Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help Needed...


  • This topic is locked This topic is locked
21 replies to this topic

#1 Dark Phoenix

Dark Phoenix

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 20 January 2007 - 11:25 AM

Lately I've been getting all sorts of popups and computer problems due to spyware infections. I've got Spybot, Ad-Aware, and SpywareBlaster installed and I run each of them almost daily, but the spyware seems to regenerate itself.

Here's a Hijack This log I just made:

Logfile of HijackThis v1.99.1
Scan saved at 20:07:46, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE
C:\WINDOWS\system32\msnmsgrs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Name\Desktop\Maintenance\HJT.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://admin:password@192.168.0.1/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {402A6F08-4258-4E5B-9C5C-A1219E3FE688} - C:\WINDOWS\system32\vtstu.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\xcbsorxv.dll
O2 - BHO: (no name) - {8DD305CF-9E07-B8DA-2053-9F5B51593195} - C:\WINDOWS\system32\ntfypbg.dll
O2 - BHO: (no name) - {91C916F5-0750-43B3-AB12-814B881ED309} - C:\WINDOWS\system32\ljjifff.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: (no name) - {B77262D7-779C-40BF-9F66-CF8443DB77AF} - C:\WINDOWS\system32\vtstu.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [Windows Load] C:\WINDOWS\system32\msnmsgrs.exe
O4 - HKLM\..\Run: [{FC073F61-0BB0-1033-1108-05011205002c}] "C:\Program Files\Common Files\{FC073F61-0BB0-1033-1108-05011205002c}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [WINDOWS] c:\qlcojek.exe
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\gohqomda.dll",setvm
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ljjifff - C:\WINDOWS\SYSTEM32\ljjifff.dll
O20 - Winlogon Notify: vtstu - C:\WINDOWS\system32\vtstu.dll
O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000272 (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


Thanks in advance.

EDIT: I've renamed it HJT.exe and re-done the scan.

Edited by Dark Phoenix, 21 January 2007 - 08:57 AM.


BC AdBot (Login to Remove)

 


#2 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:06 AM

Posted 20 January 2007 - 01:34 PM

Hi Dark Phoenix

Rename HijackThis.exe to HJT.exe and send a fresh HijackThis log, please :thumbsup:
Microsoft MVP Consumer Security
Posted Image

Posted Image

#3 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 20 January 2007 - 03:11 PM

Hi Dark Phoenix

Rename HijackThis.exe to HJT.exe and send a fresh HijackThis log, please :thumbsup:


Done. I've edited my post now.

#4 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:06 AM

Posted 21 January 2007 - 04:51 AM

Hi

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Send:

- a fresh HijackThis log
- vundofix report
- combofix report
Microsoft MVP Consumer Security
Posted Image

Posted Image

#5 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 21 January 2007 - 08:56 AM

Hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 13:54:33, on 21/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE
C:\WINDOWS\system32\msnmsgrs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Name\Desktop\Maintenance\HJT.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://admin:password@192.168.0.1/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\xcbsorxv.dll (file missing)
O2 - BHO: (no name) - {8DD305CF-9E07-B8DA-2053-9F5B51593195} - C:\WINDOWS\system32\ntfypbg.dll
O2 - BHO: (no name) - {91C916F5-0750-43B3-AB12-814B881ED309} - C:\WINDOWS\system32\ljjifff.dll (file missing)
O2 - BHO: (no name) - {95658D6F-E93D-4AD4-BBB2-AD572CD880DC} - C:\WINDOWS\system32\vtstu.dll (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [Windows Load] C:\WINDOWS\system32\msnmsgrs.exe
O4 - HKLM\..\Run: [WINDOWS] c:\qlcojek.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


Edited by Dark Phoenix, 21 January 2007 - 11:43 AM.


#6 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:06 AM

Posted 21 January 2007 - 09:11 AM

Hi

Vundofix log is so big that it cuts off .

Please send its log and combofix in separate replies that they won't cut off :thumbsup:
Microsoft MVP Consumer Security
Posted Image

Posted Image

#7 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 21 January 2007 - 11:44 AM

Sorry about that. Here's the VundoFix log:

VundoFix V6.3.2

Checking Java version...

Java version is 1.4.2.3

Java version is 1.5.0.9

Scan started at 13:41:28 21/01/2007

Listing files found while scanning....

C:\WINDOWS\SYSTEM32\aakptrra.exe
C:\WINDOWS\SYSTEM32\abuewadh.exe
C:\WINDOWS\SYSTEM32\admoqhog.ini
C:\WINDOWS\SYSTEM32\admoqhog.ini2
C:\WINDOWS\SYSTEM32\aghqplwl.exe
C:\WINDOWS\SYSTEM32\ahetitie.dll
C:\WINDOWS\SYSTEM32\ahnpdeif.exe
C:\WINDOWS\SYSTEM32\akpoejtr.exe
C:\WINDOWS\SYSTEM32\aktqkvwe.exe
C:\WINDOWS\SYSTEM32\aohctmhp.exe
C:\WINDOWS\SYSTEM32\aolljhiy.exe
C:\WINDOWS\SYSTEM32\apjhhmon.dll
C:\WINDOWS\SYSTEM32\avcgemrb.dll
C:\WINDOWS\SYSTEM32\awrembsb.dll
C:\WINDOWS\SYSTEM32\bakxgufj.dll
C:\WINDOWS\SYSTEM32\bbtdqphg.exe
C:\WINDOWS\SYSTEM32\bcaoixer.exe
C:\WINDOWS\SYSTEM32\bdywcytk.dll
C:\WINDOWS\SYSTEM32\bekvbctu.dll
C:\WINDOWS\SYSTEM32\bgimlook.exe
C:\WINDOWS\SYSTEM32\bhotnoxi.exe
C:\WINDOWS\SYSTEM32\biecoeeo.exe
C:\WINDOWS\SYSTEM32\biricgut.dll
C:\WINDOWS\SYSTEM32\bjojdnyw.exe
C:\WINDOWS\SYSTEM32\bthqhvfi.dll
C:\WINDOWS\SYSTEM32\buhonjga.dll
C:\WINDOWS\SYSTEM32\bujlofht.exe
C:\WINDOWS\SYSTEM32\bulwbdjf.dll
C:\WINDOWS\SYSTEM32\buvlqxdw.dll
C:\WINDOWS\SYSTEM32\bvtnerkv.dll
C:\WINDOWS\SYSTEM32\bxwxclex.dll
C:\WINDOWS\SYSTEM32\byqtdiac.exe
C:\WINDOWS\SYSTEM32\camnvhxt.dll
C:\WINDOWS\SYSTEM32\cdqxhjjk.exe
C:\WINDOWS\SYSTEM32\chvfaggm.dll
C:\WINDOWS\SYSTEM32\ciadhbji.dll
C:\WINDOWS\SYSTEM32\cjnrdcga.exe
C:\WINDOWS\SYSTEM32\ckatjgbi.exe
C:\WINDOWS\SYSTEM32\ckttobiy.dll
C:\WINDOWS\SYSTEM32\clpjfiox.exe
C:\WINDOWS\SYSTEM32\cmibctfs.exe
C:\WINDOWS\SYSTEM32\cprxujvh.exe
C:\WINDOWS\SYSTEM32\cqfjgmqj.dll
C:\WINDOWS\SYSTEM32\crjmbhja.exe
C:\WINDOWS\SYSTEM32\crprxslx.exe
C:\WINDOWS\SYSTEM32\ctltaekh.dll
C:\WINDOWS\SYSTEM32\ctmenyem.exe
C:\WINDOWS\SYSTEM32\cuwgxppg.exe
C:\WINDOWS\SYSTEM32\cwmedspk.dll
C:\WINDOWS\SYSTEM32\cyaqvdst.dll
C:\WINDOWS\SYSTEM32\dgelolic.exe
C:\WINDOWS\SYSTEM32\dgnfwxsv.exe
C:\WINDOWS\SYSTEM32\dmjboxhk.exe
C:\WINDOWS\SYSTEM32\dmqfnxrk.dll
C:\WINDOWS\SYSTEM32\dnkipwwx.exe
C:\WINDOWS\SYSTEM32\dnxqmedw.dll
C:\WINDOWS\SYSTEM32\dpbtaqve.exe
C:\WINDOWS\SYSTEM32\dptdpcjw.exe
C:\WINDOWS\system32\dqfsmrof.dll
C:\WINDOWS\SYSTEM32\dqhbobhc.exe
C:\WINDOWS\SYSTEM32\dtgqwqip.dll
C:\WINDOWS\SYSTEM32\dubawsme.dll
C:\WINDOWS\SYSTEM32\duyhlile.dll
C:\WINDOWS\SYSTEM32\dvaewoid.exe
C:\WINDOWS\SYSTEM32\dvfvorkm.dll
C:\WINDOWS\SYSTEM32\dvuimtik.dll
C:\WINDOWS\SYSTEM32\dvwesorn.dll
C:\WINDOWS\SYSTEM32\dydptwal.exe
C:\WINDOWS\SYSTEM32\eajjbhce.dll
C:\WINDOWS\SYSTEM32\ecgipuwq.exe
C:\WINDOWS\SYSTEM32\egjobfvn.exe
C:\WINDOWS\SYSTEM32\ehqecbeg.exe
C:\WINDOWS\SYSTEM32\eiwpueho.dll
C:\WINDOWS\SYSTEM32\elmiyjsy.exe
C:\WINDOWS\SYSTEM32\enenuksm.exe
C:\WINDOWS\SYSTEM32\eqgeujfs.exe
C:\WINDOWS\SYSTEM32\eqxaymrk.dll
C:\WINDOWS\SYSTEM32\esugmkwo.exe
C:\WINDOWS\SYSTEM32\esylboid.exe
C:\WINDOWS\SYSTEM32\eudaqpgy.exe
C:\WINDOWS\SYSTEM32\evetlqql.exe
C:\WINDOWS\SYSTEM32\evvajseh.dll
C:\WINDOWS\SYSTEM32\ewamdvar.exe
C:\WINDOWS\SYSTEM32\excephbn.exe
C:\WINDOWS\SYSTEM32\exjlqmsy.exe
C:\WINDOWS\SYSTEM32\exkrscts.dll
C:\WINDOWS\SYSTEM32\fgdoieph.dll
C:\WINDOWS\SYSTEM32\fhgbkvyj.dll
C:\WINDOWS\SYSTEM32\fhjodbwj.dll
C:\WINDOWS\SYSTEM32\fikvecqi.dll
C:\WINDOWS\SYSTEM32\fivhgarm.dll
C:\WINDOWS\SYSTEM32\fmjfwhbm.dll
C:\WINDOWS\SYSTEM32\fnlvkfqy.dll
C:\WINDOWS\SYSTEM32\fnrfanlq.exe
C:\WINDOWS\SYSTEM32\fpohiyjj.exe
C:\WINDOWS\SYSTEM32\frywfbte.dll
C:\WINDOWS\SYSTEM32\fwaknbql.exe
C:\WINDOWS\SYSTEM32\fxgeybyd.dll
C:\WINDOWS\SYSTEM32\fxqhktjw.dll
C:\WINDOWS\SYSTEM32\gdjygbyf.dll
C:\WINDOWS\SYSTEM32\gdqnfhwj.exe
C:\WINDOWS\SYSTEM32\gebxvsp.dll
C:\WINDOWS\SYSTEM32\gfjdvgmo.exe
C:\WINDOWS\SYSTEM32\ghdmnsqt.exe
C:\WINDOWS\SYSTEM32\gjdenhkd.dll
C:\WINDOWS\SYSTEM32\gjlxemmx.dll
C:\WINDOWS\SYSTEM32\gkrvyhtp.exe
C:\WINDOWS\SYSTEM32\gohqomda.dll
C:\WINDOWS\SYSTEM32\goxpsddk.dll
C:\WINDOWS\SYSTEM32\grsycrwn.dll
C:\WINDOWS\SYSTEM32\gwyaegbd.dll
C:\WINDOWS\SYSTEM32\hbhkkcxc.dll
C:\WINDOWS\SYSTEM32\hbrnmeqj.dll
C:\WINDOWS\SYSTEM32\hcgmgpaq.exe
C:\WINDOWS\SYSTEM32\hdhcsrjv.dll
C:\WINDOWS\SYSTEM32\hgbpbiev.exe
C:\WINDOWS\SYSTEM32\hjkojtxd.exe
C:\WINDOWS\SYSTEM32\hjvafuys.exe
C:\WINDOWS\SYSTEM32\hpbnejrl.exe
C:\WINDOWS\SYSTEM32\hptpgkkm.exe
C:\WINDOWS\SYSTEM32\hqkdrayv.exe
C:\WINDOWS\SYSTEM32\hrpepjrs.exe
C:\WINDOWS\SYSTEM32\iacxvomw.dll
C:\WINDOWS\SYSTEM32\ichetrgs.dll
C:\WINDOWS\SYSTEM32\idxpvlxu.dll
C:\WINDOWS\SYSTEM32\iesnjbav.exe
C:\WINDOWS\SYSTEM32\ifqdmuxn.exe
C:\WINDOWS\SYSTEM32\iimaoqqo.dll
C:\WINDOWS\SYSTEM32\iksvyppi.exe
C:\WINDOWS\SYSTEM32\iraqmoyf.exe
C:\WINDOWS\SYSTEM32\ircbxfcg.exe
C:\WINDOWS\SYSTEM32\iuawymdc.dll
C:\WINDOWS\SYSTEM32\ixwlrxjv.dll
C:\WINDOWS\SYSTEM32\iyaxsnrd.dll
C:\WINDOWS\SYSTEM32\iybhofft.exe
C:\WINDOWS\SYSTEM32\iymoijid.dll
C:\WINDOWS\SYSTEM32\jagjegks.dll
C:\WINDOWS\SYSTEM32\jbkxkkjn.dll
C:\WINDOWS\SYSTEM32\jdltauuj.exe
C:\WINDOWS\SYSTEM32\jdtdeaql.exe
C:\WINDOWS\SYSTEM32\jgwluemd.exe
C:\WINDOWS\SYSTEM32\jhpwhbso.exe
C:\WINDOWS\SYSTEM32\jichfkem.dll
C:\WINDOWS\SYSTEM32\jiklrqpp.dll
C:\WINDOWS\SYSTEM32\jisnnjaj.exe
C:\WINDOWS\SYSTEM32\jltlsahj.exe
C:\WINDOWS\SYSTEM32\jmeaqpof.exe
C:\WINDOWS\SYSTEM32\jmoctomf.exe
C:\WINDOWS\SYSTEM32\jofckeip.exe
C:\WINDOWS\SYSTEM32\jongfkkf.exe
C:\WINDOWS\SYSTEM32\jpfneexa.exe
C:\WINDOWS\SYSTEM32\jpspfvey.dll
C:\WINDOWS\SYSTEM32\jskqvcwe.exe
C:\WINDOWS\SYSTEM32\jtsosstw.exe
C:\WINDOWS\SYSTEM32\jtwfgxtf.dll
C:\WINDOWS\SYSTEM32\jupvxips.dll
C:\WINDOWS\SYSTEM32\jwjdwyjp.exe
C:\WINDOWS\SYSTEM32\jxhycgbx.exe
C:\WINDOWS\SYSTEM32\jxicnrpf.dll
C:\WINDOWS\SYSTEM32\jxxrkkpa.exe
C:\WINDOWS\SYSTEM32\kdutjgmk.dll
C:\WINDOWS\SYSTEM32\keggvcja.dll
C:\WINDOWS\SYSTEM32\kqawmybq.exe
C:\WINDOWS\SYSTEM32\kvampeme.exe
C:\WINDOWS\SYSTEM32\kvhmlgoe.dll
C:\WINDOWS\SYSTEM32\kwafqgkl.exe
C:\WINDOWS\SYSTEM32\kwqilyvr.exe
C:\WINDOWS\SYSTEM32\kylsyaij.exe
C:\WINDOWS\SYSTEM32\lbaiaabx.dll
C:\WINDOWS\SYSTEM32\lfrjspse.exe
C:\WINDOWS\SYSTEM32\lgehawle.dll
C:\WINDOWS\SYSTEM32\ljjifff.dll
C:\WINDOWS\SYSTEM32\lkbaxeru.exe
C:\WINDOWS\SYSTEM32\lltgxaav.exe
C:\WINDOWS\SYSTEM32\lphvedwl.exe
C:\WINDOWS\SYSTEM32\lpvkyhie.dll
C:\WINDOWS\SYSTEM32\lqfansyq.exe
C:\WINDOWS\SYSTEM32\lxilfhwf.dll
C:\WINDOWS\SYSTEM32\maibxkoc.exe
C:\WINDOWS\SYSTEM32\mdhgduln.dll
C:\WINDOWS\SYSTEM32\mdholjte.dll
C:\WINDOWS\SYSTEM32\mdvyxqdf.dll
C:\WINDOWS\SYSTEM32\mhnotefs.dll
C:\WINDOWS\SYSTEM32\mkrhtbpa.exe
C:\WINDOWS\SYSTEM32\mlknhsed.dll
C:\WINDOWS\SYSTEM32\mlnvlrdt.exe
C:\WINDOWS\SYSTEM32\mopvnwil.exe
C:\WINDOWS\SYSTEM32\mpustsmt.exe
C:\WINDOWS\SYSTEM32\mrpyrnts.exe
C:\WINDOWS\SYSTEM32\mscfinxe.dll
C:\WINDOWS\SYSTEM32\mswfbddd.dll
C:\WINDOWS\SYSTEM32\mteeorug.dll
C:\WINDOWS\SYSTEM32\mwfkleqn.exe
C:\WINDOWS\SYSTEM32\mwuxalhf.exe
C:\WINDOWS\SYSTEM32\mxylxntc.exe
C:\WINDOWS\SYSTEM32\nafoyeah.dll
C:\WINDOWS\SYSTEM32\ncluhrym.dll
C:\WINDOWS\SYSTEM32\nhnscdrv.dll
C:\WINDOWS\SYSTEM32\njoxvnpq.exe
C:\WINDOWS\SYSTEM32\njusbqoa.exe
C:\WINDOWS\SYSTEM32\nminxsxi.dll
C:\WINDOWS\SYSTEM32\nmodkkhg.exe
C:\WINDOWS\SYSTEM32\nnbamrov.dll
C:\WINDOWS\SYSTEM32\npkmskgk.exe
C:\WINDOWS\SYSTEM32\nuensrgy.exe
C:\WINDOWS\SYSTEM32\nvwhiamf.exe
C:\WINDOWS\SYSTEM32\nxplwxaa.dll
C:\WINDOWS\SYSTEM32\nxvpmmyr.exe
C:\WINDOWS\SYSTEM32\nxwqrwqk.exe
C:\WINDOWS\SYSTEM32\nydwipgf.dll
C:\WINDOWS\SYSTEM32\odojmdif.exe
C:\WINDOWS\SYSTEM32\ohkjlthy.dll
C:\WINDOWS\SYSTEM32\oiwdfnmr.dll
C:\WINDOWS\SYSTEM32\ojdplfko.dll
C:\WINDOWS\SYSTEM32\okfmhpsl.dll
C:\WINDOWS\SYSTEM32\ompcxltm.dll
C:\WINDOWS\SYSTEM32\onmgxynb.exe
C:\WINDOWS\SYSTEM32\oovxgpaf.dll
C:\WINDOWS\SYSTEM32\opvcvxoe.dll
C:\WINDOWS\SYSTEM32\opysskik.dll
C:\WINDOWS\SYSTEM32\osudsmvq.exe
C:\WINDOWS\SYSTEM32\oujtcvtb.dll
C:\WINDOWS\SYSTEM32\pbmnptxk.dll
C:\WINDOWS\SYSTEM32\pcixnngt.exe
C:\WINDOWS\SYSTEM32\pfdbgdir.exe
C:\WINDOWS\SYSTEM32\pfwqrjej.exe
C:\WINDOWS\SYSTEM32\pfyvcvvd.exe
C:\WINDOWS\SYSTEM32\pmhbnakp.dll
C:\WINDOWS\SYSTEM32\pmuqjxvy.dll
C:\WINDOWS\SYSTEM32\pqgjssjh.exe
C:\WINDOWS\SYSTEM32\ptkvqnig.dll
C:\WINDOWS\SYSTEM32\pwpahdcf.exe
C:\WINDOWS\SYSTEM32\qbuckcvu.exe
C:\WINDOWS\SYSTEM32\qbwydmte.exe
C:\WINDOWS\SYSTEM32\qcrkqktc.exe
C:\WINDOWS\SYSTEM32\qcuhmaog.exe
C:\WINDOWS\SYSTEM32\qdeemdxk.dll
C:\WINDOWS\SYSTEM32\qdgiqmtt.dll
C:\WINDOWS\SYSTEM32\qdvhbdmu.exe
C:\WINDOWS\SYSTEM32\qhimqfmi.dll
C:\WINDOWS\SYSTEM32\qlqfmavf.exe
C:\WINDOWS\SYSTEM32\qlsknvnl.dll
C:\WINDOWS\SYSTEM32\qmukhsyg.exe
C:\WINDOWS\SYSTEM32\qpcmwltn.exe
C:\WINDOWS\SYSTEM32\qpuektmk.dll
C:\WINDOWS\SYSTEM32\qumoyemv.exe
C:\WINDOWS\SYSTEM32\qwcleqfi.exe
C:\WINDOWS\SYSTEM32\qydtsnyg.dll
C:\WINDOWS\SYSTEM32\rbshlbjt.dll
C:\WINDOWS\SYSTEM32\rcjbuhur.dll
C:\WINDOWS\SYSTEM32\redtbmvy.exe
C:\WINDOWS\SYSTEM32\reiplvde.dll
C:\WINDOWS\SYSTEM32\rfgdlvtf.exe
C:\WINDOWS\SYSTEM32\rmypqyht.exe
C:\WINDOWS\SYSTEM32\rqmmdwsd.dll
C:\WINDOWS\SYSTEM32\rqrrrpm.dll
C:\WINDOWS\SYSTEM32\rrggtlpo.dll
C:\WINDOWS\SYSTEM32\sapkremj.exe
C:\WINDOWS\SYSTEM32\sdapnhhh.exe
C:\WINDOWS\SYSTEM32\sdrjabuj.exe
C:\WINDOWS\SYSTEM32\sgdomayx.exe
C:\WINDOWS\SYSTEM32\sglmfwdb.dll
C:\WINDOWS\SYSTEM32\sjreppkf.exe
C:\WINDOWS\SYSTEM32\soamsrbk.dll
C:\WINDOWS\SYSTEM32\spkjwrbn.exe
C:\WINDOWS\SYSTEM32\sqobagde.exe
C:\WINDOWS\SYSTEM32\styajryu.exe
C:\WINDOWS\SYSTEM32\sulmjssn.dll
C:\WINDOWS\SYSTEM32\swmcgdbs.dll
C:\WINDOWS\SYSTEM32\tcnrsdcg.exe
C:\WINDOWS\SYSTEM32\tconastn.exe
C:\WINDOWS\SYSTEM32\tehnkkpx.dll
C:\WINDOWS\SYSTEM32\tftuksfw.exe
C:\WINDOWS\SYSTEM32\thajvcvf.exe
C:\WINDOWS\SYSTEM32\thdueljj.exe
C:\WINDOWS\SYSTEM32\thiqvrgb.dll
C:\WINDOWS\SYSTEM32\thukwfbl.exe
C:\WINDOWS\SYSTEM32\tloicuru.exe
C:\WINDOWS\SYSTEM32\tohikbxc.dll
C:\WINDOWS\SYSTEM32\tonbsvos.dll
C:\WINDOWS\SYSTEM32\tryfmvys.exe
C:\WINDOWS\SYSTEM32\tskxevkk.dll
C:\WINDOWS\SYSTEM32\ttfavnxa.dll
C:\WINDOWS\SYSTEM32\twjpxegx.exe
C:\WINDOWS\SYSTEM32\tylrybqq.exe
C:\WINDOWS\SYSTEM32\uaillkwu.dll
C:\WINDOWS\SYSTEM32\udgiqsgg.exe
C:\WINDOWS\SYSTEM32\udhbpric.exe
C:\WINDOWS\SYSTEM32\uhsaxlkd.exe
C:\WINDOWS\SYSTEM32\ukfmauga.exe
C:\WINDOWS\SYSTEM32\ukjwihhu.dll
C:\WINDOWS\SYSTEM32\uowiejop.dll
C:\WINDOWS\SYSTEM32\usxtbqqx.exe
C:\WINDOWS\SYSTEM32\utstv.bak1
C:\WINDOWS\SYSTEM32\utstv.ini
C:\WINDOWS\SYSTEM32\utstv.ini2
C:\WINDOWS\SYSTEM32\utstv.tmp
C:\WINDOWS\SYSTEM32\utvttxli.dll
C:\WINDOWS\SYSTEM32\uwgivalh.exe
C:\WINDOWS\SYSTEM32\vbeeoruh.dll
C:\WINDOWS\SYSTEM32\vhquttef.exe
C:\WINDOWS\SYSTEM32\vqdpoeaf.exe
C:\WINDOWS\system32\vtstu.dll
C:\WINDOWS\SYSTEM32\vumltjpb.dll
C:\WINDOWS\SYSTEM32\vyeloiqf.exe
C:\WINDOWS\SYSTEM32\vyyiddfj.exe
C:\WINDOWS\SYSTEM32\wanxlafj.dll
C:\WINDOWS\SYSTEM32\wedkahge.dll
C:\WINDOWS\SYSTEM32\wehmoqik.exe
C:\WINDOWS\SYSTEM32\wgsamrqj.exe
C:\WINDOWS\SYSTEM32\wgytytgb.exe
C:\WINDOWS\SYSTEM32\wiskjqgi.dll
C:\WINDOWS\SYSTEM32\wkdyxoxh.dll
C:\WINDOWS\SYSTEM32\wkenmmvl.dll
C:\WINDOWS\SYSTEM32\wlfiwlll.dll
C:\WINDOWS\SYSTEM32\wmcxlcos.dll
C:\WINDOWS\SYSTEM32\wmjxoykw.dll
C:\WINDOWS\SYSTEM32\wpwwblqj.exe
C:\WINDOWS\SYSTEM32\wqtjbhjv.dll
C:\WINDOWS\SYSTEM32\wrbxdcfi.exe
C:\WINDOWS\SYSTEM32\wrgtafmu.dll
C:\WINDOWS\SYSTEM32\wrvwbnwo.exe
C:\WINDOWS\SYSTEM32\wsdbknhx.exe
C:\WINDOWS\SYSTEM32\wteydalk.exe
C:\WINDOWS\SYSTEM32\wtqdarfv.dll
C:\WINDOWS\SYSTEM32\wukavnyb.exe
C:\WINDOWS\SYSTEM32\wwwdgfts.exe
C:\WINDOWS\SYSTEM32\wyvihpdd.dll
C:\WINDOWS\system32\xcbsorxv.dll
C:\WINDOWS\SYSTEM32\xceumnwb.exe
C:\WINDOWS\SYSTEM32\xdwvjitu.exe
C:\WINDOWS\SYSTEM32\xevrfbrr.exe
C:\WINDOWS\SYSTEM32\xifvjlvw.exe
C:\WINDOWS\SYSTEM32\xiuygfph.exe
C:\WINDOWS\SYSTEM32\xiyujxil.exe
C:\WINDOWS\SYSTEM32\xjmdjbug.dll
C:\WINDOWS\SYSTEM32\xjwrdfmr.dll
C:\WINDOWS\SYSTEM32\xjyxkxlo.exe
C:\WINDOWS\SYSTEM32\xkapxekx.dll
C:\WINDOWS\SYSTEM32\xlvugwvr.exe
C:\WINDOWS\SYSTEM32\xnbpldjy.exe
C:\WINDOWS\SYSTEM32\xovxljpp.exe
C:\WINDOWS\SYSTEM32\xsvcseik.exe
C:\WINDOWS\SYSTEM32\xsxomnuh.exe
C:\WINDOWS\SYSTEM32\xtbvcwin.exe
C:\WINDOWS\SYSTEM32\xugqrsln.dll
C:\WINDOWS\SYSTEM32\xyccgvmu.dll
C:\WINDOWS\SYSTEM32\yfpjgljq.exe
C:\WINDOWS\SYSTEM32\ykloluyq.dll
C:\WINDOWS\SYSTEM32\yktbctne.exe
C:\WINDOWS\SYSTEM32\ymjjpnmg.dll
C:\WINDOWS\SYSTEM32\yqiqejsl.exe
C:\WINDOWS\SYSTEM32\yqprwalk.exe
C:\WINDOWS\SYSTEM32\ytcfcdsh.exe
C:\WINDOWS\SYSTEM32\yuvdgihw.exe
C:\WINDOWS\SYSTEM32\yvemingj.exe
C:\WINDOWS\SYSTEM32\ywrjbxke.dll

Beginning removal...

Attempting to delete C:\WINDOWS\SYSTEM32\aakptrra.exe
C:\WINDOWS\SYSTEM32\aakptrra.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\abuewadh.exe
C:\WINDOWS\SYSTEM32\abuewadh.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\admoqhog.ini
C:\WINDOWS\SYSTEM32\admoqhog.ini Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\admoqhog.ini2
C:\WINDOWS\SYSTEM32\admoqhog.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\aghqplwl.exe
C:\WINDOWS\SYSTEM32\aghqplwl.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ahetitie.dll
C:\WINDOWS\SYSTEM32\ahetitie.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ahnpdeif.exe
C:\WINDOWS\SYSTEM32\ahnpdeif.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\akpoejtr.exe
C:\WINDOWS\SYSTEM32\akpoejtr.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\aktqkvwe.exe
C:\WINDOWS\SYSTEM32\aktqkvwe.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\aohctmhp.exe
C:\WINDOWS\SYSTEM32\aohctmhp.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\aolljhiy.exe
C:\WINDOWS\SYSTEM32\aolljhiy.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\apjhhmon.dll
C:\WINDOWS\SYSTEM32\apjhhmon.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\avcgemrb.dll
C:\WINDOWS\SYSTEM32\avcgemrb.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\awrembsb.dll
C:\WINDOWS\SYSTEM32\awrembsb.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bakxgufj.dll
C:\WINDOWS\SYSTEM32\bakxgufj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bbtdqphg.exe
C:\WINDOWS\SYSTEM32\bbtdqphg.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bcaoixer.exe
C:\WINDOWS\SYSTEM32\bcaoixer.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bdywcytk.dll
C:\WINDOWS\SYSTEM32\bdywcytk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bekvbctu.dll
C:\WINDOWS\SYSTEM32\bekvbctu.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bgimlook.exe
C:\WINDOWS\SYSTEM32\bgimlook.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bhotnoxi.exe
C:\WINDOWS\SYSTEM32\bhotnoxi.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\biecoeeo.exe
C:\WINDOWS\SYSTEM32\biecoeeo.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\biricgut.dll
C:\WINDOWS\SYSTEM32\biricgut.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bjojdnyw.exe
C:\WINDOWS\SYSTEM32\bjojdnyw.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bthqhvfi.dll
C:\WINDOWS\SYSTEM32\bthqhvfi.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\buhonjga.dll
C:\WINDOWS\SYSTEM32\buhonjga.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bujlofht.exe
C:\WINDOWS\SYSTEM32\bujlofht.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bulwbdjf.dll
C:\WINDOWS\SYSTEM32\bulwbdjf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\buvlqxdw.dll
C:\WINDOWS\SYSTEM32\buvlqxdw.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bvtnerkv.dll
C:\WINDOWS\SYSTEM32\bvtnerkv.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\bxwxclex.dll
C:\WINDOWS\SYSTEM32\bxwxclex.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\byqtdiac.exe
C:\WINDOWS\SYSTEM32\byqtdiac.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\camnvhxt.dll
C:\WINDOWS\SYSTEM32\camnvhxt.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cdqxhjjk.exe
C:\WINDOWS\SYSTEM32\cdqxhjjk.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\chvfaggm.dll
C:\WINDOWS\SYSTEM32\chvfaggm.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ciadhbji.dll
C:\WINDOWS\SYSTEM32\ciadhbji.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cjnrdcga.exe
C:\WINDOWS\SYSTEM32\cjnrdcga.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ckatjgbi.exe
C:\WINDOWS\SYSTEM32\ckatjgbi.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ckttobiy.dll
C:\WINDOWS\SYSTEM32\ckttobiy.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\clpjfiox.exe
C:\WINDOWS\SYSTEM32\clpjfiox.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cmibctfs.exe
C:\WINDOWS\SYSTEM32\cmibctfs.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cprxujvh.exe
C:\WINDOWS\SYSTEM32\cprxujvh.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cqfjgmqj.dll
C:\WINDOWS\SYSTEM32\cqfjgmqj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\crjmbhja.exe
C:\WINDOWS\SYSTEM32\crjmbhja.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\crprxslx.exe
C:\WINDOWS\SYSTEM32\crprxslx.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ctltaekh.dll
C:\WINDOWS\SYSTEM32\ctltaekh.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ctmenyem.exe
C:\WINDOWS\SYSTEM32\ctmenyem.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cuwgxppg.exe
C:\WINDOWS\SYSTEM32\cuwgxppg.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cwmedspk.dll
C:\WINDOWS\SYSTEM32\cwmedspk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cyaqvdst.dll
C:\WINDOWS\SYSTEM32\cyaqvdst.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dgelolic.exe
C:\WINDOWS\SYSTEM32\dgelolic.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dgnfwxsv.exe
C:\WINDOWS\SYSTEM32\dgnfwxsv.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dmjboxhk.exe
C:\WINDOWS\SYSTEM32\dmjboxhk.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dmqfnxrk.dll
C:\WINDOWS\SYSTEM32\dmqfnxrk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dnkipwwx.exe
C:\WINDOWS\SYSTEM32\dnkipwwx.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dnxqmedw.dll
C:\WINDOWS\SYSTEM32\dnxqmedw.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dpbtaqve.exe
C:\WINDOWS\SYSTEM32\dpbtaqve.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dptdpcjw.exe
C:\WINDOWS\SYSTEM32\dptdpcjw.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dqhbobhc.exe
C:\WINDOWS\SYSTEM32\dqhbobhc.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dtgqwqip.dll
C:\WINDOWS\SYSTEM32\dtgqwqip.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dubawsme.dll
C:\WINDOWS\SYSTEM32\dubawsme.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\duyhlile.dll
C:\WINDOWS\SYSTEM32\duyhlile.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dvaewoid.exe
C:\WINDOWS\SYSTEM32\dvaewoid.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dvfvorkm.dll
C:\WINDOWS\SYSTEM32\dvfvorkm.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dvuimtik.dll
C:\WINDOWS\SYSTEM32\dvuimtik.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dvwesorn.dll
C:\WINDOWS\SYSTEM32\dvwesorn.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\dydptwal.exe
C:\WINDOWS\SYSTEM32\dydptwal.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\eajjbhce.dll
C:\WINDOWS\SYSTEM32\eajjbhce.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ecgipuwq.exe
C:\WINDOWS\SYSTEM32\ecgipuwq.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\egjobfvn.exe
C:\WINDOWS\SYSTEM32\egjobfvn.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ehqecbeg.exe
C:\WINDOWS\SYSTEM32\ehqecbeg.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\eiwpueho.dll
C:\WINDOWS\SYSTEM32\eiwpueho.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\elmiyjsy.exe
C:\WINDOWS\SYSTEM32\elmiyjsy.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\enenuksm.exe
C:\WINDOWS\SYSTEM32\enenuksm.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\eqgeujfs.exe
C:\WINDOWS\SYSTEM32\eqgeujfs.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\eqxaymrk.dll
C:\WINDOWS\SYSTEM32\eqxaymrk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\esugmkwo.exe
C:\WINDOWS\SYSTEM32\esugmkwo.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\esylboid.exe
C:\WINDOWS\SYSTEM32\esylboid.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\eudaqpgy.exe
C:\WINDOWS\SYSTEM32\eudaqpgy.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\evetlqql.exe
C:\WINDOWS\SYSTEM32\evetlqql.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\evvajseh.dll
C:\WINDOWS\SYSTEM32\evvajseh.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ewamdvar.exe
C:\WINDOWS\SYSTEM32\ewamdvar.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\excephbn.exe
C:\WINDOWS\SYSTEM32\excephbn.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\exjlqmsy.exe
C:\WINDOWS\SYSTEM32\exjlqmsy.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\exkrscts.dll
C:\WINDOWS\SYSTEM32\exkrscts.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fgdoieph.dll
C:\WINDOWS\SYSTEM32\fgdoieph.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fhgbkvyj.dll
C:\WINDOWS\SYSTEM32\fhgbkvyj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fhjodbwj.dll
C:\WINDOWS\SYSTEM32\fhjodbwj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fikvecqi.dll
C:\WINDOWS\SYSTEM32\fikvecqi.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fivhgarm.dll
C:\WINDOWS\SYSTEM32\fivhgarm.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fmjfwhbm.dll
C:\WINDOWS\SYSTEM32\fmjfwhbm.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fnlvkfqy.dll
C:\WINDOWS\SYSTEM32\fnlvkfqy.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fnrfanlq.exe
C:\WINDOWS\SYSTEM32\fnrfanlq.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fpohiyjj.exe
C:\WINDOWS\SYSTEM32\fpohiyjj.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\frywfbte.dll
C:\WINDOWS\SYSTEM32\frywfbte.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fwaknbql.exe
C:\WINDOWS\SYSTEM32\fwaknbql.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fxgeybyd.dll
C:\WINDOWS\SYSTEM32\fxgeybyd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\fxqhktjw.dll
C:\WINDOWS\SYSTEM32\fxqhktjw.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gdjygbyf.dll
C:\WINDOWS\SYSTEM32\gdjygbyf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gdqnfhwj.exe
C:\WINDOWS\SYSTEM32\gdqnfhwj.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gebxvsp.dll
C:\WINDOWS\SYSTEM32\gebxvsp.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gfjdvgmo.exe
C:\WINDOWS\SYSTEM32\gfjdvgmo.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ghdmnsqt.exe
C:\WINDOWS\SYSTEM32\ghdmnsqt.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gjdenhkd.dll
C:\WINDOWS\SYSTEM32\gjdenhkd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gjlxemmx.dll
C:\WINDOWS\SYSTEM32\gjlxemmx.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gkrvyhtp.exe
C:\WINDOWS\SYSTEM32\gkrvyhtp.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gohqomda.dll
C:\WINDOWS\SYSTEM32\gohqomda.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\goxpsddk.dll
C:\WINDOWS\SYSTEM32\goxpsddk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\grsycrwn.dll
C:\WINDOWS\SYSTEM32\grsycrwn.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\gwyaegbd.dll
C:\WINDOWS\SYSTEM32\gwyaegbd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hbhkkcxc.dll
C:\WINDOWS\SYSTEM32\hbhkkcxc.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hbrnmeqj.dll
C:\WINDOWS\SYSTEM32\hbrnmeqj.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hcgmgpaq.exe
C:\WINDOWS\SYSTEM32\hcgmgpaq.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hdhcsrjv.dll
C:\WINDOWS\SYSTEM32\hdhcsrjv.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hgbpbiev.exe
C:\WINDOWS\SYSTEM32\hgbpbiev.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hjkojtxd.exe
C:\WINDOWS\SYSTEM32\hjkojtxd.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hjvafuys.exe
C:\WINDOWS\SYSTEM32\hjvafuys.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hpbnejrl.exe
C:\WINDOWS\SYSTEM32\hpbnejrl.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hptpgkkm.exe
C:\WINDOWS\SYSTEM32\hptpgkkm.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hqkdrayv.exe
C:\WINDOWS\SYSTEM32\hqkdrayv.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\hrpepjrs.exe
C:\WINDOWS\SYSTEM32\hrpepjrs.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iacxvomw.dll
C:\WINDOWS\SYSTEM32\iacxvomw.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ichetrgs.dll
C:\WINDOWS\SYSTEM32\ichetrgs.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\idxpvlxu.dll
C:\WINDOWS\SYSTEM32\idxpvlxu.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iesnjbav.exe
C:\WINDOWS\SYSTEM32\iesnjbav.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ifqdmuxn.exe
C:\WINDOWS\SYSTEM32\ifqdmuxn.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iimaoqqo.dll
C:\WINDOWS\SYSTEM32\iimaoqqo.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iksvyppi.exe
C:\WINDOWS\SYSTEM32\iksvyppi.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iraqmoyf.exe
C:\WINDOWS\SYSTEM32\iraqmoyf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ircbxfcg.exe
C:\WINDOWS\SYSTEM32\ircbxfcg.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iuawymdc.dll
C:\WINDOWS\SYSTEM32\iuawymdc.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ixwlrxjv.dll
C:\WINDOWS\SYSTEM32\ixwlrxjv.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iyaxsnrd.dll
C:\WINDOWS\SYSTEM32\iyaxsnrd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iybhofft.exe
C:\WINDOWS\SYSTEM32\iybhofft.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\iymoijid.dll
C:\WINDOWS\SYSTEM32\iymoijid.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jagjegks.dll
C:\WINDOWS\SYSTEM32\jagjegks.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jbkxkkjn.dll
C:\WINDOWS\SYSTEM32\jbkxkkjn.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jdltauuj.exe
C:\WINDOWS\SYSTEM32\jdltauuj.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jdtdeaql.exe
C:\WINDOWS\SYSTEM32\jdtdeaql.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jgwluemd.exe
C:\WINDOWS\SYSTEM32\jgwluemd.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jhpwhbso.exe
C:\WINDOWS\SYSTEM32\jhpwhbso.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jichfkem.dll
C:\WINDOWS\SYSTEM32\jichfkem.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jiklrqpp.dll
C:\WINDOWS\SYSTEM32\jiklrqpp.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jisnnjaj.exe
C:\WINDOWS\SYSTEM32\jisnnjaj.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jltlsahj.exe
C:\WINDOWS\SYSTEM32\jltlsahj.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jmeaqpof.exe
C:\WINDOWS\SYSTEM32\jmeaqpof.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jmoctomf.exe
C:\WINDOWS\SYSTEM32\jmoctomf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jofckeip.exe
C:\WINDOWS\SYSTEM32\jofckeip.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jongfkkf.exe
C:\WINDOWS\SYSTEM32\jongfkkf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jpfneexa.exe
C:\WINDOWS\SYSTEM32\jpfneexa.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jpspfvey.dll
C:\WINDOWS\SYSTEM32\jpspfvey.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jskqvcwe.exe
C:\WINDOWS\SYSTEM32\jskqvcwe.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jtsosstw.exe
C:\WINDOWS\SYSTEM32\jtsosstw.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jtwfgxtf.dll
C:\WINDOWS\SYSTEM32\jtwfgxtf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jupvxips.dll
C:\WINDOWS\SYSTEM32\jupvxips.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jwjdwyjp.exe
C:\WINDOWS\SYSTEM32\jwjdwyjp.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jxhycgbx.exe
C:\WINDOWS\SYSTEM32\jxhycgbx.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jxicnrpf.dll
C:\WINDOWS\SYSTEM32\jxicnrpf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\jxxrkkpa.exe
C:\WINDOWS\SYSTEM32\jxxrkkpa.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\kdutjgmk.dll
C:\WINDOWS\SYSTEM32\kdutjgmk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\keggvcja.dll
C:\WINDOWS\SYSTEM32\keggvcja.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\kqawmybq.exe
C:\WINDOWS\SYSTEM32\kqawmybq.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\kvampeme.exe
C:\WINDOWS\SYSTEM32\kvampeme.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\kvhmlgoe.dll
C:\WINDOWS\SYSTEM32\kvhmlgoe.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\kwafqgkl.exe
C:\WINDOWS\SYSTEM32\kwafqgkl.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\kwqilyvr.exe
C:\WINDOWS\SYSTEM32\kwqilyvr.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\kylsyaij.exe
C:\WINDOWS\SYSTEM32\kylsyaij.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lbaiaabx.dll
C:\WINDOWS\SYSTEM32\lbaiaabx.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lfrjspse.exe
C:\WINDOWS\SYSTEM32\lfrjspse.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lgehawle.dll
C:\WINDOWS\SYSTEM32\lgehawle.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ljjifff.dll
C:\WINDOWS\SYSTEM32\ljjifff.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lkbaxeru.exe
C:\WINDOWS\SYSTEM32\lkbaxeru.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lltgxaav.exe
C:\WINDOWS\SYSTEM32\lltgxaav.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lphvedwl.exe
C:\WINDOWS\SYSTEM32\lphvedwl.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lpvkyhie.dll
C:\WINDOWS\SYSTEM32\lpvkyhie.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lqfansyq.exe
C:\WINDOWS\SYSTEM32\lqfansyq.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lxilfhwf.dll
C:\WINDOWS\SYSTEM32\lxilfhwf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\maibxkoc.exe
C:\WINDOWS\SYSTEM32\maibxkoc.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mdhgduln.dll
C:\WINDOWS\SYSTEM32\mdhgduln.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mdholjte.dll
C:\WINDOWS\SYSTEM32\mdholjte.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mdvyxqdf.dll
C:\WINDOWS\SYSTEM32\mdvyxqdf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mhnotefs.dll
C:\WINDOWS\SYSTEM32\mhnotefs.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mkrhtbpa.exe
C:\WINDOWS\SYSTEM32\mkrhtbpa.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mlknhsed.dll
C:\WINDOWS\SYSTEM32\mlknhsed.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mlnvlrdt.exe
C:\WINDOWS\SYSTEM32\mlnvlrdt.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mopvnwil.exe
C:\WINDOWS\SYSTEM32\mopvnwil.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mpustsmt.exe
C:\WINDOWS\SYSTEM32\mpustsmt.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mrpyrnts.exe
C:\WINDOWS\SYSTEM32\mrpyrnts.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mscfinxe.dll
C:\WINDOWS\SYSTEM32\mscfinxe.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mswfbddd.dll
C:\WINDOWS\SYSTEM32\mswfbddd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mteeorug.dll
C:\WINDOWS\SYSTEM32\mteeorug.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mwfkleqn.exe
C:\WINDOWS\SYSTEM32\mwfkleqn.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mwuxalhf.exe
C:\WINDOWS\SYSTEM32\mwuxalhf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mxylxntc.exe
C:\WINDOWS\SYSTEM32\mxylxntc.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nafoyeah.dll
C:\WINDOWS\SYSTEM32\nafoyeah.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ncluhrym.dll
C:\WINDOWS\SYSTEM32\ncluhrym.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nhnscdrv.dll
C:\WINDOWS\SYSTEM32\nhnscdrv.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\njoxvnpq.exe
C:\WINDOWS\SYSTEM32\njoxvnpq.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\njusbqoa.exe
C:\WINDOWS\SYSTEM32\njusbqoa.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nminxsxi.dll
C:\WINDOWS\SYSTEM32\nminxsxi.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nmodkkhg.exe
C:\WINDOWS\SYSTEM32\nmodkkhg.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nnbamrov.dll
C:\WINDOWS\SYSTEM32\nnbamrov.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\npkmskgk.exe
C:\WINDOWS\SYSTEM32\npkmskgk.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nuensrgy.exe
C:\WINDOWS\SYSTEM32\nuensrgy.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nvwhiamf.exe
C:\WINDOWS\SYSTEM32\nvwhiamf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nxplwxaa.dll
C:\WINDOWS\SYSTEM32\nxplwxaa.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nxvpmmyr.exe
C:\WINDOWS\SYSTEM32\nxvpmmyr.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nxwqrwqk.exe
C:\WINDOWS\SYSTEM32\nxwqrwqk.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nydwipgf.dll
C:\WINDOWS\SYSTEM32\nydwipgf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\odojmdif.exe
C:\WINDOWS\SYSTEM32\odojmdif.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ohkjlthy.dll
C:\WINDOWS\SYSTEM32\ohkjlthy.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\oiwdfnmr.dll
C:\WINDOWS\SYSTEM32\oiwdfnmr.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ojdplfko.dll
C:\WINDOWS\SYSTEM32\ojdplfko.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\okfmhpsl.dll
C:\WINDOWS\SYSTEM32\okfmhpsl.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ompcxltm.dll
C:\WINDOWS\SYSTEM32\ompcxltm.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\onmgxynb.exe
C:\WINDOWS\SYSTEM32\onmgxynb.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\oovxgpaf.dll
C:\WINDOWS\SYSTEM32\oovxgpaf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\opvcvxoe.dll
C:\WINDOWS\SYSTEM32\opvcvxoe.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\opysskik.dll
C:\WINDOWS\SYSTEM32\opysskik.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\osudsmvq.exe
C:\WINDOWS\SYSTEM32\osudsmvq.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\oujtcvtb.dll
C:\WINDOWS\SYSTEM32\oujtcvtb.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pbmnptxk.dll
C:\WINDOWS\SYSTEM32\pbmnptxk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pcixnngt.exe
C:\WINDOWS\SYSTEM32\pcixnngt.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pfdbgdir.exe
C:\WINDOWS\SYSTEM32\pfdbgdir.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pfwqrjej.exe
C:\WINDOWS\SYSTEM32\pfwqrjej.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pfyvcvvd.exe
C:\WINDOWS\SYSTEM32\pfyvcvvd.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pmhbnakp.dll
C:\WINDOWS\SYSTEM32\pmhbnakp.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pmuqjxvy.dll
C:\WINDOWS\SYSTEM32\pmuqjxvy.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pqgjssjh.exe
C:\WINDOWS\SYSTEM32\pqgjssjh.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ptkvqnig.dll
C:\WINDOWS\SYSTEM32\ptkvqnig.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pwpahdcf.exe
C:\WINDOWS\SYSTEM32\pwpahdcf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qbuckcvu.exe
C:\WINDOWS\SYSTEM32\qbuckcvu.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qbwydmte.exe
C:\WINDOWS\SYSTEM32\qbwydmte.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qcrkqktc.exe
C:\WINDOWS\SYSTEM32\qcrkqktc.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qcuhmaog.exe
C:\WINDOWS\SYSTEM32\qcuhmaog.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qdeemdxk.dll
C:\WINDOWS\SYSTEM32\qdeemdxk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qdgiqmtt.dll
C:\WINDOWS\SYSTEM32\qdgiqmtt.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qdvhbdmu.exe
C:\WINDOWS\SYSTEM32\qdvhbdmu.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qhimqfmi.dll
C:\WINDOWS\SYSTEM32\qhimqfmi.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qlqfmavf.exe
C:\WINDOWS\SYSTEM32\qlqfmavf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qlsknvnl.dll
C:\WINDOWS\SYSTEM32\qlsknvnl.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qmukhsyg.exe
C:\WINDOWS\SYSTEM32\qmukhsyg.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qpcmwltn.exe
C:\WINDOWS\SYSTEM32\qpcmwltn.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qpuektmk.dll
C:\WINDOWS\SYSTEM32\qpuektmk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qumoyemv.exe
C:\WINDOWS\SYSTEM32\qumoyemv.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qwcleqfi.exe
C:\WINDOWS\SYSTEM32\qwcleqfi.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\qydtsnyg.dll
C:\WINDOWS\SYSTEM32\qydtsnyg.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\rbshlbjt.dll
C:\WINDOWS\SYSTEM32\rbshlbjt.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\rcjbuhur.dll
C:\WINDOWS\SYSTEM32\rcjbuhur.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\redtbmvy.exe
C:\WINDOWS\SYSTEM32\redtbmvy.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\reiplvde.dll
C:\WINDOWS\SYSTEM32\reiplvde.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\rfgdlvtf.exe
C:\WINDOWS\SYSTEM32\rfgdlvtf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\rmypqyht.exe
C:\WINDOWS\SYSTEM32\rmypqyht.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\rqmmdwsd.dll
C:\WINDOWS\SYSTEM32\rqmmdwsd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\rqrrrpm.dll
C:\WINDOWS\SYSTEM32\rqrrrpm.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\rrggtlpo.dll
C:\WINDOWS\SYSTEM32\rrggtlpo.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sapkremj.exe
C:\WINDOWS\SYSTEM32\sapkremj.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sdapnhhh.exe
C:\WINDOWS\SYSTEM32\sdapnhhh.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sdrjabuj.exe
C:\WINDOWS\SYSTEM32\sdrjabuj.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sgdomayx.exe
C:\WINDOWS\SYSTEM32\sgdomayx.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sglmfwdb.dll
C:\WINDOWS\SYSTEM32\sglmfwdb.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sjreppkf.exe
C:\WINDOWS\SYSTEM32\sjreppkf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\soamsrbk.dll
C:\WINDOWS\SYSTEM32\soamsrbk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\spkjwrbn.exe
C:\WINDOWS\SYSTEM32\spkjwrbn.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sqobagde.exe
C:\WINDOWS\SYSTEM32\sqobagde.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\styajryu.exe
C:\WINDOWS\SYSTEM32\styajryu.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sulmjssn.dll
C:\WINDOWS\SYSTEM32\sulmjssn.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\swmcgdbs.dll
C:\WINDOWS\SYSTEM32\swmcgdbs.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tcnrsdcg.exe
C:\WINDOWS\SYSTEM32\tcnrsdcg.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tconastn.exe
C:\WINDOWS\SYSTEM32\tconastn.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tehnkkpx.dll
C:\WINDOWS\SYSTEM32\tehnkkpx.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tftuksfw.exe
C:\WINDOWS\SYSTEM32\tftuksfw.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\thajvcvf.exe
C:\WINDOWS\SYSTEM32\thajvcvf.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\thdueljj.exe
C:\WINDOWS\SYSTEM32\thdueljj.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\thiqvrgb.dll
C:\WINDOWS\SYSTEM32\thiqvrgb.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\thukwfbl.exe
C:\WINDOWS\SYSTEM32\thukwfbl.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tloicuru.exe
C:\WINDOWS\SYSTEM32\tloicuru.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tohikbxc.dll
C:\WINDOWS\SYSTEM32\tohikbxc.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tonbsvos.dll
C:\WINDOWS\SYSTEM32\tonbsvos.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tryfmvys.exe
C:\WINDOWS\SYSTEM32\tryfmvys.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tskxevkk.dll
C:\WINDOWS\SYSTEM32\tskxevkk.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ttfavnxa.dll
C:\WINDOWS\SYSTEM32\ttfavnxa.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\twjpxegx.exe
C:\WINDOWS\SYSTEM32\twjpxegx.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\tylrybqq.exe
C:\WINDOWS\SYSTEM32\tylrybqq.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\uaillkwu.dll
C:\WINDOWS\SYSTEM32\uaillkwu.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\udgiqsgg.exe
C:\WINDOWS\SYSTEM32\udgiqsgg.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\udhbpric.exe
C:\WINDOWS\SYSTEM32\udhbpric.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\uhsaxlkd.exe
C:\WINDOWS\SYSTEM32\uhsaxlkd.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ukfmauga.exe
C:\WINDOWS\SYSTEM32\ukfmauga.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\ukjwihhu.dll
C:\WINDOWS\SYSTEM32\ukjwihhu.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\uowiejop.dll
C:\WINDOWS\SYSTEM32\uowiejop.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\usxtbqqx.exe
C:\WINDOWS\SYSTEM32\usxtbqqx.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\utstv.bak1
C:\WINDOWS\SYSTEM32\utstv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\utstv.ini
C:\WINDOWS\SYSTEM32\utstv.ini Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\utstv.ini2
C:\WINDOWS\SYSTEM32\utstv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\utstv.tmp
C:\WINDOWS\SYSTEM32\utstv.tmp Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\utvttxli.dll
C:\WINDOWS\SYSTEM32\utvttxli.dll Has been deleted!
<

#8 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 21 January 2007 - 11:47 AM

And here's the ComboFix log:

"Name" - 07-01-21 13:48:11 Service Pack 2
ComboFix 07-01-21 - Running from: "C:\Documents and Settings\Name\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\{3C073~1
C:\Program Files\Common Files\{FC073~1
C:\Program Files\VSAdd-in
C:\WINDOWS\system32\components
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\Program Files\SMANTE~1
C:\qoobox\purity\WINDOWS\SSEMBL~1
C:\qoobox\purity\WINDOWS\SSEMBL~1\?ssembly
C:\qoobox\purity\WINDOWS\SYSTEM32\ASKS~1
C:\qoobox\purity\WINDOWS\SYSTEM32\STEM~1


((((((((((((((((((((((((((((((( Files Created from 2006-12-21 to 2007-01-21 ))))))))))))))))))))))))))))))))))


2007-01-21 13:41 <DIR> d-------- C:\VundoFix Backups
2007-01-20 23:35 <DIR> d-------- C:\WINDOWS\SYSTEM32\Adobe
2007-01-20 23:35 <DIR> d-------- C:\Program Files\Common Files\Vbox
2007-01-20 23:30 <DIR> d-------- C:\Adobe Illustrator Installer
2007-01-16 23:07 <DIR> d-------- C:\DOCUME~1\Name\Contacts
2007-01-16 23:01 76,412 --a------ C:\WINDOWS\SYSTEM32\qtwdlnai.dll
2007-01-16 19:40 <DIR> d-------- C:\DOCUME~1\Name\.housecall6.6
2007-01-16 18:12 76,412 --a------ C:\WINDOWS\SYSTEM32\jguctdnv.dll
2007-01-16 15:53 76,412 --a------ C:\WINDOWS\SYSTEM32\kbscosvh.dll
2007-01-14 22:17 <DIR> d-------- C:\Program Files\ImTOO
2007-01-12 16:28 <DIR> d-------- C:\DOCUME~1\Name\Application Data\Help
2007-01-11 03:00 <DIR> d-------- C:\WINDOWS\ie7updates
2006-12-31 20:36 <DIR> d-------- C:\DOCUME~1\Name\Application Data\Lavasoft
2006-12-27 13:27 <DIR> d-------- C:\DOCUME~1\Name\Application Data\çasks
2006-12-27 00:21 <DIR> d-------- C:\Program Files\MagicISO
2006-12-26 21:25 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2006-12-26 21:25 <DIR> d-------- C:\Program Files\Windows Media Components
2006-12-26 21:14 <DIR> d-------- C:\Program Files\Winnydows
2006-12-26 21:14 <DIR> d-------- C:\Program Files\AviSynth 2.5
2006-12-26 20:51 102,400 --a------ C:\WINDOWS\SYSTEM32\tsccvid.dll
2006-12-26 20:50 <DIR> d-------- C:\Program Files\TechSmith
2006-12-26 20:19 1,295,582 --a------ C:\WINDOWS\SYSTEM32\cygwin1.dll
2006-12-25 11:23 <DIR> d-------- C:\WINDOWS\setupupd
2006-12-25 11:23 <DIR> d-------- C:\WINDOWS\setup.pss
2006-12-24 19:01 <DIR> d-------- C:\DOCUME~1\Name\Application Data\Shareaza
2006-12-24 18:14 <DIR> d-------- C:\Program Files\eMule
2006-12-24 10:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Avg7
2006-12-22 23:07 <DIR> d-------- C:\Program Files\AviSynth2
2006-12-22 15:27 <DIR> d-------- C:\Program Files\Common Files\xing shared
2006-12-22 15:18 <DIR> d-------- C:\DOCUME~1\Name\Application Data\Real
2006-12-21 11:08 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Application Data\Gtek
2006-12-21 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\You've Got Pictures Screensaver
2006-12-21 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\Sun
2006-12-21 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\Sonic
2006-12-21 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\Jasc Software Inc


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

Rootkit driver pe386 is present. A rootkit scan is required

2007-01-21 13:47 -------- d-------- C:\Program Files\mozilla firefox
2007-01-21 13:31 -------- d-------- C:\DOCUME~1\Name\Application Data\utorrent
2007-01-20 23:35 -------- d-------- C:\Program Files\Common Files\adobe
2007-01-20 23:34 -------- d--h----- C:\Program Files\installshield installation information
2007-01-20 12:18 -------- d-------- C:\Program Files\spywareblaster
2007-01-18 12:53 -------- d-------- C:\Program Files\flashget
2007-01-17 20:25 -------- d---s---- C:\DOCUME~1\Name\Application Data\microsoft
2007-01-13 17:04 -------- d---s---- C:\Program Files\xfire
2007-01-07 15:36 -------- d-------- C:\DOCUME~1\Name\Application Data\adobe
2007-01-03 16:03 -------- d-------- C:\Program Files\java
2006-12-24 19:01 -------- d-------- C:\Program Files\shareaza
2006-12-23 22:26 3822 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2006-12-22 15:25 -------- d-------- C:\Program Files\Common Files\real
2006-12-20 17:22 -------- d--h----- C:\Program Files\Common Files\uninstall information
2006-12-20 17:16 -------- d-------- C:\Program Files\pedevice
2006-12-16 20:03 -------- d-------- C:\Program Files\grisoft
2006-12-11 13:39 56320 --a------ C:\WINDOWS\SYSTEM32\ntfypbg.dll
2006-12-07 05:29 2374472 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-12-03 13:41 -------- d-------- C:\DOCUME~1\Name\Application Data\winamp
2006-12-03 13:26 -------- d-------- C:\Program Files\winamp
2006-12-01 22:37 -------- d-------- C:\Program Files\dvd decrypter
2006-11-25 18:23 54884 --a------ C:\WINDOWS\SYSTEM32\cvshost.exe
2006-11-25 18:19 54884 --a------ C:\WINDOWS\SYSTEM32\msnmsgrs.exe
2006-11-25 16:11 -------- d-------- C:\Program Files\mustek 1200 ub plus
2006-11-22 20:44 -------- d-------- C:\Program Files\samsung
2006-11-08 05:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-10-27 15:09 6049280 --------- C:\WINDOWS\SYSTEM32\ieframe.dll
2006-10-27 15:09 50688 --------- C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-10-27 15:09 458752 --------- C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-10-27 15:09 413696 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-10-27 15:09 231424 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-10-27 15:09 180736 --------- C:\WINDOWS\SYSTEM32\ieui.dll
2006-10-27 15:09 156160 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-10-27 02:44 71680 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-10-27 02:44 55296 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-10-27 02:44 54784 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-10-27 02:44 43008 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-10-27 02:44 382976 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-10-27 02:44 229376 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-10-27 02:44 152064 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-10-27 02:44 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-10-27 02:44 123904 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-10-27 02:42 161792 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-10-22 15:06 208896 --a------ C:\WINDOWS\SYSTEM32\nvuninst.exe
2006-10-22 15:06 208896 --a------ C:\WINDOWS\SYSTEM32\nvudisp.exe
2006-10-22 12:22 888832 --a------ C:\WINDOWS\SYSTEM32\nvmobls.dll
2006-10-22 12:22 86016 --a------ C:\WINDOWS\SYSTEM32\nvmctray.dll
2006-10-22 12:22 81920 --a------ C:\WINDOWS\SYSTEM32\nvwddi.dll
2006-10-22 12:22 794624 --a------ C:\WINDOWS\SYSTEM32\nvcplui.exe
2006-10-22 12:22 7700480 --a------ C:\WINDOWS\SYSTEM32\nvcpl.dll
2006-10-22 12:22 581632 --a------ C:\WINDOWS\SYSTEM32\nvhwvid.dll
2006-10-22 12:22 5644288 --a------ C:\WINDOWS\SYSTEM32\nvoglnt.dll
2006-10-22 12:22 5619712 --a------ C:\WINDOWS\SYSTEM32\nvdisps.dll
2006-10-22 12:22 5255168 --a------ C:\WINDOWS\SYSTEM32\nvdispsr.dll
2006-10-22 12:22 466944 --a------ C:\WINDOWS\SYSTEM32\nvshell.dll
2006-10-22 12:22 458752 --a------ C:\WINDOWS\SYSTEM32\nvmccssr.dll
2006-10-22 12:22 4527488 --a------ C:\WINDOWS\SYSTEM32\nv4_disp.dll
2006-10-22 12:22 45056 --a------ C:\WINDOWS\SYSTEM32\nvmccsrs.dll
2006-10-22 12:22 442368 --a------ C:\WINDOWS\SYSTEM32\nvappbar.exe
2006-10-22 12:22 425984 --a------ C:\WINDOWS\SYSTEM32\keystone.exe
2006-10-22 12:22 35840 --a------ C:\WINDOWS\SYSTEM32\nvcodins.dll
2006-10-22 12:22 35840 --a------ C:\WINDOWS\SYSTEM32\nvcod.dll
2006-10-22 12:22 3203072 --a------ C:\WINDOWS\SYSTEM32\nvgamesr.dll
2006-10-22 12:22 311296 --a------ C:\WINDOWS\SYSTEM32\nvexpbar.dll
2006-10-22 12:22 3047424 --a------ C:\WINDOWS\SYSTEM32\nvgames.dll
2006-10-22 12:22 2973696 --a------ C:\WINDOWS\SYSTEM32\nvvitvsr.dll
2006-10-22 12:22 2924544 --a------ C:\WINDOWS\SYSTEM32\nvvitvs.dll
2006-10-22 12:22 286720 --a------ C:\WINDOWS\SYSTEM32\nvnt4cpl.dll
2006-10-22 12:22 2859008 --a------ C:\WINDOWS\SYSTEM32\nvmoblsr.dll
2006-10-22 12:22 229376 --a------ C:\WINDOWS\SYSTEM32\nvmccs.dll
2006-10-22 12:22 212992 --a------ C:\WINDOWS\SYSTEM32\nvapi.dll
2006-10-22 12:22 188416 --a------ C:\WINDOWS\SYSTEM32\nvmccss.dll
2006-10-22 12:22 1732608 --a------ C:\WINDOWS\SYSTEM32\nvwssr.dll
2006-10-22 12:22 1662976 --a------ C:\WINDOWS\SYSTEM32\nvwdmcpl.dll
2006-10-22 12:22 1622016 --a------ C:\WINDOWS\SYSTEM32\nwiz.exe
2006-10-22 12:22 159810 --a------ C:\WINDOWS\SYSTEM32\nvsvc32.exe
2006-10-22 12:22 147456 --a------ C:\WINDOWS\SYSTEM32\nvcolor.exe
2006-10-22 12:22 1470464 --a------ C:\WINDOWS\SYSTEM32\nview.dll
2006-10-22 12:22 1339392 --a------ C:\WINDOWS\SYSTEM32\nvdspsch.exe
2006-10-22 12:22 1236992 --a------ C:\WINDOWS\SYSTEM32\nvwss.dll
2006-10-22 12:22 1019904 --a------ C:\WINDOWS\SYSTEM32\nvwimg.dll
2006-10-22 12:22 1011712 --a------ C:\WINDOWS\SYSTEM32\nvcpluir.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Steam"=""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"IntelMeM"="C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"EPSON Stylus C42 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S10IC1.EXE /P23 \"EPSON Stylus C42 Series\" /O6 \"USB001\" /M \"Stylus C42\""
"Gtwatch"="C:\\WINDOWS\\gtwatch.exe"
"Windows Load"="C:\\WINDOWS\\system32\\msnmsgrs.exe"
"WINDOWS"="c:\\qlcojek.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DSAgnt"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Steam"
"hkey"="HKCU"
"command"="C:\\Program Files\\Valve\\Steam\\\\Steam.exe -silent"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winampa"
"hkey"="HKLM"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{91C916F5-0750-43B3-AB12-814B881ED309}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrvc32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0


Completion time: 07-01-21 13:52:22

Edited by Dark Phoenix, 21 January 2007 - 11:48 AM.


#9 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:06 AM

Posted 21 January 2007 - 12:51 PM

Hi

Open HijackThis, click do a system scan only and checkmark these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\xcbsorxv.dll (file missing)
O2 - BHO: (no name) - {8DD305CF-9E07-B8DA-2053-9F5B51593195} - C:\WINDOWS\system32\ntfypbg.dll
O2 - BHO: (no name) - {91C916F5-0750-43B3-AB12-814B881ED309} - C:\WINDOWS\system32\ljjifff.dll (file missing)
O2 - BHO: (no name) - {95658D6F-E93D-4AD4-BBB2-AD572CD880DC} - C:\WINDOWS\system32\vtstu.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [Windows Load] C:\WINDOWS\system32\msnmsgrs.exe
O4 - HKLM\..\Run: [WINDOWS] c:\qlcojek.exe
O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)


Close all windows including browser and press fix checked.

Please download the Killbox.
Unzip it to the desktop.

Please run Killbox.

Select "Delete on Reboot" and "All files"

Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\SYSTEM32\qtwdlnai.dll
C:\WINDOWS\SYSTEM32\jguctdnv.dll
C:\WINDOWS\SYSTEM32\kbscosvh.dll
C:\WINDOWS\SYSTEM32\cvshost.exe
C:\WINDOWS\SYSTEM32\msnmsgrs.exe
c:\qlcojek.exe

Go to the File menu, and choose "Paste from Clipboard".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again..

If your computer does not restart automatically, please restart it manually.

Download
http://www.uploads.ejvindh.net/rustbfix.exe
...and save it to your desktop.

Double click on rustbfix.exe to run the tool. If a Rustock.b-infection is found, you will shortly hereafter be asked to reboot the computer. The reboot will probably take quite a while, and perhaps 2 reboots will be needed. But this will happen automatically. After the reboot 2 logfiles will open (%root%\avenger.txt & %root%\rustbfix\pelog.txt). Post the content of these logfiles along with a new HijackThis log.

Re-run combofix

Send:

- a fresh HijackThis log
- combofix report
- c:\avenger.txt
- C:\rustbfix\pelog.txt

You may need several replies to post the requested logs, otherwise they might get cut off.
Microsoft MVP Consumer Security
Posted Image

Posted Image

#10 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 21 January 2007 - 02:22 PM

Avenger:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\jjcaecnu

*******************


Fatal error: integrity of Services key failed verification check! Security may be fatally compromised. Exiting immediately.

Could not open script file! Status: 0xc0000034 Abort!


Pelog:

************************* Rustock.b-fix -- By ejvindh *************************
21/01/2007 19:10:50.57

******************* Pre-run Status of system *******************

Rootkit driver PE386 is found. Starting the unload-procedure....

#11 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 21 January 2007 - 02:23 PM

Hijack This:

Logfile of HijackThis v1.99.1
Scan saved at 19:19:51, on 21/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Name\Desktop\Maintenance\HJT.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://admin:password@192.168.0.1/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



ComboFix:

"Name" - 07-01-21 19:15:19 Service Pack 2
ComboFix 07-01-21 - Running from: "C:\Documents and Settings\Name\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\Program Files\SMANTE~1
C:\qoobox\purity\WINDOWS\SSEMBL~1
C:\qoobox\purity\WINDOWS\SSEMBL~1\?ssembly
C:\qoobox\purity\WINDOWS\SYSTEM32\ASKS~1
C:\qoobox\purity\WINDOWS\SYSTEM32\STEM~1


((((((((((((((((((((((((((((((( Files Created from 2006-12-21 to 2007-01-21 ))))))))))))))))))))))))))))))))))


2007-01-21 19:13 <DIR> d-------- C:\avenger
2007-01-21 19:10 16 --a------ C:\chdir.bat
2007-01-21 19:10 <DIR> d-------- C:\Rustbfix
2007-01-21 19:07 <DIR> d-------- C:\!KillBox
2007-01-21 13:41 <DIR> d-------- C:\VundoFix Backups
2007-01-20 23:35 <DIR> d-------- C:\WINDOWS\SYSTEM32\Adobe
2007-01-20 23:35 <DIR> d-------- C:\Program Files\Common Files\Vbox
2007-01-20 23:30 <DIR> d-------- C:\Adobe Illustrator Installer
2007-01-16 23:07 <DIR> d-------- C:\DOCUME~1\Name\Contacts
2007-01-16 19:40 <DIR> d-------- C:\DOCUME~1\Name\.housecall6.6
2007-01-14 22:17 <DIR> d-------- C:\Program Files\ImTOO
2007-01-12 16:28 <DIR> d-------- C:\DOCUME~1\Name\Application Data\Help
2007-01-11 03:00 <DIR> d-------- C:\WINDOWS\ie7updates
2006-12-31 20:36 <DIR> d-------- C:\DOCUME~1\Name\Application Data\Lavasoft
2006-12-27 13:27 <DIR> d-------- C:\DOCUME~1\Name\Application Data\çasks
2006-12-27 00:21 <DIR> d-------- C:\Program Files\MagicISO
2006-12-26 21:25 <DIR> d--h----- C:\WINDOWS\msdownld.tmp
2006-12-26 21:25 <DIR> d-------- C:\Program Files\Windows Media Components
2006-12-26 21:14 <DIR> d-------- C:\Program Files\Winnydows
2006-12-26 21:14 <DIR> d-------- C:\Program Files\AviSynth 2.5
2006-12-26 20:51 102,400 --a------ C:\WINDOWS\SYSTEM32\tsccvid.dll
2006-12-26 20:50 <DIR> d-------- C:\Program Files\TechSmith
2006-12-26 20:19 1,295,582 --a------ C:\WINDOWS\SYSTEM32\cygwin1.dll
2006-12-25 11:23 <DIR> d-------- C:\WINDOWS\setupupd
2006-12-25 11:23 <DIR> d-------- C:\WINDOWS\setup.pss
2006-12-24 19:01 <DIR> d-------- C:\DOCUME~1\Name\Application Data\Shareaza
2006-12-24 18:14 <DIR> d-------- C:\Program Files\eMule
2006-12-24 10:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Avg7
2006-12-22 23:07 <DIR> d-------- C:\Program Files\AviSynth2
2006-12-22 15:27 <DIR> d-------- C:\Program Files\Common Files\xing shared
2006-12-22 15:18 <DIR> d-------- C:\DOCUME~1\Name\Application Data\Real
2006-12-21 11:08 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Application Data\Gtek
2006-12-21 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\You've Got Pictures Screensaver
2006-12-21 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\Sun
2006-12-21 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\Sonic
2006-12-21 11:08 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Application Data\Jasc Software Inc


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-21 19:13 -------- d-------- C:\Program Files\mozilla firefox
2007-01-21 19:06 -------- d-------- C:\Program Files\flashget
2007-01-21 13:31 -------- d-------- C:\DOCUME~1\Name\Application Data\utorrent
2007-01-20 23:35 -------- d-------- C:\Program Files\Common Files\adobe
2007-01-20 23:34 -------- d--h----- C:\Program Files\installshield installation information
2007-01-20 12:18 -------- d-------- C:\Program Files\spywareblaster
2007-01-17 20:25 -------- d---s---- C:\DOCUME~1\Name\Application Data\microsoft
2007-01-13 17:04 -------- d---s---- C:\Program Files\xfire
2007-01-07 15:36 -------- d-------- C:\DOCUME~1\Name\Application Data\adobe
2007-01-03 16:03 -------- d-------- C:\Program Files\java
2006-12-24 19:01 -------- d-------- C:\Program Files\shareaza
2006-12-23 22:26 3822 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2006-12-22 15:25 -------- d-------- C:\Program Files\Common Files\real
2006-12-20 17:22 -------- d--h----- C:\Program Files\Common Files\uninstall information
2006-12-20 17:16 -------- d-------- C:\Program Files\pedevice
2006-12-16 20:03 -------- d-------- C:\Program Files\grisoft
2006-12-07 05:29 2374472 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-12-03 13:41 -------- d-------- C:\DOCUME~1\Name\Application Data\winamp
2006-12-03 13:26 -------- d-------- C:\Program Files\winamp
2006-12-01 22:37 -------- d-------- C:\Program Files\dvd decrypter
2006-11-25 16:11 -------- d-------- C:\Program Files\mustek 1200 ub plus
2006-11-22 20:44 -------- d-------- C:\Program Files\samsung
2006-11-08 05:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-10-27 15:09 6049280 --------- C:\WINDOWS\SYSTEM32\ieframe.dll
2006-10-27 15:09 50688 --------- C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-10-27 15:09 458752 --------- C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-10-27 15:09 413696 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-10-27 15:09 231424 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-10-27 15:09 180736 --------- C:\WINDOWS\SYSTEM32\ieui.dll
2006-10-27 15:09 156160 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-10-27 02:44 71680 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-10-27 02:44 55296 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-10-27 02:44 54784 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-10-27 02:44 43008 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-10-27 02:44 382976 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-10-27 02:44 229376 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-10-27 02:44 152064 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-10-27 02:44 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-10-27 02:44 123904 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-10-27 02:42 161792 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-10-22 15:06 208896 --a------ C:\WINDOWS\SYSTEM32\nvuninst.exe
2006-10-22 15:06 208896 --a------ C:\WINDOWS\SYSTEM32\nvudisp.exe
2006-10-22 12:22 888832 --a------ C:\WINDOWS\SYSTEM32\nvmobls.dll
2006-10-22 12:22 86016 --a------ C:\WINDOWS\SYSTEM32\nvmctray.dll
2006-10-22 12:22 81920 --a------ C:\WINDOWS\SYSTEM32\nvwddi.dll
2006-10-22 12:22 794624 --a------ C:\WINDOWS\SYSTEM32\nvcplui.exe
2006-10-22 12:22 7700480 --a------ C:\WINDOWS\SYSTEM32\nvcpl.dll
2006-10-22 12:22 581632 --a------ C:\WINDOWS\SYSTEM32\nvhwvid.dll
2006-10-22 12:22 5644288 --a------ C:\WINDOWS\SYSTEM32\nvoglnt.dll
2006-10-22 12:22 5619712 --a------ C:\WINDOWS\SYSTEM32\nvdisps.dll
2006-10-22 12:22 5255168 --a------ C:\WINDOWS\SYSTEM32\nvdispsr.dll
2006-10-22 12:22 466944 --a------ C:\WINDOWS\SYSTEM32\nvshell.dll
2006-10-22 12:22 458752 --a------ C:\WINDOWS\SYSTEM32\nvmccssr.dll
2006-10-22 12:22 4527488 --a------ C:\WINDOWS\SYSTEM32\nv4_disp.dll
2006-10-22 12:22 45056 --a------ C:\WINDOWS\SYSTEM32\nvmccsrs.dll
2006-10-22 12:22 442368 --a------ C:\WINDOWS\SYSTEM32\nvappbar.exe
2006-10-22 12:22 425984 --a------ C:\WINDOWS\SYSTEM32\keystone.exe
2006-10-22 12:22 35840 --a------ C:\WINDOWS\SYSTEM32\nvcodins.dll
2006-10-22 12:22 35840 --a------ C:\WINDOWS\SYSTEM32\nvcod.dll
2006-10-22 12:22 3203072 --a------ C:\WINDOWS\SYSTEM32\nvgamesr.dll
2006-10-22 12:22 311296 --a------ C:\WINDOWS\SYSTEM32\nvexpbar.dll
2006-10-22 12:22 3047424 --a------ C:\WINDOWS\SYSTEM32\nvgames.dll
2006-10-22 12:22 2973696 --a------ C:\WINDOWS\SYSTEM32\nvvitvsr.dll
2006-10-22 12:22 2924544 --a------ C:\WINDOWS\SYSTEM32\nvvitvs.dll
2006-10-22 12:22 286720 --a------ C:\WINDOWS\SYSTEM32\nvnt4cpl.dll
2006-10-22 12:22 2859008 --a------ C:\WINDOWS\SYSTEM32\nvmoblsr.dll
2006-10-22 12:22 229376 --a------ C:\WINDOWS\SYSTEM32\nvmccs.dll
2006-10-22 12:22 212992 --a------ C:\WINDOWS\SYSTEM32\nvapi.dll
2006-10-22 12:22 188416 --a------ C:\WINDOWS\SYSTEM32\nvmccss.dll
2006-10-22 12:22 1732608 --a------ C:\WINDOWS\SYSTEM32\nvwssr.dll
2006-10-22 12:22 1662976 --a------ C:\WINDOWS\SYSTEM32\nvwdmcpl.dll
2006-10-22 12:22 1622016 --a------ C:\WINDOWS\SYSTEM32\nwiz.exe
2006-10-22 12:22 159810 --a------ C:\WINDOWS\SYSTEM32\nvsvc32.exe
2006-10-22 12:22 147456 --a------ C:\WINDOWS\SYSTEM32\nvcolor.exe
2006-10-22 12:22 1470464 --a------ C:\WINDOWS\SYSTEM32\nview.dll
2006-10-22 12:22 1339392 --a------ C:\WINDOWS\SYSTEM32\nvdspsch.exe
2006-10-22 12:22 1236992 --a------ C:\WINDOWS\SYSTEM32\nvwss.dll
2006-10-22 12:22 1019904 --a------ C:\WINDOWS\SYSTEM32\nvwimg.dll
2006-10-22 12:22 1011712 --a------ C:\WINDOWS\SYSTEM32\nvcpluir.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Steam"=""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"IntelMeM"="C:\\Program Files\\Intel\\Modem Event Monitor\\IntelMEM.exe"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"EPSON Stylus C42 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S10IC1.EXE /P23 \"EPSON Stylus C42 Series\" /O6 \"USB001\" /M \"Stylus C42\""
"Gtwatch"="C:\\WINDOWS\\gtwatch.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DSAgnt"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DVDLauncher"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Steam"
"hkey"="HKCU"
"command"="C:\\Program Files\\Valve\\Steam\\\\Steam.exe -silent"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winampa"
"hkey"="HKLM"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{91C916F5-0750-43B3-AB12-814B881ED309}"=""

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0


Completion time: 07-01-21 19:19:15

#12 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:02:06 AM

Posted 22 January 2007 - 02:11 AM

Hi

Avenger.txt is kind of weird, but we'll continue.

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Send:

- a fresh HijackThis log
- kaspersky report
Microsoft MVP Consumer Security
Posted Image

Posted Image

#13 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 22 January 2007 - 05:37 PM

Here's the Kaspersky report. I accidentally saved it as a web page and then copied and pasted the text from there, so it may be a little hard to read. Sorry about that. If you want I could do the scan again.

KASPERSKY ONLINE SCANNER REPORT
Monday, January 22, 2007 10:00:10 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 22/01/2007
Kaspersky Anti-Virus database records: 260887
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
F:\
G:\
Scan Statistics
Total number of scanned objects 93339
Number of viruses found 18
Number of infected objects 763 / 0
Number of suspicious objects 0
Duration of the scan process 01:19:22

Infected Object Name Virus Name Last Action
C:\!KillBox\cvshost.exe Infected: Backdoor.Win32.VB.asw skipped
C:\!KillBox\jguctdnv.dll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\!KillBox\kbscosvh.dll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\!KillBox\msnmsgrs.exe Infected: Backdoor.Win32.VB.asw skipped
C:\!KillBox\qtwdlnai.dll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Temp\b104.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Documents and Settings\Name\Local Settings\Temp\b104.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\Documents and Settings\Name\Local Settings\Temp\b104.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\Documents and Settings\Name\Local Settings\Temp\b104.exe NSIS: infected - 3 skipped
C:\Documents and Settings\Name\Local Settings\Temp\b116.exe/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.dy skipped
C:\Documents and Settings\Name\Local Settings\Temp\b116.exe/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.dy skipped
C:\Documents and Settings\Name\Local Settings\Temp\b116.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\Documents and Settings\Name\Local Settings\Temp\b116.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\Documents and Settings\Name\Local Settings\Temp\b116.exe NSIS: infected - 4 skipped
C:\Documents and Settings\Name\Local Settings\Temp\b122.exe/stream/data0002/stream/data0003 Infected: not-a-virus:AdWare.Win32.Maxifiles.aa skipped
C:\Documents and Settings\Name\Local Settings\Temp\b122.exe/stream/data0002/stream/data0004 Infected: Trojan-Downloader.Win32.Small.ece skipped
C:\Documents and Settings\Name\Local Settings\Temp\b122.exe/stream/data0002/stream Infected: Trojan-Downloader.Win32.Small.ece skipped
C:\Documents and Settings\Name\Local Settings\Temp\b122.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.ece skipped
C:\Documents and Settings\Name\Local Settings\Temp\b122.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\Documents and Settings\Name\Local Settings\Temp\b122.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\Documents and Settings\Name\Local Settings\Temp\b122.exe NSIS: infected - 6 skipped
C:\Documents and Settings\Name\Local Settings\Temp\Temporary Directory 1 for Adobe_Illustrator_CS2_v12.0_keygen_by_SSGS_(WWW.CRACK-CD.COM).zip\keygen.exe Infected: Trojan-Downloader.Win32.INService.gen skipped
C:\Documents and Settings\Name\Local Settings\Temp\Temporary Directory 1 for icecold_reloaded.zip\IceCold ReLoaded.exe Infected: HackTool.Win32.Homac skipped
C:\Documents and Settings\Name\Local Settings\Temp\Temporary Directory 2 for Adobe_Illustrator_CS2_v12.0_keygen_by_SSGS_(WWW.CRACK-CD.COM).zip\keygen.exe Infected: Trojan-Downloader.Win32.INService.gen skipped
C:\Documents and Settings\Name\Local Settings\Temp\Temporary Directory 3 for Adobe_Illustrator_CS2_v12.0_keygen_by_SSGS_(WWW.CRACK-CD.COM).zip\keygen.exe Infected: Trojan-Downloader.Win32.INService.gen skipped
C:\Documents and Settings\Name\Local Settings\Temp\Temporary Directory 4 for Adobe_Illustrator_CS2_v12.0_keygen_by_SSGS_(WWW.CRACK-CD.COM).zip\keygen.exe Infected: Trojan-Downloader.Win32.INService.gen skipped
C:\Documents and Settings\Name\My Documents\Downloads\IceCold ReLoaded.exe Infected: HackTool.Win32.Homac skipped
C:\Documents and Settings\Name\ntuser.dat Object is locked skipped
C:\Documents and Settings\Name\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Name\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\cert8.db Object is locked skipped
C:\Documents and Settings\Name\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\flashgot.log Object is locked skipped
C:\Documents and Settings\Name\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\history.dat Object is locked skipped
C:\Documents and Settings\Name\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\key3.db Object is locked skipped
C:\Documents and Settings\Name\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\parent.lock Object is locked skipped
C:\Documents and Settings\Name\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\search.sqlite Object is locked skipped
C:\Documents and Settings\Name\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Name\Application Data\Shareaza\Data\TigerTree.dat Object is locked skipped
C:\Documents and Settings\Name\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Name\Desktop\Maintenance\backups\backup-20070121-190602-571.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped
C:\Documents and Settings\Name\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_219.wmdb Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Application Data\Mozilla\Firefox\Profiles\fe4sbxoi.Name\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Name\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Name\Local Settings\History\History.IE5\MSHist012007012220070123\index.dat Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Temp\~ROMFN_000005DC Object is locked skipped
C:\Documents and Settings\Name\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Name\My Documents\Name\Programs\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Documents and Settings\Name\My Documents\Name\Programs\mirc616.exe mIRC: infected - 1 skipped
C:\Documents and Settings\Name\ntuser.dat Object is locked skipped
C:\Documents and Settings\Name\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Name\UserData\index.dat Object is locked skipped
C:\Program Files\Internet Explorer\BTOW Shared Files\btwebcontrol.dll Infected: not-a-virus:Dialer.Win32.BT.c skipped
C:\RECYCLER\S-1-5-21-145388895-513825307-1666260564-1007\Dc10.zip/keygen.exe Infected: Trojan-Downloader.Win32.INService.gen skipped
C:\RECYCLER\S-1-5-21-145388895-513825307-1666260564-1007\Dc10.zip ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-145388895-513825307-1666260564-1007\Dc21.exe Infected: Trojan-Downloader.Win32.INService.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP21\A0017384.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026452.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026454.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026484.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026489.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026490.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026493.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026497.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026498.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026509.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026510.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026517.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026522.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026527.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026528.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026542.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026543.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026548.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026553.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026554.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026565.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026580.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026585.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026589.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026595.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026596.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026601.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026602.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026611.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026614.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026615.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026626.dll Infected: Trojan-Downloader.Win32.Small.cws skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026637.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026638.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026639.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026640.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026641.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026642.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026643.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026644.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026645.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026646.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026647.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026648.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026649.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026650.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026651.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026652.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026653.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026654.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026655.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026656.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026657.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026658.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026659.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026660.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026661.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026662.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026663.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026664.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026665.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026666.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026667.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026668.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026669.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026670.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026671.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026672.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026673.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026674.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026675.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026676.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026677.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026678.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026679.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026680.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026681.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026682.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026683.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026684.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026685.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026686.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026687.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026688.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026689.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026690.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026691.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026692.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026693.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026694.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026695.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026696.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026697.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026698.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026699.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026700.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026701.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026702.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026703.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026704.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026705.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026706.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026707.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026708.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026709.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026710.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026711.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026712.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026713.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026714.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026715.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026716.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026717.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026718.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026719.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026720.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026721.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026722.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026723.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026724.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026725.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026726.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026727.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026728.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026729.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026730.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026731.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026732.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026733.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026734.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026736.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026737.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026738.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026739.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026740.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026741.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gf skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026742.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026743.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026744.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026745.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026746.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026747.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026748.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026749.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026750.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026751.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026752.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026753.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026754.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026755.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026756.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026757.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026758.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026759.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026760.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026761.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026762.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026763.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026764.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026765.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026766.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026767.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026768.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026769.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026770.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026771.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026772.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026773.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026774.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026775.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026776.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026777.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026778.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026779.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026780.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026781.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026782.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026783.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026784.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026785.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026786.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026787.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026788.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026789.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026790.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026791.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026792.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026793.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026794.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026795.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026796.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026797.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026798.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026799.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026800.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026801.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026802.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026803.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026804.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026806.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026807.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026808.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026809.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026810.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026811.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026812.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026813.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026814.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026815.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026816.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026817.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026818.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026819.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026820.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026821.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026822.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026823.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026824.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026825.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026826.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026827.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026828.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026829.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026830.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026831.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026832.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026833.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026834.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026835.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026836.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026837.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026838.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026839.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026840.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026841.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026842.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026843.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026844.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026845.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026846.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026847.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026848.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026849.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026850.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026851.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026852.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026853.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026854.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026855.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026856.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026857.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026858.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026859.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026860.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026861.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026862.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026863.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026864.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026865.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026866.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026867.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026868.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026869.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026870.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026871.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026872.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026873.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026874.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026875.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026876.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026877.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026878.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026879.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026880.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026881.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026882.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026883.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026884.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026885.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026886.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026887.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026888.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026890.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026891.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026892.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026893.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026894.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026895.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026896.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026897.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026898.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026899.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026900.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026901.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026902.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026903.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026904.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026905.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026906.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026907.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026908.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026909.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026910.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026911.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026912.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026913.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026914.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026915.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026916.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026917.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026918.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP31\A0026919.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{202550A8-7A3

#14 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 22 January 2007 - 05:38 PM

Here's the rest:

C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP33\change.log Object is locked skipped
C:\VundoFix Backups\aakptrra.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\abuewadh.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\aghqplwl.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ahetitie.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ahnpdeif.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\akpoejtr.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\aktqkvwe.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\aohctmhp.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\aolljhiy.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\apjhhmon.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\avcgemrb.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\awrembsb.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\bakxgufj.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\bbtdqphg.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\bcaoixer.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\bdywcytk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\bekvbctu.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\bgimlook.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\bhotnoxi.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\biecoeeo.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\biricgut.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\bjojdnyw.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\bthqhvfi.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\buhonjga.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\bujlofht.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\bulwbdjf.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\buvlqxdw.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\bvtnerkv.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\bxwxclex.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\byqtdiac.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\camnvhxt.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\cdqxhjjk.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\chvfaggm.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ciadhbji.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\cjnrdcga.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ckatjgbi.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ckttobiy.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\clpjfiox.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\cmibctfs.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\cprxujvh.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\cqfjgmqj.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\crjmbhja.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\crprxslx.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ctltaekh.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ctmenyem.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\cuwgxppg.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\cwmedspk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\cyaqvdst.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\dgelolic.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dgnfwxsv.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dmjboxhk.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dmqfnxrk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\dnkipwwx.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dnxqmedw.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\dpbtaqve.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dptdpcjw.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dqhbobhc.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dtgqwqip.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\dubawsme.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\duyhlile.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\dvaewoid.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dvfvorkm.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\dvuimtik.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\dvwesorn.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\dydptwal.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\eajjbhce.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ecgipuwq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\egjobfvn.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ehqecbeg.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\eiwpueho.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\elmiyjsy.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\enenuksm.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\eqgeujfs.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\eqxaymrk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\esugmkwo.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\esylboid.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\eudaqpgy.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\evetlqql.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\evvajseh.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ewamdvar.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\excephbn.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\exjlqmsy.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\exkrscts.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fgdoieph.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fhgbkvyj.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fhjodbwj.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fikvecqi.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fivhgarm.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fmjfwhbm.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fnlvkfqy.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fnrfanlq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\fpohiyjj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\frywfbte.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fwaknbql.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\fxgeybyd.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\fxqhktjw.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\gdjygbyf.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\gdqnfhwj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\gfjdvgmo.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ghdmnsqt.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\gjdenhkd.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\gjlxemmx.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\gkrvyhtp.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\gohqomda.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gf skipped
C:\VundoFix Backups\goxpsddk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\grsycrwn.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\gwyaegbd.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\hbhkkcxc.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\hbrnmeqj.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\hcgmgpaq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hdhcsrjv.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\hgbpbiev.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hjkojtxd.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hjvafuys.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hpbnejrl.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hptpgkkm.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hqkdrayv.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hrpepjrs.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\iacxvomw.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ichetrgs.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\idxpvlxu.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\iesnjbav.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ifqdmuxn.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\iimaoqqo.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\iksvyppi.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\iraqmoyf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ircbxfcg.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\iuawymdc.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ixwlrxjv.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\iyaxsnrd.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\iybhofft.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\iymoijid.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jagjegks.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jbkxkkjn.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jdltauuj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jdtdeaql.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jgwluemd.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jhpwhbso.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jichfkem.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jiklrqpp.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jisnnjaj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jltlsahj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jmeaqpof.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jmoctomf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jofckeip.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jongfkkf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jpfneexa.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jpspfvey.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jskqvcwe.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jtsosstw.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jtwfgxtf.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jupvxips.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jwjdwyjp.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jxhycgbx.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jxicnrpf.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\jxxrkkpa.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\kdutjgmk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\keggvcja.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\kqawmybq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\kvampeme.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\kvhmlgoe.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\kwafqgkl.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\kwqilyvr.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\kylsyaij.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\lbaiaabx.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\lfrjspse.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\lgehawle.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\lkbaxeru.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\lltgxaav.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\lphvedwl.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\lpvkyhie.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\lqfansyq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\lxilfhwf.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\maibxkoc.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mdhgduln.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\mdholjte.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\mdvyxqdf.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\mhnotefs.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\mkrhtbpa.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mlknhsed.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\mlnvlrdt.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mopvnwil.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mpustsmt.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mrpyrnts.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mscfinxe.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\mswfbddd.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\mteeorug.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\mwfkleqn.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mwuxalhf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mxylxntc.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nafoyeah.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ncluhrym.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\nhnscdrv.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\njoxvnpq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\njusbqoa.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nminxsxi.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\nmodkkhg.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nnbamrov.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\npkmskgk.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nuensrgy.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nvwhiamf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nxplwxaa.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\nxvpmmyr.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nxwqrwqk.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nydwipgf.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\odojmdif.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ohkjlthy.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\oiwdfnmr.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ojdplfko.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\okfmhpsl.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ompcxltm.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\onmgxynb.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\oovxgpaf.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\opvcvxoe.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\opysskik.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\osudsmvq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\oujtcvtb.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\pbmnptxk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\pcixnngt.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\pfdbgdir.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\pfwqrjej.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\pfyvcvvd.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\pmhbnakp.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\pmuqjxvy.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\pqgjssjh.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ptkvqnig.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\pwpahdcf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qbuckcvu.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qbwydmte.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qcrkqktc.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qcuhmaog.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qdeemdxk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\qdgiqmtt.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\qdvhbdmu.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qhimqfmi.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\qlqfmavf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qlsknvnl.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\qmukhsyg.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qpcmwltn.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qpuektmk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\qumoyemv.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qwcleqfi.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qydtsnyg.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\rbshlbjt.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\rcjbuhur.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\redtbmvy.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\reiplvde.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\rfgdlvtf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\rmypqyht.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\rqmmdwsd.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\rrggtlpo.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\sapkremj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\sdapnhhh.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\sdrjabuj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\sgdomayx.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\sglmfwdb.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\sjreppkf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\soamsrbk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\spkjwrbn.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\sqobagde.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\styajryu.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\sulmjssn.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\swmcgdbs.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\tcnrsdcg.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tconastn.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tehnkkpx.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\tftuksfw.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\thajvcvf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\thdueljj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\thiqvrgb.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\thukwfbl.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tloicuru.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tohikbxc.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\tonbsvos.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\tryfmvys.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tskxevkk.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\ttfavnxa.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\twjpxegx.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tylrybqq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\uaillkwu.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\udgiqsgg.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\udhbpric.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\uhsaxlkd.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ukfmauga.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ukjwihhu.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\uowiejop.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\usxtbqqx.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\utvttxli.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\uwgivalh.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\vbeeoruh.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\vhquttef.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\vqdpoeaf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\vumltjpb.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\vyeloiqf.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\vyyiddfj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wanxlafj.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wedkahge.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wehmoqik.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wgsamrqj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wgytytgb.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wiskjqgi.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wkdyxoxh.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wkenmmvl.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wlfiwlll.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wmcxlcos.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wmjxoykw.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wpwwblqj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wqtjbhjv.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wrbxdcfi.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wrgtafmu.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wrvwbnwo.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wsdbknhx.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wteydalk.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wtqdarfv.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\wukavnyb.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wwwdgfts.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\wyvihpdd.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\xcbsorxv.dll.bad Infected: Trojan.Win32.BHO.g skipped
C:\VundoFix Backups\xceumnwb.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xdwvjitu.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xevrfbrr.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xifvjlvw.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xiuygfph.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xiyujxil.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xjmdjbug.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\xjwrdfmr.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\xjyxkxlo.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xkapxekx.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\xlvugwvr.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xnbpldjy.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xovxljpp.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xsvcseik.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xsxomnuh.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xtbvcwin.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xugqrsln.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\xyccgvmu.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\yfpjgljq.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ykloluyq.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\yktbctne.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ymjjpnmg.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\yqiqejsl.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\yqprwalk.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ytcfcdsh.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\yuvdgihw.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\yvemingj.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ywrjbxke.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Debug\WPD\wpdtrace.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP33\change.log Object is locked skipped
Scan process completed.

#15 Dark Phoenix

Dark Phoenix
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:12:06 AM

Posted 22 January 2007 - 05:39 PM

And here's the Hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 22:38:22, on 22/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Name\Desktop\Maintenance\HJT.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://admin:password@192.168.0.1/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\S6U12BX\WATCH.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users