system32\mprdim.dll
[Scan path] c:\windows\system32\msacm32.dll
[Scan path] c:\windows\system32\msacm32.drv
[Scan path] c:\windows\system32\msadp32.acm
[Scan path] c:\windows\system32\msapsspc.dll
[Scan path] c:\windows\system32\msasn1.dll
[Scan path] c:\windows\system32\msaud32.acm
[Scan path] c:\windows\system32\mscoree.dll
[Scan path] c:\windows\system32\mscories.dll
[Scan path] c:\windows\system32\msctfime.ime
[Scan path] c:\windows\system32\msdtc.exe
[Scan path] c:\windows\system32\msfeedssync.exe
[Scan path] c:\windows\system32\msg711.acm
[Scan path] c:\windows\system32\msg723.acm
[Scan path] c:\windows\system32\msgina.dll
[Scan path] c:\windows\system32\msgsm32.acm
[Scan path] c:\windows\system32\msgsvc.dll
[Scan path] c:\windows\system32\msh261.drv
[Scan path] c:\windows\system32\msh263.drv
[Scan path] c:\windows\system32\mshtml.dll
[Scan path] c:\windows\system32\msi.dll
[Scan path] c:\windows\system32\msieftp.dll
[Scan path] c:\windows\system32\msiexec.exe
[Scan path] c:\windows\system32\msimg32.dll
[Scan path] c:\windows\system32\msnsspc.dll
[Scan path] c:\windows\system32\mspmsnsv.dll
[Scan path] c:\windows\system32\msprivs.dll
[Scan path] c:\windows\system32\msrle32.dll
[Scan path] c:\windows\system32\mstask.dll
[Scan path] c:\windows\system32\msv1_0.dll
[Scan path] c:\windows\system32\msvcp60.dll
[Scan path] c:\windows\system32\msvcrt.dll
[Scan path] c:\windows\system32\msvidc32.dll
[Scan path] c:\windows\system32\msvidctl.dll
[Scan path] c:\windows\system32\mswsock.dll
[Scan path] c:\windows\system32\msyuv.dll
[Scan path] c:\windows\system32\mydocs.dll
[Scan path] c:\windows\system32\ncobjapi.dll
[Scan path] c:\windows\system32\nddeapi.dll
[Scan path] c:\windows\system32\nerocheck.exe
[Scan path] c:\windows\system32\netapi32.dll
[Scan path] c:\windows\system32\netdde.exe
[Scan path] c:\windows\system32\netlogon.dll
[Scan path] c:\windows\system32\netman.dll
[Scan path] c:\windows\system32\netplwiz.dll
[Scan path] c:\windows\system32\netsetup.cpl
[Scan path] c:\windows\system32\netshell.dll
[Scan path] c:\windows\system32\normaliz.dll
[Scan path] c:\windows\system32\ntdll.dll
[Scan path] c:\windows\system32\ntdsapi.dll
[Scan path] c:\windows\system32\ntlanui2.dll
[Scan path] c:\windows\system32\ntmarta.dll
[Scan path] c:\windows\system32\ntmssvc.dll
[Scan path] c:\windows\system32\ntsd.exe
[Scan path] c:\windows\system32\ntshrui.dll
[Scan path] c:\windows\system32\occache.dll
[Scan path] c:\windows\system32\odbc32.dll
[Scan path] c:\windows\system32\odbcint.dll
[Scan path] c:\windows\system32\ole32.dll
[Scan path] c:\windows\system32\oleaut32.dll
[Scan path] c:\windows\system32\olecli32.dll
[Scan path] c:\windows\system32\olecnv32.dll
[Scan path] c:\windows\system32\olesvr32.dll
[Scan path] c:\windows\system32\olethk32.dll
[Scan path] c:\windows\system32\onex.dll
[Scan path] c:\windows\system32\opengl32.dll
[Scan path] c:\windows\system32\pclepim1.dll
[Scan path] c:\windows\system32\photowiz.dll
[Scan path] c:\windows\system32\pjlmon.dll
[Scan path] c:\windows\system32\powrprof.dll
[Scan path] c:\windows\system32\primomonnt.dll
[Scan path] c:\windows\system32\printui.dll
[Scan path] c:\windows\system32\profmap.dll
[Scan path] c:\windows\system32\psapi.dll
[Scan path] c:\windows\system32\psdrvcheck.exe
[Scan path] c:\windows\system32\pvmjpg21.dll
[Scan path] c:\windows\system32\qagentrt.dll
[Scan path] c:\windows\system32\qmgr.dll
[Scan path] c:\windows\system32\rasadhlp.dll
[Scan path] c:\windows\system32\rasauto.dll
[Scan path] c:\windows\system32\rasmans.dll
[Scan path] c:\windows\system32\regapi.dll
[Scan path] c:\windows\system32\regsvc.dll
[Scan path] c:\windows\system32\regsvr32.exe
[Scan path] c:\windows\system32\remotepg.dll
[Scan path] c:\windows\system32\rpcrt4.dll
[Scan path] c:\windows\system32\rpcss.dll
[Scan path] c:\windows\system32\rsaenh.dll
[Scan path] c:\windows\system32\rshx32.dll
[Scan path] c:\windows\system32\rsvp.exe
[Scan path] c:\windows\system32\rsvpsp.dll
[Scan path] c:\windows\system32\rtutils.dll
[Scan path] c:\windows\system32\rundll32.exe
[Scan path] c:\windows\system32\samlib.dll
[Scan path] c:\windows\system32\samsrv.dll
[Scan path] c:\windows\system32\scardsvr.exe
[Scan path] c:\windows\system32\scecli.dll
[Scan path] c:\windows\system32\scesrv.dll
[Scan path] c:\windows\system32\schannel.dll
[Scan path] c:\windows\system32\schedsvc.dll
[Scan path] c:\windows\system32\sclgntfy.dll
[Scan path] c:\windows\system32\seclogon.dll
[Scan path] c:\windows\system32\secur32.dll
[Scan path] c:\windows\system32\sendmail.dll
[Scan path] c:\windows\system32\sens.dll
[Scan path] c:\windows\system32\services.exe
[Scan path] c:\windows\system32\serwvdrv.dll
[Scan path] c:\windows\system32\sessmgr.exe
[Scan path] c:\windows\system32\setupapi.dll
[Scan path] c:\windows\system32\sfc.dll
[Scan path] c:\windows\system32\sfc_os.dll
[Scan path] c:\windows\system32\shdocvw.dll
[Scan path] c:\windows\system32\shell32.dll
[Scan path] c:\windows\system32\shimeng.dll
[Scan path] c:\windows\system32\shimgvw.dll
[Scan path] c:\windows\system32\shlwapi.dll
[Scan path] c:\windows\system32\shmedia.dll
[Scan path] c:\windows\system32\shmgrate.exe
[Scan path] c:\windows\system32\shscrap.dll
[Scan path] c:\windows\system32\shsvcs.dll
[Scan path] c:\windows\system32\sirenacm.dll
[Scan path] c:\windows\system32\sl_anet.acm
[Scan path] c:\windows\system32\slayerxp.dll
[Scan path] c:\windows\system32\smlogsvc.exe
[Scan path] c:\windows\system32\smss.exe
[Scan path] c:\windows\system32\spool\drivers\w32x86\3\e_s4i0f2.exe
[Scan path] c:\windows\system32\spoolsv.exe
[Scan path] c:\windows\system32\srsvc.dll
[Scan path] c:\windows\system32\srvsvc.dll
[Scan path] c:\windows\system32\ssdpsrv.dll
[Scan path] c:\windows\system32\stobject.dll
[Scan path] c:\windows\system32\svchost.exe
[Scan path] c:\windows\system32\sxs.dll
[Scan path] c:\windows\system32\syncui.dll
[Scan path] c:\windows\system32\tapisrv.dll
[Scan path] c:\windows\system32\tcpmon.dll
[Scan path] c:\windows\system32\termsrv.dll
[Scan path] c:\windows\system32\themeui.dll
[Scan path] c:\windows\system32\tlntsvr.exe
[Scan path] c:\windows\system32\trkwks.dll
[Scan path] c:\windows\system32\tsbyuv.dll
[Scan path] c:\windows\system32\tssoft32.acm
[Scan path] c:\windows\system32\twext.dll
[Scan path] c:\windows\system32\umpnpmgr.dll
[Scan path] c:\windows\system32\upnphost.dll
[Scan path] c:\windows\system32\ups.exe
[Scan path] c:\windows\system32\url.dll
[Scan path] c:\windows\system32\urlmon.dll
[Scan path] c:\windows\system32\usbmon.dll
[Scan path] c:\windows\system32\user32.dll
[Scan path] c:\windows\system32\userenv.dll
[Scan path] c:\windows\system32\userinit.exe
[Scan path] c:\windows\system32\uxtheme.dll
[Scan path] c:\windows\system32\version.dll
[Scan path] c:\windows\system32\vfwwdm32.dll
[Scan path] c:\windows\system32\vssapi.dll
[Scan path] c:\windows\system32\vssvc.exe
[Scan path] c:\windows\system32\w32time.dll
[Scan path] c:\windows\system32\w3ssl.dll
[Scan path] c:\windows\system32\wbem\esscli.dll
[Scan path] c:\windows\system32\wbem\fastprox.dll
[Scan path] c:\windows\system32\wbem\ncprov.dll
[Scan path] c:\windows\system32\wbem\repdrvfs.dll
[Scan path] c:\windows\system32\wbem\wbemcomn.dll
[Scan path] c:\windows\system32\wbem\wbemcons.dll
[Scan path] c:\windows\system32\wbem\wbemcore.dll
[Scan path] c:\windows\system32\wbem\wbemess.dll
[Scan path] c:\windows\system32\wbem\winmgmt.exe
[Scan path] c:\windows\system32\wbem\wmiapsrv.exe
[Scan path] c:\windows\system32\wbem\wmiprvsd.dll
[Scan path] c:\windows\system32\wbem\wmisvc.dll
[Scan path] c:\windows\system32\wbem\wmiutils.dll
[Scan path] c:\windows\system32\wdigest.dll
[Scan path] c:\windows\system32\wdmaud.drv
[Scan path] c:\windows\system32\webcheck.dll
[Scan path] c:\windows\system32\webclnt.dll
[Scan path] c:\windows\system32\wgalogon.dll
[Scan path] c:\windows\system32\wiascr.dll
[Scan path] c:\windows\system32\wiaservc.dll
[Scan path] c:\windows\system32\wiashext.dll
[Scan path] c:\windows\system32\wininet.dll
[Scan path] c:\windows\system32\winlogon.exe
[Scan path] c:\windows\system32\winmm.dll
[Scan path] c:\windows\system32\winrnr.dll
[Scan path] c:\windows\system32\winscard.dll
[Scan path] c:\windows\system32\winspool.drv
[Scan path] c:\windows\system32\winsrv.dll
[Scan path] c:\windows\system32\winsta.dll
[Scan path] c:\windows\system32\wintrust.dll
[Scan path] c:\windows\system32\wkssvc.dll
[Scan path] c:\windows\system32\wldap32.dll
[Scan path] c:\windows\system32\wlnotify.dll
[Scan path] c:\windows\system32\wmpshell.dll
[Scan path] c:\windows\system32\wpdshext.dll
[Scan path] c:\windows\system32\wpdshserviceobj.dll
[Scan path] c:\windows\system32\ws2_32.dll
[Scan path] c:\windows\system32\ws2help.dll
[Scan path] c:\windows\system32\wscsvc.dll
[Scan path] c:\windows\system32\wshext.dll
[Scan path] c:\windows\system32\wshtcpip.dll
[Scan path] c:\windows\system32\wtsapi32.dll
[Scan path] c:\windows\system32\wuaucpl.cpl
[Scan path] c:\windows\system32\wuauserv.dll
[Scan path] c:\windows\system32\wudfsvc.dll
[Scan path] c:\windows\system32\wzcsvc.dll
[Scan path] c:\windows\system32\xmlprov.dll
[Scan path] c:\windows\system32\xpsp2res.dll
[Scan path] c:\windows\system32\xpsshhdr.dll
[Scan path] c:\windows\system32\xvidvfw.dll
[Scan path] c:\windows\system32\zipfldr.dll
[Scan path] c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Scanned: 632
Infected: 2
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 0
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 3287 Kb/s
Scan time: 00:00:54
-----------------------------------------------------------------------------

c:\windows\system32\drivers\gasfkyrmuptnwm.sys - deleted

[Scan path] C:\WINDOWS\system32
C:\WINDOWS\system32\gasfkygvxexylk.dll infected with BackDoor.Tdss.based.1
C:\WINDOWS\system32\gasfkynohkftoi.dll infected with BackDoor.Tdss.based.1
C:\WINDOWS\system32\gasfkypfwkipuo.dll infected with BackDoor.Tdss.based.1
C:\WINDOWS\system32\gasfkyppbpfuma.dll infected with BackDoor.Tdss.based.1
C:\WINDOWS\system32\drivers\gasfkyrmuptnwm.sys infected with BackDoor.Tdss.based.1

[Scan path] C:\DOCUME~1\Louise\LOCALS~1\Temp
[Scan path] C:\Documents and Settings\Louise\My Documents
[Scan path] C:\WINDOWS\temp
[Scan path] C:\345334585
[Scan path] C:\aoqwlrag.exe
[Scan path] C:\AUTOEXEC.BAT
[Scan path] C:\Boot.bak
[Scan path] C:\boot.ini
[Scan path] C:\cmldr
[Scan path] C:\ComboFix.txt
[Scan path] C:\CONFIG.SYS
[Scan path] C:\cqfuy.exe
[Scan path] C:\ddqud.exe
[Scan path] C:\eopmjm.exe
[Scan path] C:\flqihkhx.exe
[Scan path] C:\hxlqib.exe
[Scan path] C:\IO.SYS
[Scan path] C:\mlhlsvq.exe
[Scan path] C:\MSDOS.SYS
[Scan path] C:\NeroBurnRightsInstaller.exe
[Scan path] C:\NTDETECT.COM
[Scan path] C:\ntldr
[Scan path] C:\pkusq.exe
[Scan path] C:\sqmdata00.sqm
[Scan path] C:\sqmdata01.sqm
[Scan path] C:\sqmdata02.sqm
[Scan path] C:\sqmdata03.sqm
[Scan path] C:\sqmdata04.sqm
[Scan path] C:\sqmdata05.sqm
[Scan path] C:\sqmdata06.sqm
[Scan path] C:\sqmdata07.sqm
[Scan path] C:\sqmdata08.sqm
[Scan path] C:\sqmnoopt00.sqm
[Scan path] C:\sqmnoopt01.sqm
[Scan path] C:\sqmnoopt02.sqm
[Scan path] C:\sqmnoopt03.sqm
[Scan path] C:\sqmnoopt04.sqm
[Scan path] C:\sqmnoopt05.sqm
[Scan path] C:\sqmnoopt06.sqm
[Scan path] C:\sqmnoopt07.sqm
[Scan path] C:\sqmnoopt08.sqm
[Scan path] C:\yhjj.exe
[Scan path] c:\documents and settings\administrator\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\all users\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\default user\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\louise\local settings\temp\hgu8ynfx.dll
[Scan path] c:\documents and settings\louise\start menu\programs\startup\desktop.ini
[Scan path] c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
[Scan path] c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
[Scan path] c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe
[Scan path] c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
[Scan path] c:\program files\apple software update\softwareupdate.exe
[Scan path] c:\program files\ati technologies\ati control panel\atiptaxx.exe
[Scan path] c:\program files\bonjour\mdnsnsp.dll
[Scan path] c:\program files\bonjour\mdnsresponder.exe
[Scan path] c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
[Scan path] c:\program files\common files\apple\mobile device support\bin\applesyncnotifier.exe
[Scan path] c:\program files\common files\doctor web\scanning engine\dwengine.exe
[Scan path] c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
[Scan path] c:\program files\common files\microsoft shared\source engine\ose.exe
[Scan path] c:\program files\common files\microsoft shared\speech\sapi.cpl
[Scan path] c:\program files\common files\microsoft shared\web components\11\owc11.dll
[Scan path] c:\program files\common files\microsoft shared\web folders\msonsext.dll
[Scan path] c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
[Scan path] c:\program files\common files\real\update_ob\realsched.exe
[Scan path] c:\program files\common files\system\ole db\oledb32.dll
[Scan path] c:\program files\creative\audiocs\ctaudcs.cpl
[Scan path] c:\program files\creative\creative zen nano plus\zen nano plus media explorer\ctmvnsu.dll
[Scan path] c:\program files\digiguide tv guide\client.exe
[Scan path] c:\program files\drweb\drweb32w.exe
[Scan path] c:\program files\drweb\drwebsp.dll
[Scan path] c:\program files\drweb\drwebupw.exe
[Scan path] c:\program files\drweb\drwsxtn.dll
[Scan path] c:\program files\drweb\spider.sys
[Scan path] c:\program files\drweb\spideragent.exe
[Scan path] c:\program files\drweb\spiderml.exe
[Scan path] c:\program files\drweb\spidernt.exe
[Scan path] c:\program files\drweb\spiderui.exe
[Scan path] c:\program files\google\common\google updater\googleupdaterservice.exe
[Scan path] c:\program files\google\google toolbar\component\fastsearch_b7c5ac242193bb3e.dll
[Scan path] c:\program files\google\google toolbar\googletoolbar_32.dll
[Scan path] c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
[Scan path] c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
[Scan path] c:\program files\hp\digital imaging\bin\hpqcxs08.dll
[Scan path] c:\program files\hp\digital imaging\bin\hpqddsvc.dll
[Scan path] c:\program files\hp\digital imaging\bin\hpqtra08.exe
[Scan path] c:\program files\hp\hp software update\hpwuschd2.exe
[Scan path] c:\program files\internet explorer\plugins\npdocbox.dll
[Scan path] c:\program files\ipod\bin\ipodservice.exe
[Scan path] c:\program files\itunes\ituneshelper.exe
[Scan path] c:\program files\itunes\itunesminiplayer.dll
[Scan path] c:\program files\java\jre6\bin\jp2ssv.dll
[Scan path] c:\program files\java\jre6\bin\jqs.exe
[Scan path] c:\program files\java\jre6\bin\jusched.exe
[Scan path] c:\program files\java\jre6\bin\npjpi160_11.dll
[Scan path] c:\program files\java\jre6\bin\ssv.dll
[Scan path] c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
[Scan path] c:\program files\java\jre6\lib\deploy\jqs\jqs.conf
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\adialhk.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\kloehk.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\mzvkbd.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\mzvkbd3.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\scieplgn.dll
[Scan path] c:\program files\lavasoft\ad-aware\aawservice.exe
[Scan path] c:\program files\lavasoft\ad-aware\ceapi.dll
[Scan path] c:\program files\lavasoft\ad-aware\pkarchive85u.dll
[Scan path] c:\program files\messenger\msmsgs.exe
[Scan path] c:\program files\microsoft office\office11\mlshext.dll
[Scan path] c:\program files\microsoft office\office11\msohev.dll
[Scan path] c:\program files\microsoft office\office11\olkfstub.dll
[Scan path] c:\program files\outlook express\setup50.exe
[Scan path] c:\program files\outlook express\wabfind.dll
[Scan path] c:\program files\quicktime\qtplugin.ocx
[Scan path] c:\program files\quicktime\qtsystem\quicktime.cpl
[Scan path] c:\program files\quicktime\qttask.exe
[Scan path] c:\program files\real\realplayer\rpbrowserrecordplugin.dll
[Scan path] c:\program files\real\realplayer\rpshell.dll
[Scan path] c:\program files\superantispyware\sasdifsv.sys
[Scan path] c:\program files\superantispyware\sasenum.sys
[Scan path] c:\program files\superantispyware\saskutil.sys
[Scan path] c:\program files\superantispyware\sasseh.dll
[Scan path] c:\program files\superantispyware\saswinlo.dll
[Scan path] c:\program files\windows live\installer\wlsetupsvc.exe
[Scan path] c:\program files\windows live\messenger\fsshext.8.5.1302.1018.dll
[Scan path] c:\program files\windows live\messenger\msgrapp.8.5.1302.1018.dll
[Scan path] c:\program files\windows live\messenger\msnmsgr.exe
[Scan path] c:\program files\windows live\messenger\usnsvc.exe
[Scan path] c:\program files\windows media player\wmpnetwk.exe
[Scan path] c:\program files\winrar\rarext.dll
[Scan path] c:\windows\apppatch\acadproc.dll
[Scan path] c:\windows\apppatch\acgenral.dll
[Scan path] c:\windows\cthelper.exe
[Scan path] c:\windows\downloaded program files\accounttracking.dll
[Scan path] c:\windows\downloaded program files\as2stubie.dll
[Scan path] c:\windows\downloaded program files\downloadmanagerv2.ocx
[Scan path] c:\windows\downloaded program files\facebookphotouploader.ocx
[Scan path] c:\windows\downloaded program files\game_uno1.dll
[Scan path] c:\windows\downloaded program files\imageuploader3.ocx
[Scan path] c:\windows\downloaded program files\imageuploader4.ocx
[Scan path] c:\windows\downloaded program files\imageuploader4_5.ocx
[Scan path] c:\windows\downloaded program files\messengerstatspaclient.dll
[Scan path] c:\windows\downloaded program files\photouploader5.ocx
[Scan path] c:\windows\downloaded program files\photouploader55.ocx
[Scan path] c:\windows\downloaded program files\snapfishactivia1000.ocx
[Scan path] c:\windows\downloaded program files\uploader_uni.ocx
[Scan path] c:\windows\ehome\ehrecvr.exe
[Scan path] c:\windows\ehome\ehsched.exe
[Scan path] c:\windows\ehome\ehtray.exe
[Scan path] c:\windows\ehome\mcrdsvc.exe
[Scan path] c:\windows\explorer.exe
[Scan path] c:\windows\inf\easycdblock.inf
[Scan path] c:\windows\inf\mcdftreg.inf
[Scan path] c:\windows\inf\msmsgs.inf
[Scan path] c:\windows\inf\msnetmtg.inf
[Scan path] c:\windows\inf\unregmp2.exe
[Scan path] c:\windows\inf\wmp11.inf
[Scan path] c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe
[Scan path] c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
[Scan path] c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe
[Scan path] c:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe
[Scan path] c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe
[Scan path] c:\windows\msagent\agentpsh.dll
[Scan path] c:\windows\network diagnostic\xpnetdiag.exe
[Scan path] c:\windows\pchealth\helpctr\binaries\pchsvc.dll
[Scan path] c:\windows\system32\advapi32.dll
[Scan path] c:\windows\system32\advpack.dll
[Scan path] c:\windows\system32\alg.exe
[Scan path] c:\windows\system32\alrsvc.dll
[Scan path] c:\windows\system32\apphelp.dll
[Scan path] c:\windows\system32\appmgmts.dll
[Scan path] c:\windows\system32\appwiz.cpl
[Scan path] c:\windows\system32\ati2evxx.exe
[Scan path] c:\windows\system32\ati2sgag.exe
[Scan path] c:\windows\system32\atl.dll
[Scan path] c:\windows\system32\audiodev.dll
[Scan path] c:\windows\system32\audiosrv.dll
[Scan path] c:\windows\system32\authz.dll
[Scan path] c:\windows\system32\autochk.exe
[Scan path] c:\windows\system32\basesrv.dll
[Scan path] c:\windows\system32\browser.dll
[Scan path] c:\windows\system32\browseui.dll
[Scan path] c:\windows\system32\cabview.dll
[Scan path] c:\windows\system32\certcli.dll
[Scan path] c:\windows\system32\cisvc.exe
[Scan path] c:\windows\system32\clbcatq.dll
[Scan path] c:\windows\system32\clipsrv.exe
[Scan path] c:\windows\system32\cnbjmon.dll
[Scan path] c:\windows\system32\comctl32.dll
[Scan path] c:\windows\system32\comdlg32.dll
[Scan path] c:\windows\system32\comres.dll
[Scan path] c:\windows\system32\config\systemprofile\start menu\programs\startup\desktop.ini
[Scan path] c:\windows\system32\credui.dll
[Scan path] c:\windows\system32\crypt32.dll
[Scan path] c:\windows\system32\cryptdll.dll
[Scan path] c:\windows\system32\cryptext.dll
[Scan path] c:\windows\system32\cryptnet.dll
[Scan path] c:\windows\system32\cryptsvc.dll
[Scan path] c:\windows\system32\cryptui.dll
[Scan path] c:\windows\system32\cscdll.dll
[Scan path] c:\windows\system32\cscui.dll
[Scan path] c:\windows\system32\csrsrv.dll
[Scan path] c:\windows\system32\csrss.exe
[Scan path] c:\windows\system32\ctfmon.exe
[Scan path] c:\windows\system32\ctsvccda.exe
[Scan path] c:\windows\system32\ctxfihlp.exe
[Scan path] c:\windows\system32\davclnt.dll
[Scan path] c:\windows\system32\dciman32.dll
[Scan path] c:\windows\system32\ddraw.dll
[Scan path] c:\windows\system32\deskadp.dll
[Scan path] c:\windows\system32\deskmon.dll
[Scan path] c:\windows\system32\deskperf.dll
[Scan path] c:\windows\system32\dfshim.dll
[Scan path] c:\windows\system32\dfsshlex.dll
[Scan path] c:\windows\system32\dhcpcsvc.dll
[Scan path] c:\windows\system32\digest.dll
[Scan path] c:\windows\system32\dimsntfy.dll
[Scan path] c:\windows\system32\diskcopy.dll
[Scan path] c:\windows\system32\dllhost.exe
[Scan path] c:\windows\system32\dmadmin.exe
[Scan path] c:\windows\system32\dmserver.dll
[Scan path] c:\windows\system32\dnsapi.dll
[Scan path] c:\windows\system32\dnsrslvr.dll
[Scan path] c:\windows\system32\docprop.dll
[Scan path] c:\windows\system32\docprop2.dll
[Scan path] c:\windows\system32\dot3api.dll
[Scan path] c:\windows\system32\dot3dlg.dll
[Scan path] c:\windows\system32\dot3gpclnt.dll
[Scan path] c:\windows\system32\dot3svc.dll
[Scan path] c:\windows\system32\drivers\acpi.sys
[Scan path] c:\windows\system32\drivers\aec.sys
[Scan path] c:\windows\system32\drivers\afd.sys
[Scan path] c:\windows\system32\drivers\arp1394.sys
[Scan path] c:\windows\system32\drivers\asapiw2k.sys
[Scan path] c:\windows\system32\drivers\asyncmac.sys
[Scan path] c:\windows\system32\drivers\atapi.sys
[Scan path] c:\windows\system32\drivers\ati2mtag.sys
[Scan path] c:\windows\system32\drivers\atmarpc.sys
[Scan path] c:\windows\system32\drivers\audstub.sys
[Scan path] c:\windows\system32\drivers\avera800.sys
[Scan path] c:\windows\system32\drivers\beep.sys
[Scan path] c:\windows\system32\drivers\ccdecode.sys
[Scan path] c:\windows\system32\drivers\cdaudio.sys
[Scan path] c:\windows\system32\drivers\cdrom.sys
[Scan path] c:\windows\system32\drivers\cercsr6.sys
[Scan path] c:\windows\system32\drivers\ctac32k.sys
[Scan path] c:\windows\system32\drivers\ctaud2k.sys
[Scan path] c:\windows\system32\drivers\ctdvda2k.sys
[Scan path] c:\windows\system32\drivers\ctoss2k.sys
[Scan path] c:\windows\system32\drivers\ctprxy2k.sys
[Scan path] c:\windows\system32\drivers\ctsfm2k.sys
[Scan path] c:\windows\system32\drivers\disk.sys
[Scan path] c:\windows\system32\drivers\dmboot.sys
[Scan path] c:\windows\system32\drivers\dmio.sys
[Scan path] c:\windows\system32\drivers\dmload.sys
[Scan path] c:\windows\system32\drivers\dmusic.sys
[Scan path] c:\windows\system32\drivers\drmkaud.sys
[Scan path] c:\windows\system32\drivers\dwprot.sys
[Scan path] c:\windows\system32\drivers\dwshd.sys
[Scan path] c:\windows\system32\drivers\e1e5132.sys
[Scan path] c:\windows\system32\drivers\emupia2k.sys
[Scan path] c:\windows\system32\drivers\fdc.sys
[Scan path] c:\windows\system32\drivers\fips.sys
[Scan path] c:\windows\system32\drivers\flpydisk.sys
[Scan path] c:\windows\system32\drivers\fltmgr.sys
[Scan path] c:\windows\system32\drivers\fs_rec.sys
[Scan path] c:\windows\system32\drivers\ftdisk.sys
[Scan path] c:\windows\system32\drivers\gearaspiwdm.sys
[Scan path] c:\windows\system32\drivers\ha20x2k.sys
[Scan path] c:\windows\system32\drivers\hidusb.sys
[Scan path] c:\windows\system32\drivers\hsf_cnxt.sys
[Scan path] c:\windows\system32\drivers\hsf_dp.sys
[Scan path] c:\windows\system32\drivers\hsfhwbs2.sys
[Scan path] c:\windows\system32\drivers\http.sys
[Scan path] c:\windows\system32\drivers\i8042prt.sys
[Scan path] c:\windows\system32\drivers\iastor.sys
[Scan path] c:\windows\system32\drivers\imapi.sys
[Scan path] c:\windows\system32\drivers\intelppm.sys
[Scan path] c:\windows\system32\drivers\ip6fw.sys
[Scan path] c:\windows\system32\drivers\ipfltdrv.sys
[Scan path] c:\windows\system32\drivers\ipinip.sys
[Scan path] c:\windows\system32\drivers\ipnat.sys
[Scan path] c:\windows\system32\drivers\ipsec.sys
[Scan path] c:\windows\system32\drivers\irenum.sys
[Scan path] c:\windows\system32\drivers\isapnp.sys
[Scan path] c:\windows\system32\drivers\kbdclass.sys
[Scan path] c:\windows\system32\drivers\kbdhid.sys
[Scan path] c:\windows\system32\drivers\kl1.sys
[Scan path] c:\windows\system32\drivers\klbg.sys
[Scan path] c:\windows\system32\drivers\klfltdev.sys
[Scan path] c:\windows\system32\drivers\klif.sys
[Scan path] c:\windows\system32\drivers\klim5.sys
[Scan path] c:\windows\system32\drivers\kmixer.sys
[Scan path] c:\windows\system32\drivers\ksecdd.sys
[Scan path] c:\windows\system32\drivers\mdmxsdk.sys
[Scan path] c:\windows\system32\drivers\mhndrv.sys
[Scan path] c:\windows\system32\drivers\mnmdd.sys
[Scan path] c:\windows\system32\drivers\modemcsa.sys
[Scan path] c:\windows\system32\drivers\mouclass.sys
[Scan path] c:\windows\system32\drivers\mouhid.sys
[Scan path] c:\windows\system32\drivers\mountmgr.sys
[Scan path] c:\windows\system32\drivers\mpe.sys
[Scan path] c:\windows\system32\drivers\mrxdav.sys
[Scan path] c:\windows\system32\drivers\mrxsmb.sys
[Scan path] c:\windows\system32\drivers\msfs.sys
[Scan path] c:\windows\system32\drivers\msgpc.sys
[Scan path] c:\windows\system32\drivers\mskssrv.sys
[Scan path] c:\windows\system32\drivers\mspclock.sys
[Scan path] c:\windows\system32\drivers\mspqm.sys
[Scan path] c:\windows\system32\drivers\mssmbios.sys
[Scan path] c:\windows\system32\drivers\mstee.sys
[Scan path] c:\windows\system32\drivers\mup.sys
[Scan path] c:\windows\system32\drivers\nabtsfec.sys
[Scan path] c:\windows\system32\drivers\ndis.sys
[Scan path] c:\windows\system32\drivers\ndisip.sys
[Scan path] c:\windows\system32\drivers\ndistapi.sys
[Scan path] c:\windows\system32\drivers\ndisuio.sys
[Scan path] c:\windows\system32\drivers\ndiswan.sys
[Scan path] c:\windows\system32\drivers\netbios.sys
[Scan path] c:\windows\system32\drivers\netbt.sys
[Scan path] c:\windows\system32\drivers\nic1394.sys
[Scan path] c:\windows\system32\drivers\npfs.sys
[Scan path] c:\windows\system32\drivers\null.sys
[Scan path] c:\windows\system32\drivers\nwlnkflt.sys
[Scan path] c:\windows\system32\drivers\nwlnkfwd.sys
[Scan path] c:\windows\system32\drivers\ohci1394.sys
[Scan path] c:\windows\system32\drivers\partmgr.sys
[Scan path] c:\windows\system32\drivers\pavboot.sys
[Scan path] c:\windows\system32\drivers\pci.sys
[Scan path] c:\windows\system32\drivers\pciide.sys
[Scan path] c:\windows\system32\drivers\psched.sys
[Scan path] c:\windows\system32\drivers\ptilink.sys
[Scan path] c:\windows\system32\drivers\pxhelp20.sys
[Scan path] c:\windows\system32\drivers\rasacd.sys
[Scan path] c:\windows\system32\drivers\rasl2tp.sys
[Scan path] c:\windows\system32\drivers\raspppoe.sys
[Scan path] c:\windows\system32\drivers\raspptp.sys
[Scan path] c:\windows\system32\drivers\raspti.sys
[Scan path] c:\windows\system32\drivers\rdbss.sys
[Scan path] c:\windows\system32\drivers\rdpcdd.sys
[Scan path] c:\windows\system32\drivers\rdpdr.sys
[Scan path] c:\windows\system32\drivers\rdpwd.sys
[Scan path] c:\windows\system32\drivers\redbook.sys
[Scan path] c:\windows\system32\drivers\scsiport.sys
[Scan path] c:\windows\system32\drivers\secdrv.sys
[Scan path] c:\windows\system32\drivers\sfloppy.sys
[Scan path] c:\windows\system32\drivers\slip.sys
[Scan path] c:\windows\system32\drivers\splitter.sys
[Scan path] c:\windows\system32\drivers\sr.sys
[Scan path] c:\windows\system32\drivers\srv.sys
[Scan path] c:\windows\system32\drivers\streamip.sys
[Scan path] c:\windows\system32\drivers\swenum.sys
[Scan path] c:\windows\system32\drivers\swmidi.sys
[Scan path] c:\windows\system32\drivers\sysaudio.sys
[Scan path] c:\windows\system32\drivers\tcpip.sys
[Scan path] c:\windows\system32\drivers\tdpipe.sys
[Scan path] c:\windows\system32\drivers\tdtcp.sys
[Scan path] c:\windows\system32\drivers\termdd.sys
[Scan path] c:\windows\system32\drivers\update.sys
[Scan path] c:\windows\system32\drivers\usbccgp.sys
[Scan path] c:\windows\system32\drivers\usbehci.sys
[Scan path] c:\windows\system32\drivers\usbhub.sys
[Scan path] c:\windows\system32\drivers\usbprint.sys
[Scan path] c:\windows\system32\drivers\usbscan.sys
[Scan path] c:\windows\system32\drivers\usbsermpt.sys
[Scan path] c:\windows\system32\drivers\usbstor.sys
[Scan path] c:\windows\system32\drivers\usbuhci.sys
[Scan path] c:\windows\system32\drivers\vga.sys
[Scan path] c:\windows\system32\drivers\volsnap.sys
[Scan path] c:\windows\system32\drivers\wanarp.sys
[Scan path] c:\windows\system32\drivers\wdmaud.sys
[Scan path] c:\windows\system32\drivers\ws2ifsl.sys
[Scan path] c:\windows\system32\drivers\wstcodec.sys
[Scan path] c:\windows\system32\drivers\wudfpf.sys
[Scan path] c:\windows\system32\drivers\wudfrd.sys
[Scan path] c:\windows\system32\drprov.dll
[Scan path] c:\windows\system32\dskquota.dll
[Scan path] c:\windows\system32\dskquoui.dll
[Scan path] c:\windows\system32\dsquery.dll
[Scan path] c:\windows\system32\dssec.dll
[Scan path] c:\windows\system32\dsuiext.dll
[Scan path] c:\windows\system32\eappcfg.dll
[Scan path] c:\windows\system32\eappprxy.dll
[Scan path] c:\windows\system32\eapsvc.dll
[Scan path] c:\windows\system32\ebpmon24.dll
[Scan path] c:\windows\system32\ersvc.dll
[Scan path] c:\windows\system32\es.dll
[Scan path] c:\windows\system32\esent.dll
[Scan path] c:\windows\system32\eventlog.dll
[Scan path] c:\windows\system32\extmgr.dll
[Scan path] c:\windows\system32\fdeploy.dll
[Scan path] c:\windows\system32\firewall.cpl
[Scan path] c:\windows\system32\fontext.dll
[Scan path] c:\windows\system32\gdi32.dll
[Scan path] c:\windows\system32\glu32.dll
[Scan path] c:\windows\system32\gptext.dll
[Scan path] c:\windows\system32\hhctrl.ocx
[Scan path] c:\windows\system32\hidserv.dll
[Scan path] c:\windows\system32\hnetcfg.dll
[Scan path] c:\windows\system32\hpzll4v2.dll
[Scan path] c:\windows\system32\hticons.dll
[Scan path] c:\windows\system32\iac25_32.ax
[Scan path] c:\windows\system32\iccvid.dll
[Scan path] c:\windows\system32\icmui.dll
[Scan path] c:\windows\system32\ie4uinit.exe
[Scan path] c:\windows\system32\iedkcs32.dll
[Scan path] c:\windows\system32\ieframe.dll
[Scan path] c:\windows\system32\iertutil.dll
[Scan path] c:\windows\system32\ieudinit.exe
[Scan path] c:\windows\system32\imaadp32.acm
[Scan path] c:\windows\system32\imagehlp.dll
[Scan path] c:\windows\system32\imapi.exe
[Scan path] c:\windows\system32\imm32.dll
[Scan path] c:\windows\system32\inetcomm.dll
[Scan path] c:\windows\system32\iphlpapi.dll
[Scan path] c:\windows\system32\ipnathlp.dll
[Scan path] c:\windows\system32\ir32_32.dll
[Scan path] c:\windows\system32\ir41_32.ax
[Scan path] c:\windows\system32\ir50_32.dll
[Scan path] c:\windows\system32\itss.dll
[Scan path] c:\windows\system32\iyuv_32.dll
[Scan path] c:\windows\system32\kerberos.dll
[Scan path] c:\windows\system32\kernel32.dll
[Scan path] c:\windows\system32\klogon.dll
[Scan path] c:\windows\system32\kmsvc.dll
[Scan path] c:\windows\system32\l3codeca.acm
[Scan path] c:\windows\system32\linkinfo.dll
[Scan path] c:\windows\system32\lmhsvc.dll
[Scan path] c:\windows\system32\localspl.dll
[Scan path] c:\windows\system32\locator.exe
[Scan path] c:\windows\system32\logon.scr
[Scan path] c:\windows\system32\logonui.exe
[Scan path] c:\windows\system32\lsasrv.dll
[Scan path] c:\windows\system32\lsass.exe
[Scan path] c:\windows\system32\lz32.dll
[Scan path] c:\windows\system32\macromed\flash\flash10b.ocx
[Scan path] c:\windows\system32\mdimon.dll
[Scan path] c:\windows\system32\mhn.dll
[Scan path] c:\windows\system32\midimap.dll
[Scan path] c:\windows\system32\mlang.dll
[Scan path] c:\windows\system32\mmcshext.dll
[Scan path] c:\windows\system32\mmsys.cpl
[Scan path] c:\windows\system32\mnmsrvc.exe
[Scan path] c:\windows\system32\mpr.dll
[Scan path] c:\windows\system32\mprdim.dll
[Scan path] c:\windows\system32\msacm32.dll
[Scan path] c:\windows\system32\msacm32.drv
[Scan path] c:\windows\system32\msadp32.acm
[Scan path] c:\windows\system32\msapsspc.dll
[Scan path] c:\windows\system32\msasn1.dll
[Scan path] c:\windows\system32\msaud32.acm
[Scan path] c:\windows\system32\mscoree.dll
[Scan path] c:\windows\system32\mscories.dll
[Scan path] c:\windows\system32\msctfime.ime
[Scan path] c:\windows\system32\msdtc.exe
[Scan path] c:\windows\system32\msfeedssync.exe
[Scan path] c:\windows\system32\msg711.acm
[Scan path] c:\windows\system32\msg723.acm
[Scan path] c:\windows\system32\msgina.dll
[Scan path] c:\windows\system32\msgsm32.acm
[Scan path] c:\windows\system32\msgsvc.dll
[Scan path] c:\windows\system32\msh261.drv
[Scan path] c:\windows\system32\msh263.drv
[Scan path] c:\windows\system32\mshtml.dll
[Scan path] c:\windows\system32\msi.dll
[Scan path] c:\windows\system32\msieftp.dll
[Scan path] c:\windows\system32\msiexec.exe
[Scan path] c:\windows\system32\msimg32.dll
[Scan path] c:\windows\system32\msnsspc.dll
[Scan path] c:\windows\system32\mspmsnsv.dll
[Scan path] c:\windows\system32\msprivs.dll
[Scan path] c:\windows\system32\msrle32.dll
[Scan path] c:\windows\system32\mstask.dll
[Scan path] c:\windows\system32\msv1_0.dll
[Scan path] c:\windows\system32\msvcp60.dll
[Scan path] c:\windows\system32\msvcrt.dll
[Scan path] c:\windows\system32\msvidc32.dll
[Scan path] c:\windows\system32\msvidctl.dll
[Scan path] c:\windows\system32\mswsock.dll
[Scan path] c:\windows\system32\msyuv.dll
[Scan path] c:\windows\system32\mydocs.dll
[Scan path] c:\windows\system32\ncobjapi.dll
[Scan path] c:\windows\system32\nddeapi.dll
[Scan path] c:\windows\system32\nerocheck.exe
[Scan path] c:\windows\system32\netapi32.dll
[Scan path] c:\windows\system32\netdde.exe
[Scan path] c:\windows\system32\netlogon.dll
[Scan path] c:\windows\system32\netman.dll
[Scan path] c:\windows\system32\netplwiz.dll
[Scan path] c:\windows\system32\netrap.dll
[Scan path] c:\windows\system32\netsetup.cpl
[Scan path] c:\windows\system32\netshell.dll
[Scan path] c:\windows\system32\netui0.dll
[Scan path] c:\windows\system32\netui1.dll
[Scan path] c:\windows\system32\normaliz.dll
[Scan path] c:\windows\system32\ntdll.dll
[Scan path] c:\windows\system32\ntdsapi.dll
[Scan path] c:\windows\system32\ntlanman.dll
[Scan path] c:\windows\system32\ntlanui2.dll
[Scan path] c:\windows\system32\ntmarta.dll
[Scan path] c:\windows\system32\ntmssvc.dll
[Scan path] c:\windows\system32\ntsd.exe
[Scan path] c:\windows\system32\ntshrui.dll
[Scan path] c:\windows\system32\occache.dll
[Scan path] c:\windows\system32\odbc32.dll
[Scan path] c:\windows\system32\odbcint.dll
[Scan path] c:\windows\system32\ole32.dll
[Scan path] c:\windows\system32\oleaut32.dll
[Scan path] c:\windows\system32\olecli32.dll
[Scan path] c:\windows\system32\olecnv32.dll
[Scan path] c:\windows\system32\olesvr32.dll
[Scan path] c:\windows\system32\olethk32.dll
[Scan path] c:\windows\system32\onex.dll
[Scan path] c:\windows\system32\opengl32.dll
[Scan path] c:\windows\system32\pclepim1.dll
[Scan path] c:\windows\system32\photowiz.dll
[Scan path] c:\windows\system32\pjlmon.dll
[Scan path] c:\windows\system32\powrprof.dll
[Scan path] c:\windows\system32\primomonnt.dll
[Scan path] c:\windows\system32\printui.dll
[Scan path] c:\windows\system32\profmap.dll
[Scan path] c:\windows\system32\psapi.dll
[Scan path] c:\windows\system32\psdrvcheck.exe
[Scan path] c:\windows\system32\pvmjpg21.dll
[Scan path] c:\windows\system32\qagentrt.dll
[Scan path] c:\windows\system32\qmgr.dll
[Scan path] c:\windows\system32\rasadhlp.dll
[Scan path] c:\windows\system32\rasauto.dll
[Scan path] c:\windows\system32\rasmans.dll
[Scan path] c:\windows\system32\regapi.dll
[Scan path] c:\windows\system32\regsvc.dll
[Scan path] c:\windows\system32\regsvr32.exe
[Scan path] c:\windows\system32\remotepg.dll
[Scan path] c:\windows\system32\rpcrt4.dll
[Scan path] c:\windows\system32\rpcss.dll
[Scan path] c:\windows\system32\rsaenh.dll
[Scan path] c:\windows\system32\rshx32.dll
[Scan path] c:\windows\system32\rsvp.exe
[Scan path] c:\windows\system32\rsvpsp.dll
[Scan path] c:\windows\system32\rtutils.dll
[Scan path] c:\windows\system32\rundll32.exe
[Scan path] c:\windows\system32\samlib.dll
[Scan path] c:\windows\system32\samsrv.dll
[Scan path] c:\windows\system32\scardsvr.exe
[Scan path] c:\windows\system32\scecli.dll
[Scan path] c:\windows\system32\scesrv.dll
[Scan path] c:\windows\system32\schannel.dll
[Scan path] c:\windows\system32\schedsvc.dll
[Scan path] c:\windows\system32\sclgntfy.dll
[Scan path] c:\windows\system32\seclogon.dll
[Scan path] c:\windows\system32\secur32.dll
[Scan path] c:\windows\system32\sendmail.dll
[Scan path] c:\windows\system32\sens.dll
[Scan path] c:\windows\system32\services.exe
[Scan path] c:\windows\system32\serwvdrv.dll
[Scan path] c:\windows\system32\sessmgr.exe
[Scan path] c:\windows\system32\setupapi.dll
[Scan path] c:\windows\system32\sfc.dll
[Scan path] c:\windows\system32\sfc_os.dll
[Scan path] c:\windows\system32\shdocvw.dll
[Scan path] c:\windows\system32\shell32.dll
[Scan path] c:\windows\system32\shimeng.dll
[Scan path] c:\windows\system32\shimgvw.dll
[Scan path] c:\windows\system32\shlwapi.dll
[Scan path] c:\windows\system32\shmedia.dll
[Scan path] c:\windows\system32\shmgrate.exe
[Scan path] c:\windows\system32\shscrap.dll
[Scan path] c:\windows\system32\shsvcs.dll
[Scan path] c:\windows\system32\sirenacm.dll
[Scan path] c:\windows\system32\sl_anet.acm
[Scan path] c:\windows\system32\slayerxp.dll
[Scan path] c:\windows\system32\smlogsvc.exe
[Scan path] c:\windows\system32\smss.exe
[Scan path] c:\windows\system32\spool\drivers\w32x86\3\e_s4i0f2.exe
[Scan path] c:\windows\system32\spoolsv.exe
[Scan path] c:\windows\system32\srsvc.dll
[Scan path] c:\windows\system32\srvsvc.dll
[Scan path] c:\windows\system32\ssdpsrv.dll
[Scan path] c:\windows\system32\stobject.dll
[Scan path] c:\windows\system32\svchost.exe
[Scan path] c:\windows\system32\sxs.dll
[Scan path] c:\windows\system32\syncui.dll
[Scan path] c:\windows\system32\tapisrv.dll
[Scan path] c:\windows\system32\tcpmon.dll
[Scan path] c:\windows\system32\termsrv.dll
[Scan path] c:\windows\system32\themeui.dll
[Scan path] c:\windows\system32\tlntsvr.exe
[Scan path] c:\windows\system32\trkwks.dll
[Scan path] c:\windows\system32\tsbyuv.dll
[Scan path] c:\windows\system32\tssoft32.acm
[Scan path] c:\windows\system32\twext.dll
[Scan path] c:\windows\system32\umpnpmgr.dll
[Scan path] c:\windows\system32\upnphost.dll
[Scan path] c:\windows\system32\ups.exe
[Scan path] c:\windows\system32\url.dll
[Scan path] c:\windows\system32\urlmon.dll
[Scan path] c:\windows\system32\usbmon.dll
[Scan path] c:\windows\system32\user32.dll
[Scan path] c:\windows\system32\userenv.dll
[Scan path] c:\windows\system32\userinit.exe
[Scan path] c:\windows\system32\uxtheme.dll
[Scan path] c:\windows\system32\version.dll
[Scan path] c:\windows\system32\vfwwdm32.dll
[Scan path] c:\windows\system32\vssapi.dll
[Scan path] c:\windows\system32\vssvc.exe
[Scan path] c:\windows\system32\w32time.dll
[Scan path] c:\windows\system32\w3ssl.dll
[Scan path] c:\windows\system32\wbem\esscli.dll
[Scan path] c:\windows\system32\wbem\fastprox.dll
[Scan path] c:\windows\system32\wbem\ncprov.dll
[Scan path] c:\windows\system32\wbem\repdrvfs.dll
[Scan path] c:\windows\system32\wbem\wbemcomn.dll
[Scan path] c:\windows\system32\wbem\wbemcore.dll
[Scan path] c:\windows\system32\wbem\wbemess.dll
[Scan path] c:\windows\system32\wbem\winmgmt.exe
[Scan path] c:\windows\system32\wbem\wmiapsrv.exe
[Scan path] c:\windows\system32\wbem\wmiprvsd.dll
[Scan path] c:\windows\system32\wbem\wmisvc.dll
[Scan path] c:\windows\system32\wbem\wmiutils.dll
[Scan path] c:\windows\system32\wdigest.dll
[Scan path] c:\windows\system32\wdmaud.drv
[Scan path] c:\windows\system32\webcheck.dll
[Scan path] c:\windows\system32\webclnt.dll
[Scan path] c:\windows\system32\wgalogon.dll
[Scan path] c:\windows\system32\wiascr.dll
[Scan path] c:\windows\system32\wiaservc.dll
[Scan path] c:\windows\system32\wiashext.dll
[Scan path] c:\windows\system32\wininet.dll
[Scan path] c:\windows\system32\winlogon.exe
[Scan path] c:\windows\system32\winmm.dll
[Scan path] c:\windows\system32\winrnr.dll
[Scan path] c:\windows\system32\winscard.dll
[Scan path] c:\windows\system32\winspool.drv
[Scan path] c:\windows\system32\winsrv.dll
[Scan path] c:\windows\system32\winsta.dll
[Scan path] c:\windows\system32\wintrust.dll
[Scan path] c:\windows\system32\wkssvc.dll
[Scan path] c:\windows\system32\wldap32.dll
[Scan path] c:\windows\system32\wlnotify.dll
[Scan path] c:\windows\system32\wmpshell.dll
[Scan path] c:\windows\system32\wpdshext.dll
[Scan path] c:\windows\system32\wpdshserviceobj.dll
[Scan path] c:\windows\system32\ws2_32.dll
[Scan path] c:\windows\system32\ws2help.dll
[Scan path] c:\windows\system32\wscsvc.dll
[Scan path] c:\windows\system32\wshext.dll
[Scan path] c:\windows\system32\wshtcpip.dll
[Scan path] c:\windows\system32\wtsapi32.dll
[Scan path] c:\windows\system32\wuaucpl.cpl
[Scan path] c:\windows\system32\wuauserv.dll
[Scan path] c:\windows\system32\wudfsvc.dll
[Scan path] c:\windows\system32\wzcsvc.dll
[Scan path] c:\windows\system32\xmlprov.dll
[Scan path] c:\windows\system32\xpsp2res.dll
[Scan path] c:\windows\system32\xpsshhdr.dll
[Scan path] c:\windows\system32\xvidvfw.dll
[Scan path] c:\windows\system32\zipfldr.dll
[Scan path] c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Scanned: 43698
Infected: 5
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 0
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 1618 Kb/s
Scan time: 00:34:02
-----------------------------------------------------------------------------

C:\WINDOWS\system32\gasfkygvxexylk.dll - deleted
C:\WINDOWS\system32\gasfkynohkftoi.dll - deleted
C:\WINDOWS\system32\gasfkypfwkipuo.dll - deleted
C:\WINDOWS\system32\gasfkyppbpfuma.dll - deleted
C:\WINDOWS\system32\drivers\gasfkyrmuptnwm.sys - deleted

[Scan path] C:\
-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Scanned: 71069
Infected: 0
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 0
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 1982 Kb/s
Scan time: 00:31:48
-----------------------------------------------------------------------------

Scanning interrupted by user! - no viruses found
=============================================================================
Total session statistics
=============================================================================
Scanned: 115399
Infected: 7
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 6
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 776 Kb/s
Scan time: 01:05:53
=============================================================================

=============================================================================
Dr.Web Scanner for Windows v5.00.7 (5.00.7.09210)
© Doctor Web, Ltd., 1992-2009
Log generated on: 2009-10-20, 22:06:47 [LOUISESMAIN][Louise]
Command line: "C:\Program Files\DrWeb\DrWeb32w.exe"
Operating system: Windows XP Professional x86 (Build 2600), Service Pack 3
=============================================================================
DwShield doesn't load
Engine version: 5.00 (5.00.0.12182)
Engine API version: 2.02
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwtoday.vdb - 11444 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50047.vdb - 12425 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50046.vdb - 4903 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50045.vdb - 3476 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50044.vdb - 8537 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50043.vdb - 5741 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50042.vdb - 4308 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50041.vdb - 5456 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50040.vdb - 6848 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50039.vdb - 5479 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50038.vdb - 8526 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50037.vdb - 7640 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50036.vdb - 6071 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50035.vdb - 4983 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50034.vdb - 2139 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50033.vdb - 3732 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50032.vdb - 6424 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50031.vdb - 5242 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50030.vdb - 2770 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50029.vdb - 2685 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50028.vdb - 3327 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50027.vdb - 4697 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50026.vdb - 2792 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50025.vdb - 5841 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50024.vdb - 2260 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50023.vdb - 4796 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50022.vdb - 5098 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50021.vdb - 4891 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50020.vdb - 5033 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50019.vdb - 3254 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50018.vdb - 5206 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50017.vdb - 7585 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50016.vdb - 5298 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50015.vdb - 5947 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50014.vdb - 6039 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50013.vdb - 5309 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50012.vdb - 3511 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50011.vdb - 2495 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50010.vdb - 4565 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50009.vdb - 4467 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50008.vdb - 5196 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50007.vdb - 2359 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50006.vdb - 1938 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50005.vdb - 3335 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50004.vdb - 3185 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50003.vdb - 1468 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50002.vdb - 280 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50001.vdb - 567 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drw50000.vdb - 1194 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwebase.vdb - 423328 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwrtoday.vdb - 110 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50003.vdb - 508 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50002.vdb - 665 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwr50001.vdb - 626 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwntoday.vdb - 229 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50006.vdb - 597 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50005.vdb - 554 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50004.vdb - 680 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50003.vdb - 712 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50002.vdb - 925 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\dwn50001.vdb - 840 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwrisky.vdb - 3316 virus records
[Virus database] C:\Documents and Settings\All Users\Application Data\Doctor Web\Bases\drwnasty.vdb - 19303 virus records
Total virus records: 683155
[Self-checking] C:\Program Files\DrWeb\DrWeb32w.exe
Key file: C:\Program Files\DrWeb\drwdemo.key
License key number: 1405302341
Registered to: Doctor Web trial user: Louise Green
License key activates on: 2009-10-20
License key expires on: 2009-11-19

[Scan path] c:\documents and settings\administrator\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\all users\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\default user\start menu\programs\startup\desktop.ini
[Scan path] c:\documents and settings\louise\local settings\temp\hgu8ynfx.dll
[Scan path] c:\documents and settings\louise\local settings\temp\i64xg6fq.dll
[Scan path] c:\documents and settings\louise\start menu\programs\startup\desktop.ini
[Scan path] c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
[Scan path] c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll
[Scan path] c:\program files\adobe\acrobat 7.0\reader\adobeupdatemanager.exe
[Scan path] c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
[Scan path] c:\program files\apple software update\softwareupdate.exe
[Scan path] c:\program files\ati technologies\ati control panel\atiptaxx.exe
[Scan path] c:\program files\bonjour\mdnsnsp.dll
[Scan path] c:\program files\bonjour\mdnsresponder.exe
[Scan path] c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe
[Scan path] c:\program files\common files\apple\mobile device support\bin\applesyncnotifier.exe
[Scan path] c:\program files\common files\doctor web\scanning engine\dwengine.exe
[Scan path] c:\program files\common files\microsoft shared\office11\msoxmlmf.dll
[Scan path] c:\program files\common files\microsoft shared\source engine\ose.exe
[Scan path] c:\program files\common files\microsoft shared\speech\sapi.cpl
[Scan path] c:\program files\common files\microsoft shared\web components\11\owc11.dll
[Scan path] c:\program files\common files\microsoft shared\web folders\msonsext.dll
[Scan path] c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll
[Scan path] c:\program files\common files\real\update_ob\realsched.exe
[Scan path] c:\program files\common files\system\ole db\oledb32.dll
[Scan path] c:\program files\creative\audiocs\ctaudcs.cpl
[Scan path] c:\program files\creative\creative zen nano plus\zen nano plus media explorer\ctmvnsu.dll
[Scan path] c:\program files\digiguide tv guide\client.exe
[Scan path] c:\program files\drweb\drweb32w.exe
[Scan path] c:\program files\drweb\drwebsp.dll
[Scan path] c:\program files\drweb\drwebupw.exe
[Scan path] c:\program files\drweb\drwsxtn.dll
[Scan path] c:\program files\drweb\spider.sys
[Scan path] c:\program files\drweb\spideragent.exe
[Scan path] c:\program files\drweb\spiderml.exe
[Scan path] c:\program files\drweb\spidernt.exe
[Scan path] c:\program files\drweb\spiderui.exe
[Scan path] c:\program files\google\common\google updater\googleupdaterservice.exe
[Scan path] c:\program files\google\google toolbar\component\fastsearch_b7c5ac242193bb3e.dll
[Scan path] c:\program files\google\google toolbar\googletoolbar_32.dll
[Scan path] c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
[Scan path] c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
[Scan path] c:\program files\hp\digital imaging\bin\hpqcxs08.dll
[Scan path] c:\program files\hp\digital imaging\bin\hpqddsvc.dll
[Scan path] c:\program files\hp\digital imaging\bin\hpqtra08.exe
[Scan path] c:\program files\hp\hp software update\hpwuschd2.exe
[Scan path] c:\program files\internet explorer\plugins\npdocbox.dll
[Scan path] c:\program files\ipod\bin\ipodservice.exe
[Scan path] c:\program files\itunes\ituneshelper.exe
[Scan path] c:\program files\itunes\itunesminiplayer.dll
[Scan path] c:\program files\java\jre6\bin\jp2iexp.dll
[Scan path] c:\program files\java\jre6\bin\jp2ssv.dll
[Scan path] c:\program files\java\jre6\bin\jqs.exe
[Scan path] c:\program files\java\jre6\bin\jusched.exe
[Scan path] c:\program files\java\jre6\bin\npjpi160_11.dll
[Scan path] c:\program files\java\jre6\bin\ssv.dll
[Scan path] c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
[Scan path] c:\program files\java\jre6\lib\deploy\jqs\jqs.conf
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\adialhk.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\kloehk.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\mzvkbd.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\mzvkbd3.dll
[Scan path] c:\program files\kaspersky lab\kaspersky internet security 2009\scieplgn.dll
[Scan path] c:\program files\lavasoft\ad-aware\aawservice.exe
[Scan path] c:\program files\lavasoft\ad-aware\ceapi.dll
[Scan path] c:\program files\lavasoft\ad-aware\pkarchive85u.dll
-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Scanned: 83
Infected: 0
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 0
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 2365 Kb/s
Scan time: 00:00:11
-----------------------------------------------------------------------------

#10 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:10:12 PM

Posted 20 October 2009 - 06:39 PM

c:\windows\system32\drivers\gasfkyrmuptnwm.sys
c:\windows\system32\drivers\gasfkyrmuptnwm.sys infected with BackDoor.Tdss.based.1
Definitely infected with rootkits even thought it says they've been deleted

Please run the scans I posted in post number8

Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#11 legreen

legreen
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:12 AM

Posted 21 October 2009 - 01:00 PM

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/21 18:47
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================

Drivers
-------------------
Name: dump_iastor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iastor.sys
Address: 0x9FB00000 Size: 872448 File Visible: No Signed: -
Status: -

Name: tatertot.scr.sys
Image Path: C:\WINDOWS\system32\drivers\tatertot.scr.sys
Address: 0xBAB18000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: c:\documents and settings\all users\application data\kaspersky lab\avp8\data\av1.tmp
Status: Allocation size mismatch (API: 40288256, Raw: 0)

Path: c:\documents and settings\all users\application data\kaspersky lab\avp8\data\av11.tmp
Status: Allocation size mismatch (API: 40288256, Raw: 0)

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\22\122-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v122-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v122-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\46\46-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v46-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v46-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\69\69-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v69-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v69-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\00\100-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v100-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v100-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\01\101-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v101-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v101-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\02\102-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v102-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v102-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\03\103-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v103-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v103-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\04\104-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v104-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v104-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\05\105-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v105-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v105-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\06\106-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v106-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v106-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\07\107-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v107-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v107-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\08\108-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v108-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v108-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\09\109-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v109-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v109-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\10\110-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v110-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v110-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\11\111-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v111-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v111-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\12\112-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v112-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v112-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\13\113-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v113-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v113-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\14\114-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v114-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v114-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\15\115-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v115-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v115-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\16\60-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v116-{4EEC5E4A-850B-45FA-9D05-067872C049AE}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\17\117-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v117-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v117-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\18\118-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v118-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v118-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\19\119-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v119-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v119-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\20\120-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v120-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v120-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\21\121-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v121-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v121-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\47\47-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v47-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v47-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\48\48-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v48-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v48-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\49\49-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v49-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v49-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\50\50-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v50-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v50-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\51\51-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v51-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v51-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\52\52-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v52-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v52-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\53\53-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v53-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v53-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\54\54-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v54-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v54-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\55\55-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v55-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v55-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\56\56-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v56-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v56-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\57\57-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v57-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v57-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\58\58-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v58-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v58-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\59\59-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v59-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v59-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\60\60-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v60-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v60-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\61\61-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v61-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v61-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\62\62-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v62-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v62-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\63\63-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v63-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v63-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\64\64-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v64-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v64-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\65\65-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v65-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v65-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\66\66-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v66-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v66-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\67\67-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v67-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v67-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\68\68-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v68-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v68-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\70\70-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v70-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v70-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\71\71-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v71-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v71-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\72\72-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v72-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v72-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\73\73-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v73-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v73-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\74\74-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v74-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v74-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\75\75-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v75-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v75-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\76\76-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v76-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v76-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\77\77-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v77-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v77-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\78\78-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v78-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v78-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\79\79-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v79-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v79-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\80\80-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v80-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v80-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\81\81-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v81-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v81-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\82\82-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v82-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v82-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\83\83-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v83-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v83-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\84\84-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v84-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v84-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\85\85-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v85-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v85-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\86\86-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v86-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v86-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\87\87-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v87-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v87-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\88\88-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v88-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v88-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\89\89-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v89-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v89-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Messenger\lou_e_green@hotmail.com\SharingMetadata\vsologaistoa@hotmail.com\DFSR\Staging\CS{E0427137-06C8-4B22-0F38-D3D9A7856BEC}\90\90-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v90-{8FD6B084-E136-4241-BE53-E1BC210BDB5A}-v90-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS
StatuSSDT
-------------------
#: 011 Function Name: NtAdjustPrivilegesToken
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fca72

#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd01e

#: 031 Function Name: NtConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fea82

#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe438

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc1e8

#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa56003e4

#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fce1a

#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc62a

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc82a

#: 066 Function Name: NtDeviceIoControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe744

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa56008f0

#: 071 Function Name: NtEnumerateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc940

#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc9a8

#: 084 Function Name: NtFsControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe5fa

#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55ffea8

#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe294

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc34a

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fcc40

#: 125 Function Name: NtOpenSection
Status: Hooked by "dwprot.sys" at address 0xba5e1f86

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fcb96

#: 160 Function Name: NtQueryKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fca10

#: 161 Function Name: NtQueryMultipleValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc714

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc4f2

#: 180 Function Name: NtQueueApcThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa5600110

#: 193 Function Name: NtReplaceKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fbe6a

#: 200 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55ff30c

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fbfcc

#: 206 Function Name: NtResumeThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa56007c0

#: 207 Function Name: NtSaveKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fbc68

#: 210 Function Name: NtSecureConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe924

#: 213 Function Name: NtSetContextThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fcf18

#: 237 Function Name: NtSetSecurityObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fffa2

#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa5600438

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fc3a0

#: 253 Function Name: NtSuspendProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa560051c

#: 254 Function Name: NtSuspendThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa5600648

#: 255 Function Name: NtSystemDebugControl
Status: Hooked by "dwprot.sys" at address 0xba5e1ebc

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fccea

#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fcd5c

Shadow SSDT
-------------------
#: 013 Function Name: NtGdiBitBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe1d4

#: 227 Function Name: NtGdiMaskBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe234

#: 237 Function Name: NtGdiPlgBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe264

#: 292 Function Name: NtGdiStretchBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe204

#: 307 Function Name: NtUserAttachThreadInput
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd6c4

#: 323 Function Name: NtUserCallOneParam
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe890

#: 378 Function Name: NtUserFindWindowEx
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd9a2

#: 383 Function Name: NtUserGetAsyncKeyState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd604

#: 414 Function Name: NtUserGetKeyboardState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd664

#: 416 Function Name: NtUserGetKeyState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd634

#: 460 Function Name: NtUserMessageCall
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55ffd24

#: 475 Function Name: NtUserPostMessage
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55ffd7c

#: 476 Function Name: NtUserPostThreadMessage
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55ffda8

#: 483 Function Name: NtUserQueryWindow
Status: Hooked by "dwprot.sys" at address 0xba5e1916

#: 491 Function Name: NtUserRegisterRawInputDevices
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fe83a

#: 502 Function Name: NtUserSendInput
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd97c

#: 549 Function Name: NtUserSetWindowsHookEx
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd076

#: 552 Function Name: NtUserSetWinEventHook
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xa55fd28e

==EOF==







Volume in drive C has no label.
Volume Serial Number is 1495-6339

Directory of C:\WINDOWS\$NtServicePackUninstall$

10/08/2004 12:00 180,224 scecli.dll

Directory of C:\WINDOWS\$NtServicePackUninstall$

10/08/2004 12:00 407,040 netlogon.dll

Directory of C:\WINDOWS\$NtServicePackUninstall$

10/08/2004 12:00 55,808 eventlog.dll
3 File(s) 643,072 bytes

Directory of C:\WINDOWS\ServicePackFiles\i386

14/04/2008 01:12 181,248 scecli.dll

Directory of C:\WINDOWS\ServicePackFiles\i386

14/04/2008 01:12 407,040 netlogon.dll

Directory of C:\WINDOWS\ServicePackFiles\i386

14/04/2008 01:11 56,320 eventlog.dll
3 File(s) 644,608 bytes

Directory of C:\WINDOWS\system32

14/04/2008 01:12 181,248 scecli.dll

Directory of C:\WINDOWS\system32

14/04/2008 01:12 407,040 netlogon.dll

Directory of C:\WINDOWS\system32

14/04/2008 01:11 56,320 eventlog.dll
3 File(s) 644,608 bytes

Total Files Listed:
9 File(s) 1,932,288 bytes
0 Dir(s) 12,952,690,688 bytes free

#12 garmanma

garmanma

    Computer Masochist


  • Staff Emeritus
  • 27,809 posts
  • OFFLINE
  •  
  • Location:Cleveland, Ohio
  • Local time:10:12 PM

Posted 21 October 2009 - 06:07 PM

Using the last 2 logs that you ran scans for, post them here


Now that you were successful in creating those two logs you need to post them in our HJT forum There they will help you with the removal through some custom scripts and programs that we cannot run here in this forum

First, try to run a DDS / HJT log as outlined in our preparation guide:
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/

If it won't run, don't worry, just give a brief description and tell them that these logs were all you could get to run successfully

Post them here:
http://www.bleepingcomputer.com/forums/f/22/virus-trojan-spyware-and-malware-removal-logs/

The HJT team is extremely busy, so be patient and good luck
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#13 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,805 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:10:12 PM

Posted 22 October 2009 - 07:52 PM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/t/266214/rootkits-infection/ you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a HJT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the HJT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the HJT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the HJT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days, up to two weeks perhaps less, to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users