Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Keylogger? Email passwords were stolen


  • Please log in to reply
7 replies to this topic

#1 Chis

Chis

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 29 December 2009 - 11:01 AM

My dad just had all three of his emails hijacked yesterday, and I suspect there's some unwanted activity on this computer ... otherwise it seems to be running okay.

I downloaded Avira not too long ago and it found and quarantined evidence of 'HTML/Crypted.Gen [virus].'
I also did a full Malwarebytes scan and came up with 5 infections.

Malwarebytes' Anti-Malware 1.42
Database version: 3447
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/29/2009 12:32:55 AM
mbam-log-2009-12-29 (00-32-55).txt

Scan type: Full Scan (C:\|)
Objects scanned: 230618
Time elapsed: 52 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\SoftSoldier (Rogue.SoftSoldier) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\RECYCLER\S-1-5-21-3359162341-2101431105-2089585461-1005\Dc1202.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-3359162341-2101431105-2089585461-1005\Dc297.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-3359162341-2101431105-2089585461-1005\Dc775.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-3359162341-2101431105-2089585461-1005\Dc1584.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP263\A0028038.exe (Rogue.Installer) -> Quarantined and deleted successfully.

Thanks.

Edit -- I just scanned the computer with superantispyware in safe mode, and the log is not pretty.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/29/2009 at 01:12 PM

Application Version : 4.32.1000

Core Rules Database Version : 4379
Trace Rules Database Version: 2246

Scan type : Complete Scan
Total Scan Time : 00:35:21

Memory items scanned : 243
Memory threats detected : 0
Registry items scanned : 8289
Registry threats detected : 0
File items scanned : 36075
File threats detected : 848

Adware.Tracking Cookie
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@collective-media[1].txt
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@richmedia.yahoo[1].txt
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@doubleclick[2].txt
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@ads.monster[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.bridgetrack[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ihireaccounting[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.pointroll[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@www.accountonline[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ehg-foxnewsnetworkllc.hitbox[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@pixel-hk.pixelinteractivemedia[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@counter6.sextracker[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ad.yieldmanager[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@chitika[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@burstnet[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@statcounter[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@sitestat.mayoclinic[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@network.realmedia[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.cnn[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@interclick[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@adbrite[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@worldsex[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@downloads.trymedia[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@usnews.122.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@accountonline[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@bnkedu.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@medicaldevicelink.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@content.yieldmanager[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@content.yieldmanager[3].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@smartmoney.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@invitemedia[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@tacoda[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@freepornjerk[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@specificmedia[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@nextag[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@eyewonder[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@revsci[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.collegeconfidential[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.ihispano[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@foxnews.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.shutterfly[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@bluestreak[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ru4[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@media.adrevolver[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@www.freeporndaily[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@www.qksrv[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@www.googleadservices[5].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@mediaplex[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@rb4.worldsex[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.meredithads[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@hitbox[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@www.googleadservices[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@cb.adbureau[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@media.adrevolver[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@freeporndaily[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@allegis.122.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@adopt.euroclick[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@casalemedia[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.hobsons-us[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.backchina[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@realmedia[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@collective-media[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@adopt.specificclick[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@dynamic.media.adrevolver[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@cdn4.specificclick[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@statse.webtrendslive[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@videoegg.adbureau[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@beacon.dmsinsights[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@fastclick[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@l1.qsstats[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@richmedia.yahoo[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@bs.serving-sys[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@at.atwola[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@pornprosnetwork[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.undertone[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ad.wsod[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@tribalfusion[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@atdmt[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@serving-sys[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ad2adnetwork[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@trafficmp[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@tracking.realtor[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@a1.interclick[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@adserver.adtechus[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ero-advertising[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@zedo[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@momisnaked[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@sextracker[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@sales.liveperson[4].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@specificclick[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@qnsr[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@msnportal.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@sales.liveperson[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@fasttrackenglish[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.ft[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@apmebf[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@questionmarket[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@www.clickmanage[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@edge.ru4[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@intermundomedia[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@sales.liveperson[3].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@monstercom.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.youniversitytv[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@adrevolver[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@pointroll[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.people.com[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@webmarketing123com.122.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@usatoday1.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@mkt10.122.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ameriprisestats[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@trackalyzer[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@kontera[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@ads.monster[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@advertising[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@imrworldwide[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@porndad[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@wsclick.infospace[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@click.payserve[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@topporn[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@overture[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@www.clickr[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@counter2.sextracker[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@doubleclick[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@www.ihireaccounting[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@247realmedia[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@toplist[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@toplist[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@msnbc.112.2o7[1].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@adinterax[2].txt
C:\Documents and Settings\VISITORS\Cookies\visitors@insightexpressai[1].txt

Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{46DE8921-1D39-44D2-A9E9-64119261F211}\RP294\A0031599.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{46DE8921-1D39-44D2-A9E9-64119261F211}\RP294\A0031600.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{46DE8921-1D39-44D2-A9E9-64119261F211}\RP294\A0031601.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{46DE8921-1D39-44D2-A9E9-64119261F211}\RP294\A0031602.EXE

Rogue.Agent/Gen-Nullo[DLL]
C:\WINDOWS\2FA3DO5NLOADEZ9347.DLL
C:\WINDOWS\11E89DDZARE1865.DLL
C:\WINDOWS\13AZV9R5409.DLL
C:\WINDOWS\16745Z9RM2485.DLL
C:\WINDOWS\1848VIR9Z605.DLL
C:\WINDOWS\1B4295Z2148.DLL
C:\WINDOWS\211859ROJ3D6Z.DLL
C:\WINDOWS\21332HACK95OZ7BD.DLL
C:\WINDOWS\2156S9EAL3Z07.DLL
C:\WINDOWS\254ZSP9W5RE2034.DLL
C:\WINDOWS\26059HACKTZOL29.DLL
C:\WINDOWS\28843S9AM5OTZ20.DLL
C:\WINDOWS\2942ZHAC9TOOL549.DLL
C:\WINDOWS\29542HACK5OOZ642.DLL
C:\WINDOWS\2978ZVIR9S359.DLL
C:\WINDOWS\2A55Z9IEF142.DLL
C:\WINDOWS\2F35ZIR7369.DLL
C:\WINDOWS\2Z991S5Y6F1.DLL
C:\WINDOWS\32DDVIRZ695.DLL
C:\WINDOWS\32Z76V9RUS5E8.DLL
C:\WINDOWS\35749ORM63Z.DLL
C:\WINDOWS\3D4EB9CKDZOR2754.DLL
C:\WINDOWS\419ASP5WARE2901Z.DLL
C:\WINDOWS\3Z49DOWNLOA5E92030.DLL
C:\WINDOWS\41ZDA5DWA9E1955.DLL
C:\WINDOWS\43C85PARSE1292Z.DLL
C:\WINDOWS\4A59THIEF1336Z.DLL
C:\WINDOWS\4624BACKDOO9Z845.DLL
C:\WINDOWS\4815WO5MZ59.DLL
C:\WINDOWS\4B2ZDOWNLOAD5R21729.DLL
C:\WINDOWS\4BZ9STE951626.DLL
C:\WINDOWS\505Z7SPAM9OT2C5.DLL
C:\WINDOWS\50983TROJ36Z.DLL
C:\WINDOWS\51699TROJZ1F.DLL
C:\WINDOWS\560CZ5DW9RE2539.DLL
C:\WINDOWS\53ZFSPYWARE18559.DLL
C:\WINDOWS\56183HZC9TOOL29B.DLL
C:\WINDOWS\5858SPA5BOT3Z09.DLL
C:\WINDOWS\5994VIRZS5F0.DLL
C:\WINDOWS\5B21ZHIEF23719.DLL
C:\WINDOWS\5DB09ZREAT17884.DLL
C:\WINDOWS\5DD395DWARZ1946.DLL
C:\WINDOWS\5Z7DOWNLOADER2779.DLL
C:\WINDOWS\61Z4SPYWARE6159.DLL
C:\WINDOWS\62C5DOW9LOZDER1958.DLL
C:\WINDOWS\651BTHREA5Z7490.DLL
C:\WINDOWS\6536A9DZARE2953.DLL
C:\WINDOWS\6F79SZA5S996.DLL
C:\WINDOWS\763ASPZW5RE996.DLL
C:\WINDOWS\77ZSPYW9RE1576.DLL
C:\WINDOWS\7AB65TE9L1Z81.DLL
C:\WINDOWS\7FCBDOWN95ZDER600.DLL
C:\WINDOWS\9055I9194Z.DLL
C:\WINDOWS\915ZTRO5775.DLL
C:\WINDOWS\9237BACKDZOR1569.DLL
C:\WINDOWS\92566SP5MBOZ674.DLL
C:\WINDOWS\9474ZSPAM5OT373.DLL
C:\WINDOWS\98EEBA5KDOORZ601.DLL
C:\WINDOWS\98ESTEA52Z58.DLL
C:\WINDOWS\9C9STEAZ566.DLL
C:\WINDOWS\9Z105SPY145.DLL
C:\WINDOWS\9Z44HACKTOOL3D5.DLL
C:\WINDOWS\SYSTEM32\10A1ZPAR9E5597.DLL
C:\WINDOWS\SYSTEM32\11Z19TR5J39F.DLL
C:\WINDOWS\SYSTEM32\13925ZROJ259.DLL
C:\WINDOWS\SYSTEM32\15739SPAMBOZ49F5.DLL
C:\WINDOWS\SYSTEM32\16237NOT5AZVIRUS3309.DLL
C:\WINDOWS\SYSTEM32\190Z7VIR5S59B.DLL
C:\WINDOWS\SYSTEM32\191529ROZ225.DLL
C:\WINDOWS\SYSTEM32\1916Z5IR9S66F.DLL
C:\WINDOWS\SYSTEM32\1A5CVIR94Z9.DLL
C:\WINDOWS\SYSTEM32\19B5ADZWARE1597.DLL
C:\WINDOWS\SYSTEM32\19Z90SPAMB5TF1.DLL
C:\WINDOWS\SYSTEM32\19Z96HA5KTO9L58C.DLL
C:\WINDOWS\SYSTEM32\21952SPAMZOT3975.DLL
C:\WINDOWS\SYSTEM32\20181VIR5S9B1Z.DLL
C:\WINDOWS\SYSTEM32\20966S5AMBOT794Z.DLL
C:\WINDOWS\SYSTEM32\2096DOW59OADERZ915.DLL
C:\WINDOWS\SYSTEM32\23Z5SP5WARE14689.DLL
C:\WINDOWS\SYSTEM32\24185TR5J9EZ.DLL
C:\WINDOWS\SYSTEM32\25759DDZARE834.DLL
C:\WINDOWS\SYSTEM32\28209Z5OJ590.DLL
C:\WINDOWS\SYSTEM32\28371TR5J19Z.DLL
C:\WINDOWS\SYSTEM32\2855ZSPY89.DLL
C:\WINDOWS\SYSTEM32\29098HAZKTOO591.DLL
C:\WINDOWS\SYSTEM32\29527SZAMBOTCB.DLL
C:\WINDOWS\SYSTEM32\2Z500VIRUS9E0.DLL
C:\WINDOWS\SYSTEM32\34C195R3Z66.DLL
C:\WINDOWS\SYSTEM32\37ZSPA5SE2980.DLL
C:\WINDOWS\SYSTEM32\3935SZY55C.DLL
C:\WINDOWS\SYSTEM32\3Z985VIRUS133.DLL
C:\WINDOWS\SYSTEM32\3F1Z9TEAL2595.DLL
C:\WINDOWS\SYSTEM32\3Z7CD9WNL5ADER44.DLL
C:\WINDOWS\SYSTEM32\4956ZTEAL995.DLL
C:\WINDOWS\SYSTEM32\4751ZACKD5OR7859.DLL
C:\WINDOWS\SYSTEM32\49DCBACKZOO53212.DLL
C:\WINDOWS\SYSTEM32\50925DDWARE1Z25.DLL
C:\WINDOWS\SYSTEM32\52759TEALZ44.DLL
C:\WINDOWS\SYSTEM32\54526S9Y4Z4.DLL
C:\WINDOWS\SYSTEM32\54BAZDWARE3915.DLL
C:\WINDOWS\SYSTEM32\58599WORM971Z.DLL
C:\WINDOWS\SYSTEM32\553B59ZRSE606.DLL
C:\WINDOWS\SYSTEM32\5715BACK9OORZ255.DLL
C:\WINDOWS\SYSTEM32\5895T5ZJ59B.DLL
C:\WINDOWS\SYSTEM32\58Z5VIR5S699.DLL
C:\WINDOWS\SYSTEM32\5C5CSPARZE9116.DLL
C:\WINDOWS\SYSTEM32\5CBZSTE9L898.DLL
C:\WINDOWS\SYSTEM32\5F79TH9EAT305Z7.DLL
C:\WINDOWS\SYSTEM32\65SPY9ARZ905.DLL
C:\WINDOWS\SYSTEM32\66DD9DDZ5RE1670.DLL
C:\WINDOWS\SYSTEM32\6926TRZJ358.DLL
C:\WINDOWS\SYSTEM32\6F95THIEF32Z5.DLL
C:\WINDOWS\SYSTEM32\739BVZ51202.DLL
C:\WINDOWS\SYSTEM32\7515ACZ9OOL213.DLL
C:\WINDOWS\SYSTEM32\7563VIRU5Z69.DLL
C:\WINDOWS\SYSTEM32\7691H5CKTOOZ65.DLL
C:\WINDOWS\SYSTEM32\77F0SPYW59EZ987.DLL
C:\WINDOWS\SYSTEM32\793EVIZ557.DLL
C:\WINDOWS\SYSTEM32\7D42ADDZARE92525.DLL
C:\WINDOWS\SYSTEM32\8Z89HA9KTOOL752.DLL
C:\WINDOWS\SYSTEM32\9214TR5J2ZC.DLL
C:\WINDOWS\SYSTEM32\94801HACKZ5OL5FB.DLL
C:\WINDOWS\SYSTEM32\9569ZHIEF759.DLL
C:\WINDOWS\SYSTEM32\9D96THIEZ695.DLL
C:\WINDOWS\SYSTEM32\BF4ZO5NLOA9ER855.DLL
C:\WINDOWS\SYSTEM32\Z0999SPY5695.DLL
C:\WINDOWS\SYSTEM32\Z9494VIRUS7075.DLL
C:\WINDOWS\SYSTEM32\Z959VIR1306.DLL
C:\WINDOWS\SYSTEM32\ZB73SPA5S92543.DLL
C:\WINDOWS\Z57109ORM3F5.DLL
C:\WINDOWS\Z2STEAL1599.DLL
C:\WINDOWS\Z69595RUS131.DLL
C:\WINDOWS\Z905SPYWARE1596.DLL
C:\WINDOWS\Z9BDOWNL5ADER2183.DLL
C:\WINDOWS\ZB7THREA9143935.DLL
C:\WINDOWS\ZD49VIR895.DLL

Rogue.Agent/Gen-Nullo[OCX-Spec]
C:\WINDOWS\12467NOT9A-VIRUZ5BF.OCX
C:\WINDOWS\126369O5ZA-VIRUS85.OCX
C:\WINDOWS\57782N9Z-A-VIRUS346.OCX
C:\WINDOWS\6759NOT-Z-VIRUS529.OCX
C:\WINDOWS\SYSTEM32\12547ZOT-A-VIRU5439.OCX
C:\WINDOWS\SYSTEM32\19996NOT-A-VI5US409Z.OCX
C:\WINDOWS\SYSTEM32\2539359T-Z-VIRUS7FA.OCX
C:\WINDOWS\SYSTEM32\6530NOT-A-V5R9ZAC.OCX
C:\WINDOWS\Z207NOT-A9V5RUS455.OCX

Rogue.Agent/Gen-Nullo[CPL-Spec]
C:\WINDOWS\1021ZNOT-A5VIR9SFA.CPL
C:\WINDOWS\14456NOT-A9VIRUSZE0.CPL
C:\WINDOWS\19530NOT-A-VIRZS676.CPL
C:\WINDOWS\55565N9T-Z-VIRUS3E7.CPL
C:\WINDOWS\SYSTEM32\29716NOT-AZVIRUS6155.CPL
C:\WINDOWS\SYSTEM32\31977N5Z-A-VIRUS4F4.CPL
C:\WINDOWS\SYSTEM32\55264NOZ-A-VIRUS690.CPL

Rogue.Agent/Gen-Nullo[BIN]
C:\WINDOWS\105EBACKZO9R2089.BIN
C:\WINDOWS\10BESP5WAR9793Z.BIN
C:\WINDOWS\113365IRUS190Z.BIN
C:\WINDOWS\179685IZUS6FB.BIN
C:\WINDOWS\14D4V9R75Z.BIN
C:\WINDOWS\15201SPAMBZ94FC.BIN
C:\WINDOWS\16409IRU5692Z.BIN
C:\WINDOWS\1682SP59BOT6Z0.BIN
C:\WINDOWS\1A359OWNLO5DER2320Z.BIN
C:\WINDOWS\179Z85ORM51A.BIN
C:\WINDOWS\216009OR530Z.BIN
C:\WINDOWS\22394HZCK9OOL565.BIN
C:\WINDOWS\251159PAMBZT2BA.BIN
C:\WINDOWS\25DA9ZE5L308.BIN
C:\WINDOWS\25Z6VIR2955.BIN
C:\WINDOWS\28995HAZKTOOL7D5.BIN
C:\WINDOWS\29565TROJ3ZC.BIN
C:\WINDOWS\29Z31WORM45.BIN
C:\WINDOWS\2Z349TR5J599.BIN
C:\WINDOWS\3129ZSPY7915.BIN
C:\WINDOWS\31759TROJ3DCZ.BIN
C:\WINDOWS\3496ZHREAT14025.BIN
C:\WINDOWS\37195IZUS5789.BIN
C:\WINDOWS\39D8THREZT13955.BIN
C:\WINDOWS\3D79BAZKD5OR3263.BIN
C:\WINDOWS\4C5CSPYW9RE3Z1.BIN
C:\WINDOWS\4D3A5OWNLOZDER28379.BIN
C:\WINDOWS\4E55THREATZ1965.BIN
C:\WINDOWS\4F34SPYZARE955.BIN
C:\WINDOWS\52BZSPYWARE17649.BIN
C:\WINDOWS\5744SPYWAZE5899.BIN
C:\WINDOWS\58D5T9REAT2787Z.BIN
C:\WINDOWS\5B659IEF1996Z.BIN
C:\WINDOWS\594ASPYWARE2285Z.BIN
C:\WINDOWS\59E8ADD5AZE390.BIN
C:\WINDOWS\59SZYWARE3050.BIN
C:\WINDOWS\60C5HZEF2269.BIN
C:\WINDOWS\735FSTEALZ659.BIN
C:\WINDOWS\7109TZO57AB.BIN
C:\WINDOWS\7199VI57Z.BIN
C:\WINDOWS\7519V5RZ63.BIN
C:\WINDOWS\752BBZC9DOOR3187.BIN
C:\WINDOWS\75BFDOWNLOAD9R2137Z.BIN
C:\WINDOWS\78965ZOJ776.BIN
C:\WINDOWS\7EA9ADZWARE1595.BIN
C:\WINDOWS\7Z07SPAMB5T9EC.BIN
C:\WINDOWS\7Z64V9R1555.BIN
C:\WINDOWS\7ZFAT95EF1501.BIN
C:\WINDOWS\8185ZORM19E.BIN
C:\WINDOWS\904ZADDW5RE1005.BIN
C:\WINDOWS\93Z45SPY2A4.BIN
C:\WINDOWS\97345V5RUS114Z.BIN
C:\WINDOWS\961SZEAL26505.BIN
C:\WINDOWS\9690VIRUS9Z5.BIN
C:\WINDOWS\9DZ8SPYW5RE2197.BIN
C:\WINDOWS\9Z899SPY65B.BIN
C:\WINDOWS\E77BACKDOORZ594.BIN
C:\WINDOWS\SYSTEM32\112889PAMBOTZF5.BIN
C:\WINDOWS\SYSTEM32\11Z24V59US1DD.BIN
C:\WINDOWS\SYSTEM32\146039ORM5Z3.BIN
C:\WINDOWS\SYSTEM32\14Z5ST5A92319.BIN
C:\WINDOWS\SYSTEM32\17123SPA5BOT2ZA9.BIN
C:\WINDOWS\SYSTEM32\172Z5SPY7E69.BIN
C:\WINDOWS\SYSTEM32\1766AZDWAR5994.BIN
C:\WINDOWS\SYSTEM32\18Z84H9CKT5OL5B8.BIN
C:\WINDOWS\SYSTEM32\1A26BACKDO9R85Z.BIN
C:\WINDOWS\SYSTEM32\21Z55TROJ509.BIN
C:\WINDOWS\SYSTEM32\22094HACKTOZL5CE5.BIN
C:\WINDOWS\SYSTEM32\2629HACKTO5L58EZ.BIN
C:\WINDOWS\SYSTEM32\26Z1ADDWARE5729.BIN
C:\WINDOWS\SYSTEM32\291125IRUS3ZA.BIN
C:\WINDOWS\SYSTEM32\2A20THREZT159959.BIN
C:\WINDOWS\SYSTEM32\2A7ZP9WARE530.BIN
C:\WINDOWS\SYSTEM32\2CZ4SPA5SE26059.BIN
C:\WINDOWS\SYSTEM32\348CZHI5F1984.BIN
C:\WINDOWS\SYSTEM32\348CTZ9EA531122.BIN
C:\WINDOWS\SYSTEM32\3A01STEAZ5695.BIN
C:\WINDOWS\SYSTEM32\359DSTEA93522Z.BIN
C:\WINDOWS\SYSTEM32\35Z5AD9WARE3085.BIN
C:\WINDOWS\SYSTEM32\392DSZYWA5E296.BIN
C:\WINDOWS\SYSTEM32\3F9BZHIEF537.BIN
C:\WINDOWS\SYSTEM32\410ESPYWA95131Z.BIN
C:\WINDOWS\SYSTEM32\42B2SPAR5Z911.BIN
C:\WINDOWS\SYSTEM32\44Z55OWN9OADER1390.BIN
C:\WINDOWS\SYSTEM32\4959VZR9S3D4.BIN
C:\WINDOWS\SYSTEM32\4B9ZADDW9RE9165.BIN
C:\WINDOWS\SYSTEM32\4CCEBAC5DOOR1Z129.BIN
C:\WINDOWS\SYSTEM32\4DE0B9CK5OORZ734.BIN
C:\WINDOWS\SYSTEM32\4EC15OZNLOADER2957.BIN
C:\WINDOWS\SYSTEM32\4Z9E9P5WARE3081.BIN
C:\WINDOWS\SYSTEM32\4ZB1THIEF5695.BIN
C:\WINDOWS\SYSTEM32\52CDSZAR593192.BIN
C:\WINDOWS\SYSTEM32\54835VIR9SZBD.BIN
C:\WINDOWS\SYSTEM32\5550ZOR953.BIN
C:\WINDOWS\SYSTEM32\56744SPAMBOT4Z39.BIN
C:\WINDOWS\SYSTEM32\57Z609PYA2.BIN
C:\WINDOWS\SYSTEM32\5948VZRU939.BIN
C:\WINDOWS\SYSTEM32\5C56ZPARSE899.BIN
C:\WINDOWS\SYSTEM32\6099SP53E1Z.BIN
C:\WINDOWS\SYSTEM32\6115THIEF509Z9.BIN
C:\WINDOWS\SYSTEM32\695ZBACKDOOR2765.BIN
C:\WINDOWS\SYSTEM32\69A7SPARS51177Z.BIN
C:\WINDOWS\SYSTEM32\6CB3BA9KDOZR24185.BIN
C:\WINDOWS\SYSTEM32\72D3ZDDWAR59490.BIN
C:\WINDOWS\SYSTEM32\74F7BZCK59OR593.BIN
C:\WINDOWS\SYSTEM32\7993S5EAZ2029.BIN
C:\WINDOWS\SYSTEM32\7865HACKTO5L9ZD.BIN
C:\WINDOWS\SYSTEM32\7877DOWZLOADER9045.BIN
C:\WINDOWS\SYSTEM32\79059ROJ3ZC.BIN
C:\WINDOWS\SYSTEM32\90F5ADDWA5E2824Z.BIN
C:\WINDOWS\SYSTEM32\7CC65OWNLOADE92Z57.BIN
C:\WINDOWS\SYSTEM32\82995ACKTOOZ79B9.BIN
C:\WINDOWS\SYSTEM32\8Z60SPAMBOT359.BIN
C:\WINDOWS\SYSTEM32\93931WZRM5E8.BIN
C:\WINDOWS\SYSTEM32\95419WZRM345.BIN
C:\WINDOWS\SYSTEM32\9795VIRZS2D49.BIN
C:\WINDOWS\SYSTEM32\98Z36SPAMBOT513.BIN
C:\WINDOWS\SYSTEM32\9ZE4DOWNLO5DER644.BIN
C:\WINDOWS\SYSTEM32\9Z6A5HREAT20652.BIN
C:\WINDOWS\SYSTEM32\E30ADDW95E267Z.BIN
C:\WINDOWS\SYSTEM32\EFFDOWNLOADE9557Z.BIN
C:\WINDOWS\SYSTEM32\Z008THIEF11095.BIN
C:\WINDOWS\SYSTEM32\Z856S5AMBOT419.BIN
C:\WINDOWS\SYSTEM32\Z859IR973.BIN
C:\WINDOWS\SYSTEM32\ZD55S9ARSE2122.BIN
C:\WINDOWS\SYSTEM32\ZE5FS9ARSE1461.BIN
C:\WINDOWS\Z5597TRO92485.BIN
C:\WINDOWS\Z5869TROJ95.BIN
C:\WINDOWS\Z6909IRUS5B.BIN
C:\WINDOWS\Z7461WORM9B5.BIN
C:\WINDOWS\Z79BSPARSE5919.BIN
C:\WINDOWS\Z89509ACKTOOL3F1.BIN
C:\WINDOWS\Z9AETHIE52511.BIN
C:\WINDOWS\ZF94SPYWARE5669.BIN

Rogue.Agent/Gen-Nullo[EXE-Spec]
C:\WINDOWS\11527NOT-A-VZ9U548C.EXE
C:\WINDOWS\13998NO5-A-VI9UZ72.EXE
C:\WINDOWS\24909NOT-A-VIR5S46Z.EXE
C:\WINDOWS\23797N9T-AZV5RUS11E.EXE
C:\WINDOWS\24305NOZ9A-VIRUS5C.EXE
C:\WINDOWS\5995NOT-Z-VIRUS127.EXE
C:\WINDOWS\9530NOZ-A-VIRU5689.EXE
C:\WINDOWS\SYSTEM32\24116NOT-A-VI5US2Z9.EXE
C:\WINDOWS\SYSTEM32\26083NOT-A-VIR59639Z.EXE
C:\WINDOWS\SYSTEM32\31997NOT-A-5IRUSDAZ.EXE
C:\WINDOWS\SYSTEM32\974Z0NO5-A-VIRUS2B4.EXE

Rogue.Agent/Gen-Nullo[EXE]
C:\WINDOWS\11530SP5MBOTZ9D.EXE
C:\WINDOWS\135139ORZ4D9.EXE
C:\WINDOWS\137509ORMZ34.EXE
C:\WINDOWS\14ZESPARSE2559.EXE
C:\WINDOWS\1528Z5IR9S307.EXE
C:\WINDOWS\1537TROJ6Z59.EXE
C:\WINDOWS\169DADDWA5E2Z35.EXE
C:\WINDOWS\18301SZY529.EXE
C:\WINDOWS\199585AZKTOOL37C.EXE
C:\WINDOWS\1F28BACKD9OR593Z.EXE
C:\WINDOWS\1Z449O5M4C1.EXE
C:\WINDOWS\1Z869VIR5S6279.EXE
C:\WINDOWS\21865HZCKTOOL5B9.EXE
C:\WINDOWS\21B6AD95ARE2Z97.EXE
C:\WINDOWS\233HACKTOO5Z79.EXE
C:\WINDOWS\2359STZAL1933.EXE
C:\WINDOWS\23993SPYZ965.EXE
C:\WINDOWS\2509SPZWARE2365.EXE
C:\WINDOWS\256ZV5R79.EXE
C:\WINDOWS\25C4DZWNLOADE9536.EXE
C:\WINDOWS\295459ACKTOOL47Z.EXE
C:\WINDOWS\27652W5RM6ZA9.EXE
C:\WINDOWS\2F44S5ZWARE9061.EXE
C:\WINDOWS\2Z05SPYWARE397.EXE
C:\WINDOWS\30455WORZ93D.EXE
C:\WINDOWS\30FE9OWNL5ADERZ579.EXE
C:\WINDOWS\32DDT9RE5TZ1887.EXE
C:\WINDOWS\3907TZ5J69C.EXE
C:\WINDOWS\3A1BDOWNLOADER1Z519.EXE
C:\WINDOWS\3A995OWNLOZDER1086.EXE
C:\WINDOWS\3B39BACZDO9R28255.EXE
C:\WINDOWS\3C43DOZN9OADER2585.EXE
C:\WINDOWS\3D96SPYWARE15Z1.EXE
C:\WINDOWS\3Z169TEAL5156.EXE
C:\WINDOWS\3ZFBADDWA9E159.EXE
C:\WINDOWS\49A2SPARS51Z00.EXE
C:\WINDOWS\49B8T5REAZ20183.EXE
C:\WINDOWS\4ZA55ACK9OOR1962.EXE
C:\WINDOWS\4AE59DDZARE2659.EXE
C:\WINDOWS\4BZCSPA59E46.EXE
C:\WINDOWS\538ZT5IEF3971.EXE
C:\WINDOWS\52949PARSE185Z.EXE
C:\WINDOWS\54F3THI9F9Z4.EXE
C:\WINDOWS\5507THRZA925383.EXE
C:\WINDOWS\592CZPARSE549.EXE
C:\WINDOWS\575BT9REAZ16472.EXE
C:\WINDOWS\5963TR5JZF0.EXE
C:\WINDOWS\5DBS9EAZ2810.EXE
C:\WINDOWS\5Z31SP9MBO54A9.EXE
C:\WINDOWS\62Z4SPAMBOT5795.EXE
C:\WINDOWS\6B6FZHRE5T16794.EXE
C:\WINDOWS\71F9BACKDOZ52104.EXE
C:\WINDOWS\901ASTEZ52185.EXE
C:\WINDOWS\7Z39THIEF1954.EXE
C:\WINDOWS\80Z3WO5M19.EXE
C:\WINDOWS\9837SPZM5OT6C99.EXE
C:\WINDOWS\9C6ZSPA5SE2067.EXE
C:\WINDOWS\9ZF3SPARS51842.EXE
C:\WINDOWS\RESDEFE.EXE
C:\WINDOWS\SYSTEM32\5520ZP9WARE1652.EXE
C:\WINDOWS\SYSTEM32\10270TRO938Z5.EXE
C:\WINDOWS\SYSTEM32\1156ZHRE9T11752.EXE
C:\WINDOWS\SYSTEM32\12369VIR5S9Z5.EXE
C:\WINDOWS\SYSTEM32\165H5CK9OOL6ZA.EXE
C:\WINDOWS\SYSTEM32\15052HACZTOO94BB.EXE
C:\WINDOWS\SYSTEM32\15C9THIEFZ889.EXE
C:\WINDOWS\SYSTEM32\18982HACKTZ5L41A.EXE
C:\WINDOWS\SYSTEM32\17180HACKT5O92CZ.EXE
C:\WINDOWS\SYSTEM32\1970BA9KDOOR15Z.EXE
C:\WINDOWS\SYSTEM32\192975PAMBOT6EBZ.EXE
C:\WINDOWS\SYSTEM32\196065IR9S719Z.EXE
C:\WINDOWS\SYSTEM32\19991WOR534Z.EXE
C:\WINDOWS\SYSTEM32\19Z2ADDWA5E2991.EXE
C:\WINDOWS\SYSTEM32\1A61ZAC59OOR1877.EXE
C:\WINDOWS\SYSTEM32\1D5BV5R1950Z.EXE
C:\WINDOWS\SYSTEM32\2210ZW95M3C9.EXE
C:\WINDOWS\SYSTEM32\22814SP965Z.EXE
C:\WINDOWS\SYSTEM32\26496TROZ5B9.EXE
C:\WINDOWS\SYSTEM32\26544T9OZAC.EXE
C:\WINDOWS\SYSTEM32\29Z619PA5BOT39.EXE
C:\WINDOWS\SYSTEM32\289BST5AL12Z6.EXE
C:\WINDOWS\SYSTEM32\29496SZY55F.EXE
C:\WINDOWS\SYSTEM32\2CF5ZI92452.EXE
C:\WINDOWS\SYSTEM32\2DC3VI91975Z.EXE
C:\WINDOWS\SYSTEM32\2Z5DVIR995.EXE
C:\WINDOWS\SYSTEM32\30548SZ56B19.EXE
C:\WINDOWS\SYSTEM32\309ADZW5LOADER2839.EXE
C:\WINDOWS\SYSTEM32\31334HACKTO5LZ94.EXE
C:\WINDOWS\SYSTEM32\31780ZROJ9AE5.EXE
C:\WINDOWS\SYSTEM32\36ACT5I9F852Z.EXE
C:\WINDOWS\SYSTEM32\3A96DZWNLOADER5779.EXE
C:\WINDOWS\SYSTEM32\3E5EBAZKDOO92139.EXE
C:\WINDOWS\SYSTEM32\3Z9605IRUS1859.EXE
C:\WINDOWS\SYSTEM32\4246ST5AL995Z.EXE
C:\WINDOWS\SYSTEM32\45F3THZEAT2955.EXE
C:\WINDOWS\SYSTEM32\46C5ZTE9L3092.EXE
C:\WINDOWS\SYSTEM32\50570WZRM2F9.EXE
C:\WINDOWS\SYSTEM32\509ZPAR5E2865.EXE
C:\WINDOWS\SYSTEM32\5266ZVIRUS90.EXE
C:\WINDOWS\SYSTEM32\54690VZRU9470.EXE
C:\WINDOWS\SYSTEM32\555ADDWARZ9363.EXE
C:\WINDOWS\SYSTEM32\5599THZ5AT17356.EXE
C:\WINDOWS\SYSTEM32\55Z79ORM9.EXE
C:\WINDOWS\SYSTEM32\564ZT5OJ3E29.EXE
C:\WINDOWS\SYSTEM32\5651T9IZF270.EXE
C:\WINDOWS\SYSTEM32\568ZS9Y710.EXE
C:\WINDOWS\SYSTEM32\58C6ZHR9A56424.EXE
C:\WINDOWS\SYSTEM32\592FTZIEF108.EXE
C:\WINDOWS\SYSTEM32\5979ZIR945.EXE
C:\WINDOWS\SYSTEM32\5D6FTHREAT1697Z.EXE
C:\WINDOWS\SYSTEM32\5Z57T9IEF88.EXE
C:\WINDOWS\SYSTEM32\630BB9CZDOOR7615.EXE
C:\WINDOWS\SYSTEM32\6Z59SPY5959.EXE
C:\WINDOWS\SYSTEM32\7F0CBACKD5O9Z44.EXE
C:\WINDOWS\SYSTEM32\9673SPZ577.EXE
C:\WINDOWS\SYSTEM32\91B5TEALZ074.EXE
C:\WINDOWS\SYSTEM32\9995HACZTOOLC5.EXE
C:\WINDOWS\SYSTEM32\9Z43HACKTOOL59C.EXE
C:\WINDOWS\SYSTEM32\AFDBA9KDOOZ2952.EXE
C:\WINDOWS\SYSTEM32\AZ65TE9L3170.EXE
C:\WINDOWS\SYSTEM32\B80ZPYWAR95393.EXE
C:\WINDOWS\SYSTEM32\C29ZHREA58892.EXE
C:\WINDOWS\SYSTEM32\Z336SPYW9RE5225.EXE
C:\WINDOWS\SYSTEM32\Z1DBSP5RSE3927.EXE
C:\WINDOWS\SYSTEM32\Z582S9ARSE2275.EXE
C:\WINDOWS\SYSTEM32\ZB5ESPARS91616.EXE
C:\WINDOWS\Z4378WORM495.EXE

Rogue.Agent/Gen-Nullo[CPL]
C:\WINDOWS\11933HAZKTOOLB95.CPL
C:\WINDOWS\1415ZVIRUS590.CPL
C:\WINDOWS\13795HACKTOOL9BZ5.CPL
C:\WINDOWS\139005PYZ5A.CPL
C:\WINDOWS\15E9ZOWNLOADER945.CPL
C:\WINDOWS\1803Z5ROJ5B59.CPL
C:\WINDOWS\1834ZSPAMB95179.CPL
C:\WINDOWS\1855ZDDW9RE21.CPL
C:\WINDOWS\18899PARZE2165.CPL
C:\WINDOWS\194ZT5REAT11060.CPL
C:\WINDOWS\19755WORM7B9Z.CPL
C:\WINDOWS\1AF9DOWNLOADER25Z1.CPL
C:\WINDOWS\1D69DOWNLOADZ5679.CPL
C:\WINDOWS\1ECBADDWZRE9549.CPL
C:\WINDOWS\1Z3599PYDB.CPL
C:\WINDOWS\218V5RUZ49E.CPL
C:\WINDOWS\223159OZMDC.CPL
C:\WINDOWS\230BZHRE9T57855.CPL
C:\WINDOWS\23557SPAMBOTZ995.CPL
C:\WINDOWS\24180HA5ZT9OL5C4.CPL
C:\WINDOWS\25ZAVIR9293.CPL
C:\WINDOWS\26490WORM58EZ.CPL
C:\WINDOWS\26608TR5Z48A9.CPL
C:\WINDOWS\27ATZ5EAT157939.CPL
C:\WINDOWS\29535HAC9TZO54FD.CPL
C:\WINDOWS\29D5ADDZARE456.CPL
C:\WINDOWS\2C52ZHR5AT4729.CPL
C:\WINDOWS\2D59SPARSZ5532.CPL
C:\WINDOWS\313ZADD5A9E604.CPL
C:\WINDOWS\2Z819TR5J62B9.CPL
C:\WINDOWS\3093STEAL1595Z.CPL
C:\WINDOWS\345DSPYZARE9256.CPL
C:\WINDOWS\35C5SPYWAZE9695.CPL
C:\WINDOWS\3Z1S9ARSE3521.CPL
C:\WINDOWS\402V5R5Z9.CPL
C:\WINDOWS\442ASTE9L59Z5.CPL
C:\WINDOWS\4581THZEF759.CPL
C:\WINDOWS\4656STEAZ5269.CPL
C:\WINDOWS\51BZ9IR2778.CPL
C:\WINDOWS\54618WORM9CZ.CPL
C:\WINDOWS\553HA9KTOOZ690.CPL
C:\WINDOWS\556759ACKTOZL194.CPL
C:\WINDOWS\5575ZP9RSE2886.CPL
C:\WINDOWS\55Z6V9R2068.CPL
C:\WINDOWS\56FBDO59LOADZR2326.CPL
C:\WINDOWS\5Z67ST5AL1904.CPL
C:\WINDOWS\5BZEDOWNLO9D5R1960.CPL
C:\WINDOWS\5C66THIEZ3955.CPL
C:\WINDOWS\6AE4BACKDOO59Z09.CPL
C:\WINDOWS\6004A9DWARZ2554.CPL
C:\WINDOWS\6599ZTEAL25875.CPL
C:\WINDOWS\66A8THIE53Z91.CPL
C:\WINDOWS\67559IZ5.CPL
C:\WINDOWS\683ZTHREAT5909.CPL
C:\WINDOWS\6AAFVZR5619.CPL
C:\WINDOWS\6B49TH5E9165Z.CPL
C:\WINDOWS\6B98VI5Z105.CPL
C:\WINDOWS\6D81BACKDOZR9526.CPL
C:\WINDOWS\6E3FDOWNLO5ZER5849.CPL
C:\WINDOWS\6EE8ZI91057.CPL
C:\WINDOWS\7015AD59ARE1300Z.CPL
C:\WINDOWS\791SPAR5E235Z.CPL
C:\WINDOWS\7559SPYWARE23Z0.CPL
C:\WINDOWS\7969DOWNLOAZE51937.CPL
C:\WINDOWS\8575HAZK9OOL1DF.CPL
C:\WINDOWS\9355STEAZ672.CPL
C:\WINDOWS\9506ZIR9S578.CPL
C:\WINDOWS\959ZTHIEF445.CPL
C:\WINDOWS\99D5ZHIEF51.CPL
C:\WINDOWS\B1DTHIEF950Z.CPL
C:\WINDOWS\SYSTEM32\11119W9R5Z53.CPL
C:\WINDOWS\SYSTEM32\1196ZOWNL5ADER619.CPL
C:\WINDOWS\SYSTEM32\15040SPYZ909.CPL
C:\WINDOWS\SYSTEM32\1520B9CKDOOR50Z4.CPL
C:\WINDOWS\SYSTEM32\1550ZVIR9S32E.CPL
C:\WINDOWS\SYSTEM32\15Z90VIR5SE2.CPL
C:\WINDOWS\SYSTEM32\18755WOR974CZ.CPL
C:\WINDOWS\SYSTEM32\26254SZY6359.CPL
C:\WINDOWS\SYSTEM32\259935IRUS70Z9.CPL
C:\WINDOWS\SYSTEM32\26233WZ5M21C9.CPL
C:\WINDOWS\SYSTEM32\26773ZP5439.CPL
C:\WINDOWS\SYSTEM32\2E85DZWNLOADE924475.CPL
C:\WINDOWS\SYSTEM32\2C38SP5WARZ1089.CPL
C:\WINDOWS\SYSTEM32\30Z5THI591111.CPL
C:\WINDOWS\SYSTEM32\319Z59ORM505.CPL
C:\WINDOWS\SYSTEM32\34C5SPARSEZ951.CPL
C:\WINDOWS\SYSTEM32\353ZST9AL1161.CPL
C:\WINDOWS\SYSTEM32\37559ZR1233.CPL
C:\WINDOWS\SYSTEM32\3E65DO9NLZADER5387.CPL
C:\WINDOWS\SYSTEM32\4159ADDWAR522Z9.CPL
C:\WINDOWS\SYSTEM32\47EATH9EFZ575.CPL
C:\WINDOWS\SYSTEM32\4C53BZCKDO5R21449.CPL
C:\WINDOWS\SYSTEM32\4D1ATH5EF3293Z.CPL
C:\WINDOWS\SYSTEM32\4FE0VZR5291.CPL
C:\WINDOWS\SYSTEM32\5242VZ9US150.CPL
C:\WINDOWS\SYSTEM32\54B2SPARS9Z115.CPL
C:\WINDOWS\SYSTEM32\54Z58WOR9451.CPL
C:\WINDOWS\SYSTEM32\5589VIRUSZD.CPL
C:\WINDOWS\SYSTEM32\5C39ST5AZ29149.CPL
C:\WINDOWS\SYSTEM32\5922HACKTOOLZB9.CPL
C:\WINDOWS\SYSTEM32\5B5DDOWNLO9DERZ490.CPL
C:\WINDOWS\SYSTEM32\5C5FDOWN95ADZR948.CPL
C:\WINDOWS\SYSTEM32\5FF8BACKDOO5Z912.CPL
C:\WINDOWS\SYSTEM32\6471SPAMB9T2Z5.CPL
C:\WINDOWS\SYSTEM32\649AS5EAL1Z74.CPL
C:\WINDOWS\SYSTEM32\6758SPY95REZ541.CPL
C:\WINDOWS\SYSTEM32\6A91STZ5L295.CPL
C:\WINDOWS\SYSTEM32\6B75TZREA914953.CPL
C:\WINDOWS\SYSTEM32\6C54THIE9Z289.CPL
C:\WINDOWS\SYSTEM32\75D49PYWARE3092Z.CPL
C:\WINDOWS\SYSTEM32\7151ZACKD9OR968.CPL
C:\WINDOWS\SYSTEM32\7593ZIR2583.CPL
C:\WINDOWS\SYSTEM32\7795SPARSE9307Z.CPL
C:\WINDOWS\SYSTEM32\92165WZRM2BA.CPL
C:\WINDOWS\SYSTEM32\9412S5Y5ZF.CPL
C:\WINDOWS\SYSTEM32\9953TROJ2Z65.CPL
C:\WINDOWS\SYSTEM32\984AADDWARE1053Z.CPL
C:\WINDOWS\SYSTEM32\9DB1ADDZAR5122.CPL
C:\WINDOWS\SYSTEM32\9F94S5YWZRE2857.CPL
C:\WINDOWS\SYSTEM32\E3B5I978Z.CPL
C:\WINDOWS\SYSTEM32\Z2590SPAMBOT9885.CPL
C:\WINDOWS\SYSTEM32\Z299A5DWAR92854.CPL
C:\WINDOWS\SYSTEM32\Z45AADDWAR512749.CPL
C:\WINDOWS\Z0589TROJ332.CPL
C:\WINDOWS\Z1565SPY5989.CPL
C:\WINDOWS\Z2552SP5269.CPL
C:\WINDOWS\Z268SPAMB9T586.CPL
C:\WINDOWS\Z2EDSPY9ARE2534.CPL
C:\WINDOWS\Z324SPAR5E2219.CPL
C:\WINDOWS\Z94645PY92E.CPL
C:\WINDOWS\Z5A0B9CK5OOR250.CPL
C:\WINDOWS\Z952BACK9OOR356.CPL
C:\WINDOWS\ZB83S9YWARE1785.CPL

Rogue.Agent/Gen-Nullo[OCX]
C:\WINDOWS\12525ZPY7569.OCX
C:\WINDOWS\13DZTHREAT96055.OCX
C:\WINDOWS\162639ACKZ5OL10D.OCX
C:\WINDOWS\173Z9VI9US1DB5.OCX
C:\WINDOWS\19188WORM6Z15.OCX
C:\WINDOWS\19419SP5M9ZT1FE.OCX
C:\WINDOWS\197TH5EF952Z.OCX
C:\WINDOWS\19927ZAC5TOOL5CF.OCX
C:\WINDOWS\1F5EZPYWAR91145.OCX
C:\WINDOWS\22023ZROJ95D.OCX
C:\WINDOWS\211525I9US7Z9.OCX
C:\WINDOWS\222375ZOJ59C.OCX
C:\WINDOWS\257ZHACKTO9L53D.OCX
C:\WINDOWS\289Z0W5RM22E.OCX
C:\WINDOWS\28Z95OWN9OADER2218.OCX
C:\WINDOWS\29B25TEAL2Z95.OCX
C:\WINDOWS\2BZ4THIEF16359.OCX
C:\WINDOWS\2D32SZ5WARE6559.OCX
C:\WINDOWS\35C0THRZA911558.OCX
C:\WINDOWS\318ZSP9MBOT5125.OCX
C:\WINDOWS\326CTHIEFZ598.OCX
C:\WINDOWS\3865ZT9AL630.OCX
C:\WINDOWS\39BBTHR5AZ20628.OCX
C:\WINDOWS\3CAZAD59ARE2240.OCX
C:\WINDOWS\3Z8CDOWN9OADER25165.OCX
C:\WINDOWS\3Z9DADDWARE1651.OCX
C:\WINDOWS\45EZSPARSE2995.OCX
C:\WINDOWS\42CFZDDW9RE2956.OCX
C:\WINDOWS\44E5I9Z069.OCX
C:\WINDOWS\4539SPARSE1393Z.OCX
C:\WINDOWS\45ABZAC9DOOR3156.OCX
C:\WINDOWS\4619TZOJ57A.OCX
C:\WINDOWS\48ZADD95RE589.OCX
C:\WINDOWS\4956SPARSZ9015.OCX
C:\WINDOWS\4CD6SPAZ951283.OCX
C:\WINDOWS\4DD95PARSE1Z16.OCX
C:\WINDOWS\51B6D9WNLOAZER2217.OCX
C:\WINDOWS\52185PYZ9C.OCX
C:\WINDOWS\52A5SPARS9286Z.OCX
C:\WINDOWS\5652W59M7D0Z.OCX
C:\WINDOWS\5691VI51Z06.OCX
C:\WINDOWS\56FESPA5SE29Z4.OCX
C:\WINDOWS\5ABETHIEF9855Z.OCX
C:\WINDOWS\5D929HREAZ3595.OCX
C:\WINDOWS\5F7DTHIEF9Z56.OCX
C:\WINDOWS\6044T5IE9636Z.OCX
C:\WINDOWS\60FA5Z9EF1844.OCX
C:\WINDOWS\69Z49I52388.OCX
C:\WINDOWS\6CD2SZYWA591119.OCX
C:\WINDOWS\6Z28SPY5ARE1969.OCX
C:\WINDOWS\74F9T9IEZ1525.OCX
C:\WINDOWS\7617BA5KD9ZR3104.OCX
C:\WINDOWS\7781VZ9254.OCX
C:\WINDOWS\7E5ZADDWAR9288.OCX
C:\WINDOWS\7Z5VIRUSA9.OCX
C:\WINDOWS\7Z69T5OJ86.OCX
C:\WINDOWS\9439SP5Z91.OCX
C:\WINDOWS\90809TROJZ54.OCX
C:\WINDOWS\93559VIZU5100.OCX
C:\WINDOWS\935VIRZS759.OCX
C:\WINDOWS\9531TR9J52Z5.OCX
C:\WINDOWS\954ZSPY5.OCX
C:\WINDOWS\959SPARS52735Z.OCX
C:\WINDOWS\9692ADDWZRE1385.OCX
C:\WINDOWS\988HACZTOO9599.OCX
C:\WINDOWS\99Z0SPAMBOT3615.OCX
C:\WINDOWS\9F25DOWNLOADEZ15475.OCX
C:\WINDOWS\BEZSPYWARE259.OCX
C:\WINDOWS\C93ADDWARE14Z75.OCX
C:\WINDOWS\FB5BAC9DOZR570.OCX
C:\WINDOWS\SYSTEM32\1063TH9EF303Z5.OCX
C:\WINDOWS\SYSTEM32\12685SP963Z.OCX
C:\WINDOWS\SYSTEM32\14299HZCKTOOL3975.OCX
C:\WINDOWS\SYSTEM32\1540VI9UZ155.OCX
C:\WINDOWS\SYSTEM32\15509WOR9Z36.OCX
C:\WINDOWS\SYSTEM32\1690THREAT13Z085.OCX
C:\WINDOWS\SYSTEM32\18785SPZMBOT3EC9.OCX
C:\WINDOWS\SYSTEM32\1923SZYWAR515189.OCX
C:\WINDOWS\SYSTEM32\1951ZPAMBOT975.OCX
C:\WINDOWS\SYSTEM32\19BEZ9ARSE259.OCX
C:\WINDOWS\SYSTEM32\1Z786HACKTOOL596.OCX
C:\WINDOWS\SYSTEM32\2099STEAL1Z75.OCX
C:\WINDOWS\SYSTEM32\22555ZROJ4FA9.OCX
C:\WINDOWS\SYSTEM32\26942WOR5736Z.OCX
C:\WINDOWS\SYSTEM32\27153SPA9BOT6D2Z.OCX
C:\WINDOWS\SYSTEM32\296ZSPARSE30245.OCX
C:\WINDOWS\SYSTEM32\2B35AZDWA9E2079.OCX
C:\WINDOWS\SYSTEM32\2BA95OZNLOADER2503.OCX
C:\WINDOWS\SYSTEM32\303749ZRM5D5.OCX
C:\WINDOWS\SYSTEM32\355HZCKT9OL696.OCX
C:\WINDOWS\SYSTEM32\3EZEDOWNLOA5ER909.OCX
C:\WINDOWS\SYSTEM32\3Z14SPARSE1539.OCX
C:\WINDOWS\SYSTEM32\3Z211H95KTOOL475.OCX
C:\WINDOWS\SYSTEM32\3Z466SPY7579.OCX
C:\WINDOWS\SYSTEM32\4359STE9LZ264.OCX
C:\WINDOWS\SYSTEM32\442S5Y9AZE3022.OCX
C:\WINDOWS\SYSTEM32\4D539HREATZ6980.OCX
C:\WINDOWS\SYSTEM32\49B2SPYWARZ21765.OCX
C:\WINDOWS\SYSTEM32\49C4SZARSE2285.OCX
C:\WINDOWS\SYSTEM32\5191THREAZ25934.OCX
C:\WINDOWS\SYSTEM32\50AF9HIZF353.OCX
C:\WINDOWS\SYSTEM32\5253SZY2F9.OCX
C:\WINDOWS\SYSTEM32\52DCA9DWARZ4575.OCX
C:\WINDOWS\SYSTEM32\5509DOWNZOADER3264.OCX
C:\WINDOWS\SYSTEM32\55B7ZHREAT991045.OCX
C:\WINDOWS\SYSTEM32\5786SZY495.OCX
C:\WINDOWS\SYSTEM32\59799P5ZBOT70A.OCX
C:\WINDOWS\SYSTEM32\5B46VIR429Z.OCX
C:\WINDOWS\SYSTEM32\5BZ8S9YWA5E2399.OCX
C:\WINDOWS\SYSTEM32\5CC0DOWN9ZADER2641.OCX
C:\WINDOWS\SYSTEM32\6D44THIEZ9582.OCX
C:\WINDOWS\SYSTEM32\67F4TH5EA9Z379.OCX
C:\WINDOWS\SYSTEM32\67FZ5OWNL9ADER764.OCX
C:\WINDOWS\SYSTEM32\6910TH5EAT28Z90.OCX
C:\WINDOWS\SYSTEM32\6965WORZ4F9.OCX
C:\WINDOWS\SYSTEM32\6F98A5D9AREZ84.OCX
C:\WINDOWS\SYSTEM32\7283ZA5KDOOR982.OCX
C:\WINDOWS\SYSTEM32\7295VIRZ05.OCX
C:\WINDOWS\SYSTEM32\75ZDT9IEF1529.OCX
C:\WINDOWS\SYSTEM32\7D5B9HREATZ9700.OCX
C:\WINDOWS\SYSTEM32\7DB1S9ZWARE1485.OCX
C:\WINDOWS\SYSTEM32\8CF95IEF2457Z.OCX
C:\WINDOWS\SYSTEM32\92555SPAMBOTZ18.OCX
C:\WINDOWS\SYSTEM32\962915ORM40AZ.OCX
C:\WINDOWS\SYSTEM32\971585RZJ799.OCX
C:\WINDOWS\SYSTEM32\97Z75PARSE3138.OCX
C:\WINDOWS\SYSTEM32\986ZVIR5S781.OCX
C:\WINDOWS\SYSTEM32\99733S5AZBOT79A.OCX
C:\WINDOWS\SYSTEM32\99B4BACK5OZR2868.OCX
C:\WINDOWS\SYSTEM32\9EZBVIR5199.OCX
C:\WINDOWS\SYSTEM32\9F9VI519Z0.OCX
C:\WINDOWS\SYSTEM32\9ZCCBACKDOOR2365.OCX
C:\WINDOWS\SYSTEM32\B93VI5Z4.OCX
C:\WINDOWS\SYSTEM32\D3BST9ALZ505.OCX
C:\WINDOWS\SYSTEM32\E9DVIZ15595.OCX
C:\WINDOWS\SYSTEM32\Z865BACKDOOR3249.OCX
C:\WINDOWS\SYSTEM32\Z395VIRUS243.OCX
C:\WINDOWS\SYSTEM32\Z4C4BACKDO9R2551.OCX
C:\WINDOWS\SYSTEM32\Z62S9AR5E497.OCX
C:\WINDOWS\SYSTEM32\Z7E9SPAR5E2022.OCX
C:\WINDOWS\SYSTEM32\ZA15V9R1123.OCX
C:\WINDOWS\Z315T5OJ5B9.OCX
C:\WINDOWS\Z5061VI9US62F.OCX

Rogue.Agent/Gen-Nullo[BIN-Spec]
C:\WINDOWS\1612ZNO59A-VIRUS480.BIN
C:\WINDOWS\2539ZNOT-A-VIRUS7C75.BIN
C:\WINDOWS\279565OT-A-VIRU9Z4.BIN
C:\WINDOWS\5688NOT-Z-V5RUS1B9.BIN
C:\WINDOWS\SYSTEM32\22615N5T-Z-VIRUS295.BIN
C:\WINDOWS\SYSTEM32\28157NOTZA-VIRUS599.BIN
C:\WINDOWS\SYSTEM32\27565NO5-A-VIRUS6Z9.BIN

Rogue.Agent/Gen-Nullo[DLL-Spec]
C:\WINDOWS\17085NOZ-A9VIRUS5D5.DLL
C:\WINDOWS\20Z19NOT-9-5IRUSEE.DLL
C:\WINDOWS\26758NOT5A-VZRUS9A4.DLL
C:\WINDOWS\SYSTEM32\17439NOT-AZV9RU5735.DLL
C:\WINDOWS\SYSTEM32\28620N9Z-5-VIRUS25.DLL
C:\WINDOWS\SYSTEM32\52300NOT-Z-VIRU91F5.DLL

Edited by Chis, 29 December 2009 - 01:28 PM.


BC AdBot (Login to Remove)

 


#2 Chis

Chis
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 30 December 2009 - 09:46 AM

Dad got back into his email today, but all of his email messages were deleted ... :thumbsup:
I'm still wondering how he managed to get so much junk on his computer.

#3 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:57 AM

Posted 30 December 2009 - 11:39 AM

Hello and welcome. You need to upadte both MBAM and SAS and rescan . Some of those in SAS were False positives,fixed in the update. If they still show then they are real.

You shold change all Passwords from a non infected PC for now.

Rerun MBAM (MalwareBytes) like this:

Open MBAM in normal mode and click Update tab, select Check for Updates,when done
click Scanner tab,select Quick scan and scan (normal mode).
After scan click Remove Selected, Post new scan log and Reboot into normal mode.


Open SUPER from icon and Update it
Under Scanner Options make sure the following are checked (leave all others unchecked):
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining
.
Click the "Close" button to leave the control center screen and exit the program. DO NOT run yet.

Now reboot into Safe Mode: How to enter safe mode(XP)
Using the F8 Method
Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode
.


Next if using a router,you must reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds). If you donít know the router's default password, you can look it up HERE.

Edited by boopme, 30 December 2009 - 11:41 AM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#4 Chis

Chis
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 30 December 2009 - 09:00 PM

Thanks, boopme!

MBAM came up clean.

Malwarebytes' Anti-Malware 1.43
Database version: 3460
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/30/2009 8:55:48 PM
mbam-log-2009-12-30 (20-55-48).txt

Scan type: Quick Scan
Objects scanned: 146370
Time elapsed: 12 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


I'm going to assume I run SAS in safe mode, so I'll do that now :thumbsup:

By the way, my dad is also having issues with the printer (HP Officejet Pro). He's able to print, but he can't scan. It's funny because this is a networked computer and the two other computers in the network can both print and scan. Could this have anything to do with malware?

#5 Chis

Chis
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 30 December 2009 - 09:12 PM

Sorry, and after I reset my router, my laptop can't find it anymore through wireless connection. Does it change names when you reset it? Or do I have to do some extra fiddling on my dad's computer?

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:57 AM

Posted 30 December 2009 - 09:43 PM

I think he has many corrupted files now from all the malwares.
The majority of infection are delivered thru Email ( maybe a blessing they got tossed). What antivirus is being used as it should scan email first. Also there no defense if one opens attachments with links if they do not scan them first.

You can un and reinstall the printer..Maybe need to ask the experts in hardware or netwoking on the best way.
Reconfigure the network connection . Like when you first set it up.

Maybe run one or both of these first.

Please run System File Checker sfc /scannow... For more information on this tool see How To Use Sfc.exe To Repair System Files


You will need your operating system CD handy.

Open Windows Task Manager....by pressing CTRL+SHIFT+ESC

Then click File.. then New Task(Run)

In the box that opens type sfc /scannow ......There is a space between c and /

Click OK
Let it run and insert the XP CD when asked.


Dial-A-Fix
We need to repair some of windows' internal registration settings
  • Please download Dial-A-Fix from one of the following mirrors:
  • Extract the zip file to your desktop.
  • Double click Dial-a-Fix.exe to start the program.
  • Press the green double checkmark box (Looks like this: Posted Image)
  • UNcheck "Empty Temp Folders", as well as "Adjust Time/Date" in the prep section. The prep section should then look like this:
    Posted Image
  • When the window looks like this, press the GO button in the bottom of the window.
    Posted Image
  • Exit/Close Dial-A-Fix

Edited by boopme, 30 December 2009 - 09:44 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 Chis

Chis
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:03:57 AM

Posted 31 December 2009 - 03:30 PM

He actually didn't have any antivirus software before now (just installed Avira after the infection).
I tried to run system file checker. The first time it started successfully, and I thought there were no problems with any of the internal files because it never prompted me and it just disappeared by itself.
But then I ran dial-a-fix and near the end there were a bunch of problems - it kept saying that certain files in the system32 folder were not registerable or corrupted, like iesetup, inseng, mshtml, msrating ...
So then I thought, maybe system file checker never completed after all, and I tried to rerun it, but now all that happens is a black box briefly flashes and disappears. :S

Here is the log for SAS.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/30/2009 at 09:54 PM

Application Version : 4.32.1000

Core Rules Database Version : 4428
Trace Rules Database Version: 2254

Scan type : Complete Scan
Total Scan Time : 00:51:35

Memory items scanned : 234
Memory threats detected : 0
Registry items scanned : 8154
Registry threats detected : 0
File items scanned : 93945
File threats detected : 6

Adware.Tracking Cookie
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@atdmt[2].txt
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@ads.monster[1].txt
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@collective-media[1].txt
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@doubleclick[2].txt
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@mmstat[2].txt
C:\Documents and Settings\JOEL ORENSTEIN\Cookies\joel_orenstein@ads.bleepingcomputer[1].txt

#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,199 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:04:57 AM

Posted 31 December 2009 - 04:14 PM

Ok, it's definate that they have many corrupted files.. You will need to do either a Repair or a Full with format or you will continue to have issues.

Your decision as to what action to take should be made by reading and asking yourself the questions presented in "When Should I Format, How Should I Reinstall?" In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. Wiping your drive, reformatting, and performing a clean install of the OS or doing a factory restore removes everything and is the safest action but I cannot make that decision for you.

Reformatting a hard disk deletes all data. If you decide to reformat, you can back up all your important documents, data files and photos. The safest practice is not to backup any autorun.ini or .exe files because they may be infected. Some types of malware may disguise itself by adding and hiding its extension to the existing extension of files so be sure you take a close look at the full name. After reformatting, as a precaution, make sure you scan these files with your anti-virus prior to copying them back to your hard drive.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users